Method and system for web malware detection based on cross-lingual semantic analysis
Patent Information
- Application Number
- CN202310227212.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-03-10
- Publication Date
- 2026-09-29
- Estimated Expiration
- 2043-03-10
AI Technical Summary
基于JavaScript抽象语法树(Jast,Zozzle)、控制流、数据流(JStap)的检测器无法提取跨语言的语义信息;基于特征的检测器无法提取细粒度特征,导致误报率和漏报率都较高
[0050](1)当攻击者在JavaScript程序中调用WebAssembly模块构建跨语言的Web恶意程序时,现有技术由于只关注JavaScript部分的程序信息,无法捕捉跨语言的恶意行为。本发明针对此问题设计了一种跨语言的静态程序分析方法,可以同时捕捉单一语言以及跨语言的程序依赖辅助恶意软件识别,具有更高的准确性和分析鲁棒性。
Smart Images

Figure CN116432176B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of computer data processing technology, and specifically to a method and system for detecting web malware based on cross-language semantic analysis. Background Technology
[0002] With the rapid expansion of the internet and the surge in the number of internet users, web-based applications and services are also growing exponentially. To provide users with a better user experience and more convenient services, websites are implementing many functions that were originally server-side using JavaScript code directly on the web client. While JavaScript code, with its cross-platform compatibility, remote embedding capability, and dynamic execution, offers users numerous conveniences and a superior interactive experience, it also brings many risks and threats to web user terminals. For example, phishing websites can easily lead users to compromised privacy; another example is drive-by-download attacks, where users automatically download malicious software to their local devices. Cybersecurity reports indicate that a large number of malicious web pages are active worldwide every day, and the attack code within these pages is diverse and stealthy, with 17.1% of attacks being carried out using JavaScript code.
[0003] To defend against these attacks, researchers have proposed a series of methods to detect malicious programs on the web. Some work involves statically analyzing the semantics of web page scripts before execution, while others dynamically capture malicious behavior during script execution through methods such as code instrumentation. The former, due to its low overhead and fast execution, has become the preferred detection method for browsers. Attackers, in order to bypass existing malware detection methods, often use code obfuscation techniques to hide malicious behavior, leading both attackers and defenders to continuously design more complex code obfuscation methods and targeted detection tools. Currently, the most advanced web malware detection technology uses machine learning techniques to learn the characteristics of malicious JavaScript code and train models to detect malware.
[0004] While previous research on the semantics of malicious JavaScript has yielded some results, it has overlooked the fact that JavaScript is not the only client-side web language. With the continuous development of the Web, WebAssembly has been introduced as a new language for Web development. As of November 2017, WebAssembly was supported by all major browsers, and as of August 2021, 94% of browsers installed on the market supported WebAssembly. This new web-side programming language provides attackers with entirely new avenues of opportunity. Researchers have demonstrated that attackers can leverage WebAssembly to hide malicious functionality in web applications, generating a type of cross-language web malware. This type of malware consists of JavaScript and WebAssembly modules and can carry out malicious actions through cross-language interaction. Previous malware detection methods based on JavaScript semantics have been unable to effectively capture the semantics of these programs; cutting-edge detection tools have achieved recall rates as low as 0% for such malware, posing a significant security threat.
[0005] Current defenses against these attacks are largely ineffective. Detectors based on JavaScript Abstract Syntax Trees (Jast, Zozzle), control flow, and data flow (JStap) cannot extract cross-language semantic information; feature-based detectors cannot extract fine-grained features, resulting in high false positive and false negative rates. Therefore, both academia and industry lack suitable detection methods that can effectively identify cross-language malware. Summary of the Invention
[0006] To address the aforementioned technical problems, this invention provides a web malware detection method based on cross-language semantic analysis. Specifically, this invention designs a static program dependency analysis method for JavaScript code, using this method to extract the WebAssembly module from the program to be detected and model the cross-language interaction API between the JavaScript module and the WebAssembly module. For the WebAssembly module in the program to be detected, this invention further designs a static program analysis method for WebAssembly and obtains an abstract syntax tree. Finally, this invention designs a semantic restoration method that can effectively restore the hidden program semantics of the WebAssembly module into the JavaScript program based on cross-language interaction information and the WebAssembly abstract syntax tree, achieving effective detection of cross-language web malware. This method can be embedded as an independent program preprocessing module into various existing JavaScript malware detection methods, and developers of related detection tools can use it without modifying the original model.
[0007] To achieve the above objectives, the present invention proposes the following technical solution:
[0008] In a first aspect, the present invention provides a method for detecting web malware based on cross-language semantic analysis, comprising the following steps:
[0009] (1) Obtain the JavaScript code of the program under test and generate a JavaScript program dependency graph;
[0010] (2) Based on the predefined function labels, filter the cross-language interactive API call points in the JavaScript program dependency graph, and extract parameters and dependencies through data flow relationships;
[0011] (3) Determine the parameter type based on the parameters and dependencies obtained in step (2), decode the WebAssembly binary format program content of the program under test partition by partition, and extract the metadata of each partition.
[0012] (4) Convert the metadata of each partition into a list data structure, perform fine-grained analysis of the WebAssembly partition code, construct the WebAssembly abstract syntax tree for each code instruction, and trace the control flow dependency and data flow dependency in the WebAssembly program.
[0013] (5) Based on the WebAssembly abstract syntax tree, the control flow dependency and data flow dependency in the WebAssembly program, construct the WebAssembly program dependency graph based on ES6 syntax rules;
[0014] (6) Embed the WebAssembly program dependency graph into the cross-language interactive API call point of the JavaScript program dependency graph, and fill in the cross-language control flow and data flow dependencies between the two parts of the dependency graph according to the parameters and dependencies of the cross-language interactive API call point. Restore the WebAssembly program semantics to the original JavaScript program, and perform Web malware detection on the restored JavaScript program.
[0015] Further, step (1) includes:
[0016] (1-1) Obtain the JavaScript code of the program to be tested provided by the user;
[0017] (1-2) Based on ES6 syntax rules, the JavaScript code is parsed into an abstract syntax tree. If the parsing is incorrect, the process will terminate, an alert will be issued and manual processing will be requested. If the parsing is successful, proceed to step (1-3).
[0018] (1-3) Transform the JSON-formatted abstract syntax tree into a tree-like data structure, add control flow dependencies between syntax nodes, and output the JavaScript program control flow graph;
[0019] (1-4) Traverse the JavaScript program control flow graph according to the depth-first rule, record the data flow dependencies between functions and variables in the program under test, and expand the JavaScript program control flow graph into a JavaScript program dependency graph.
[0020] Furthermore, step (2) includes:
[0021] (2-1) Depth-first traversal of the JavaScript program dependency graph. During the traversal, when the node type is a function call, determine whether the function name belongs to the cross-language interaction API provided in the WebAssembly official documentation. If it does not belong to the cross-language interaction API, there is no need to record it. Otherwise, record the function call, parameters and return value to filter out the cross-language interaction API call points in the JavaScript program dependency graph.
[0022] (2-2) Analyze the cross-language interaction API call points obtained in step (2-1) one by one, process them according to different API function types, and obtain parameters and dependencies.
[0023] Furthermore, step (2-2) includes:
[0024] (2-2a) If the function type is WebAssembly.Module or WebAssembly.Instantiate, it means that the parameter type is WebAssembly binary format. Pass the parameter to the next stage for WebAssembly binary program parsing.
[0025] (2-2b) If the function type is WebAssembly.Instantiate or WebAssembly.Instance, it means that the function returns a WebAssembly Instance type variable. This type variable can derive WebAssembly functions. Therefore, it is necessary to perform backward data flow analysis on the return value to supplement the data flow from WebAssembly to the JavaScript module.
[0026] (2-2c) If the function type is WebAssembly.Table, WebAssembly.Memory, or WebAssembly.Global, it means that the function returns a WebAssembly element. This type of variable can be imported into the WebAssembly module. Therefore, it is necessary to perform backward data flow analysis on the return value to supplement the data flow from JavaScript to the WebAssembly module.
[0027] Furthermore, step (3) includes:
[0028] (3-1) Determine the parameter type based on the parameters and dependencies obtained in step (2). For WebAssembly binary type parameters, use the parsing function to parse the WebAssembly binary program content partition by partition. If the parsing fails, terminate, issue an alarm and request manual processing. If the parsing is successful, proceed to step (3-2).
[0029] (3-2) Store the parsed readable metadata according to the WebAssembly partition type, which includes custom section, type section, import section, function section, table section, memory section, global section, export section, start section, element section, code section, data section and data count section.
[0030] Furthermore, step (4) includes:
[0031] (4-1) Determine the partition type. If the partition type is not code, store the corresponding partition metadata as auxiliary data in a list and convert each partition metadata into a list data structure. If the partition type is code, proceed to step (4-2).
[0032] (4-2) Perform fine-grained analysis on the WebAssembly partition code, construct an abstract syntax tree for each code instruction, and simulate the WebAssembly stack virtual machine to trace the control flow dependencies and data flow dependencies in the WebAssembly program.
[0033] Furthermore, step (4-2) includes:
[0034] (4-2a) If the code instruction references a global type variable, then read the global type list stored in step (4-1) and perform push and pop operations on the relevant parameters; similarly, if the code instruction references a local type variable, then read the local type list stored in step (4-1) and perform push and pop operations on the relevant parameters.
[0035] (4-2b) If the code instruction is a control flow block-level instruction, a new program node is created for the block-level instruction, and step (4-2) is repeated for the lower-level instructions belonging to the block-level instruction, and the block-level instruction type is recorded.
[0036] (4-2c) If the code instruction is a numeric variable type, first determine the number of push parameters and pop parameters corresponding to the instruction, simulate the parameter push and pop process based on the analysis results, and then construct the control flow dependency and data flow dependency between instructions.
[0037] Furthermore, step (5) includes:
[0038] (5-1) Obtain the WebAssembly abstract syntax tree, control flow dependencies and data flow dependencies in the WebAssembly program obtained in step (4);
[0039] (5-2) Based on the ES6 syntax rules, the WebAssembly abstract syntax tree is converted into a program dependency graph consistent with the JavaScript syntax rules layer by layer, and the control flow dependency and data flow dependency are added to the program dependency graph in turn to construct a complete WebAssembly program dependency graph.
[0040] Furthermore, step (6) includes:
[0041] (6-1) Obtain the JavaScript program dependency graph obtained in step (1), the WebAssembly program dependency graph obtained in step (5), and the cross-language interaction API call points obtained in step (2);
[0042] (6-2) Based on the backflow analysis results in step (2-2b), determine the WebAssembly function export point in the JavaScript program dependency graph, and replace the subgraph with the function export point as the root node with the corresponding WebAssembly program dependency graph.
[0043] (6-3) Based on the backward data flow analysis results in step (2-2c), determine the import point of the WebAssembly function in the JavaScript program, add the corresponding data dependency relationship to the newly generated program dependency graph, and finally restore the semantics of the WebAssembly program to the original JavaScript program.
[0044] Secondly, the present invention provides a web malware detection system based on cross-language semantic analysis, comprising:
[0045] The JavaScript code static dependency analysis module is used to obtain the JavaScript code of the program under test, generate a JavaScript program dependency graph, and filter cross-language interactive API call points in the JavaScript program dependency graph according to predefined function tags, and extract parameters and dependencies through data flow relationships.
[0046] The WebAssembly code static analysis module is used to determine the parameter type based on the parameters and dependencies obtained from the JavaScript code static dependency analysis module, decode the WebAssembly binary format program content of the program under test partition by partition, extract the metadata of each partition, convert the metadata of each partition into a list data structure, perform fine-grained analysis of the WebAssembly partition code, construct the WebAssembly abstract syntax tree for each code instruction, and track the control flow dependencies and data flow dependencies in the WebAssembly program.
[0047] Furthermore, based on the WebAssembly abstract syntax tree, the control flow dependencies and data flow dependencies in the WebAssembly program, a WebAssembly program dependency graph is constructed using ES6 syntax rules;
[0048] The semantic restoration module based on cross-language interaction information is used to embed the WebAssembly program dependency graph into the cross-language interaction API call point of the JavaScript program dependency graph, and to complete the cross-language control flow and data flow dependencies between the two parts of the dependency graph according to the parameters and dependencies of the cross-language interaction API call point, restore the semantics of the WebAssembly program to the original JavaScript program, and perform web malware detection on the restored JavaScript program.
[0049] Compared with the prior art, the beneficial effects of the present invention are as follows:
[0050] (1) When attackers call the WebAssembly module in a JavaScript program to build cross-language web malware, existing technologies, which only focus on the JavaScript part of the program information, cannot capture cross-language malicious behavior. To address this problem, this invention designs a cross-language static program analysis method that can simultaneously capture both single-language and cross-language program dependencies to assist in malware identification, and has higher accuracy and analytical robustness.
[0051] (2) This invention considers the hidden data stream dependencies introduced by ES6 asynchronous syntax for the first time in the static program dependency analysis of JavaScript code, which can effectively make up for the missing information in the data stream analysis process of existing tools.
[0052] (3) The malware identification system described in this invention has a highly modular feature. It provides static analysis modules for both mainstream Web languages, and the static analysis modules have high portability and can be flexibly adapted to new language specifications in future version iterations.
[0053] (4) The semantic restoration module provided by this invention has high compatibility. Existing JavaScript malware detection tools only need to add interface code to be compatible with this method, realizing cross-language malware identification function without modifying the core algorithm. Attached Figure Description
[0054] Figure 1 This is a schematic diagram of the architecture of the Web malware detection method based on cross-language semantic analysis of the present invention;
[0055] Figure 2 A flowchart illustrating the process of constructing a dependency graph in static dependency analysis of JavaScript code;
[0056] Figure 3 A flowchart illustrating the static program analysis process for WebAssembly code;
[0057] Figure 4 This is a flowchart illustrating the process of semantic reconstruction of a program based on cross-language interactive information. Detailed Implementation
[0058] The present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be noted that the embodiments described below are intended to facilitate the understanding of the present invention and do not limit it in any way.
[0059] like Figure 1As shown, the Web malware detection method based on cross-language semantic analysis of the present invention includes static program dependency analysis of JavaScript code, static program analysis of WebAssembly code, and program semantic restoration based on cross-language interaction information. The static program dependency analysis of JavaScript code includes constructing a JavaScript program dependency graph (PDG) and extracting cross-language interaction APIs from the JavaScript program dependency graph. The static program analysis of WebAssembly code includes parsing the WebAssembly binary program, extracting the WebAssembly abstract syntax tree, and constructing WebAssembly program dependencies. The program semantic restoration based on cross-language interaction information uses the first two parts of information to locate the embedding point, embedding the WebAssembly program dependency graph into the JavaScript program dependency graph to achieve semantic restoration.
[0060] The construction of a JavaScript program dependency graph includes: the user provides the JavaScript code of the program to be tested; the JavaScript code is parsed into an abstract syntax tree according to ECMA syntax rules; the JSON-formatted abstract syntax tree is then converted into a tree-like data structure; the JavaScript program control flow graph and data flow graph are generated in sequence; and finally, they are integrated into a JavaScript program dependency graph.
[0061] Extracting cross-language interaction APIs from the JavaScript program dependency graph includes: analyzing the JavaScript program dependency graph, traversing the program dependency graph to scan node function names, filtering cross-language interaction API call points in the program dependency graph according to the WebAssembly official documentation, extracting parameters and dependencies through data flow relationships, and outputting them to the next analysis stage.
[0062] WebAssembly binary program parsing includes: reading in the parameters and dependencies obtained from the cross-language interaction API extraction phase of the JavaScript program dependency graph, and determining the parameter type; if the corresponding parameter is in WebAssembly binary format, then the binary program is decoded, WebAssembly partitions are decoded one by one in sequence, and the parsed metadata is input into the next analysis phase.
[0063] WebAssembly abstract syntax tree extraction includes: reading in the metadata output from the previous stage's WebAssembly binary program parsing, converting each partition's metadata into a list-based data structure; then performing fine-grained analysis on the WebAssembly function partition code, traversing code instructions and constructing an abstract syntax tree; simultaneously simulating the WebAssembly stack virtual machine, tracing the control flow and data flow dependencies in the WebAssembly program, and outputting the results to the next stage.
[0064] WebAssembly program dependency construction includes: reading in the WebAssembly abstract syntax tree (API) output from the extraction phase, extracting the API, control flow dependencies, and data flow dependencies, and integrating these three parts into a JavaScript program dependency based on ECMA syntax rules. Figure 1 A unified format is used to output the WebAssembly application dependency graph to the next stage.
[0065] The program semantic restoration based on cross-language interaction information includes: reading in the JavaScript program dependency graph, WebAssembly program dependency graph, and cross-language interaction API call points output from the above stages; embedding the WebAssembly program dependency graph into the JavaScript program dependency graph call points; and further supplementing the cross-language control flow and data flow dependencies between the two dependency graphs based on the parameters and dependencies of the cross-language interaction API call points to restore the program semantics.
[0066] Figure 1 The static program dependency analysis module for JavaScript code includes two steps:
[0067] (1.a) JavaScript Static Analysis: This step generates a dependency graph of the JavaScript portion of the program under test. This dependency graph serves as the raw input for subsequent analysis modules and is ultimately restored to the reconstructed JavaScript dependency graph.
[0068] (1.b) Cross-language interaction extraction: This step takes the JavaScript program dependency graph as input, filters out and marks the API nodes related to cross-language interaction according to the predefined function labels, and uses them for cross-language program dependency tracking in subsequent semantic reconstruction.
[0069] like Figure 2As shown, the process of constructing a JavaScript program dependency graph through static analysis is as follows: Initially, the user sets up a suitable version of Node.js and Python environment according to their actual needs and provides the source code of the program to be tested. First, the JavaScript static analysis program reads the source code of the program to be tested. Then, based on the ES6 syntax file, it uses the Esprima library to parse the JavaScript code into an abstract syntax tree. After successful parsing, a program control flow graph is constructed based on the node types and adjacency relationships of the abstract syntax tree. Furthermore, based on the program control flow graph, the data flow relationships between functions and variables are constructed, finally outputting the program dependency graph.
[0070] Extracting cross-language interaction APIs from the JavaScript program dependency graph includes: analyzing the JavaScript program dependency graph, traversing the program dependency graph to scan node function names, filtering cross-language interaction API call points in the program dependency graph according to the official WebAssembly documentation, and extracting parameters and dependencies through data flow relationships, which are then output to the next analysis stage.
[0071] (2-1) Depth-first traversal of the program dependency graph of the JavaScript program. During the traversal, when the node type is a function call, determine whether the function name belongs to the cross-language interaction API provided in the WebAssembly official documentation. If it does not belong, there is no need to record it. Otherwise, record the function call, parameters and return value, and output it to the next step.
[0072] (2-2) Analyze the cross-language interaction API call points obtained in step (2-1) one by one, and process them according to different API function types.
[0073] In one specific embodiment of the present invention, step (2-2) involves processing different function types accordingly, including:
[0074] (2-2a) If the function type is WebAssembly.Module or WebAssembly.Instantiate, it means that the parameter type is WebAssembly binary format. This parameter is passed to the next stage as input for the WebAssembly binary program parsing.
[0075] (2-2b) If the function type is WebAssembly.Instantiate or WebAssembly.Instance, it means that the function returns a WebAssembly Instance type variable. This type variable can derive WebAssembly functions. Therefore, it is necessary to perform backward data flow analysis on the return value to supplement the data flow from WebAssembly to the JavaScript module.
[0076] (2-2c) If the function type is WebAssembly.Table, WebAssembly.Memory, or WebAssembly.Global, it means that the function returns a WebAssembly element. This type of variable can be imported into the WebAssembly module. Therefore, it is necessary to perform backward data flow analysis on the return value to supplement the data flow from JavaScript to the WebAssembly module.
[0077] The static program analysis process of WebAssembly code is as follows: Figure 3 As shown:
[0078] The process reads in the WebAssembly binary stream obtained from the cross-language interaction API extraction phase of the JavaScript program dependency graph, decodes each WebAssembly section sequentially, and outputs section metadata. Based on the section metadata, it converts each section metadata into a list data structure and constructs an abstract syntax tree based on the code sections. Finally, it tracks the control flow and data flow dependencies in the WebAssembly program and integrates the WebAssembly abstract syntax tree, control flow dependencies, and data flow dependencies into a program dependency graph that conforms to the JavaScript syntax standard based on ES6 syntax rules.
[0079] Specifically, static program analysis of WebAssembly code includes WebAssembly binary program parsing, WebAssembly abstract syntax tree extraction, and WebAssembly program dependency construction; the specific steps of WebAssembly binary program parsing include:
[0080] (3-1) Determine the parameter type based on the parameters and dependencies obtained in step (2). For WebAssembly binary type parameters, use the parsing function to parse the WebAssembly binary program content partition by partition. If the parsing fails, terminate the subsequent analysis process, issue an alarm and request manual processing.
[0081] (3-2) If the parsing is successful, the metadata is stored and output to the next stage according to the partition type; specifically, the WebAssembly partition types include custom section, type section, import section, function section, table section, memory section, global section, export section, start section, element section, code section, data section, and data count section; the binary data of the above partitions is parsed into readable metadata and output to the next stage.
[0082] The specific steps for extracting the WebAssembly abstract syntax tree include:
[0083] (4-1) Read in the metadata output by the WebAssembly binary program in the previous stage and convert it into a list data structure. Specifically, execute the analysis logic according to different partition types: if the partition type is not code, store the metadata corresponding to the partition type in the list as auxiliary data for code partition analysis; if the partition type is code, proceed to the next step.
[0084] (4-2) Perform fine-grained analysis on the WebAssembly function partition code and construct an abstract syntax tree instruction by instruction; at the same time, simulate the WebAssembly stack virtual machine, trace the control flow and data flow dependencies in the WebAssembly program, and output the final result to the next stage.
[0085] In one specific embodiment of the present invention, step (4-2) involves performing fine-grained analysis of the WebAssembly function partition code and constructing an abstract syntax tree instruction by instruction, including:
[0086] (4-2a) If the code instruction references a global type variable, the global type list stored in step (4-1) is read, and push / pop operations are performed on the relevant parameters. Similarly, if the code instruction references a local type variable, the local type list stored in step (4-1) is read, and push / pop operations are performed on the relevant parameters.
[0087] (4-2b) If the code instruction is a control flow block-level instruction, a new program node is created for the block-level instruction, and step (4-2) is repeated for the lower-level instructions belonging to the block-level instruction, and the block-level instruction type is recorded.
[0088] (4-2c) If the instruction is a numeric variable type, first determine the number of parameters pushed onto the stack and the number of parameters popped from the stack corresponding to the instruction. Based on the analysis results, simulate the parameter push and pop process, and then construct the control flow dependency and data flow dependency between instructions.
[0089] The specific steps for building WebAssembly application dependencies include:
[0090] (5-1) Read in the WebAssembly abstract syntax tree, the control flow dependencies and data flow dependencies in the WebAssembly program.
[0091] (5-2) Based on ECMA syntax, the WebAssembly abstract syntax tree is converted into a program dependency graph consistent with JavaScript syntax rules layer by layer. The collected control flow dependencies and data flow dependencies are then added to the WebAssembly program dependency graph in turn. Finally, a complete WebAssembly program dependency graph is constructed and output to the next stage.
[0092] The process of program semantic restoration based on cross-language interactive information, such as Figure 4 As shown:
[0093] First, the JavaScript program dependency graph and the WebAssembly program dependency graph are read in, and the semantic restoration of program execution is analyzed. Then, based on predefined rules and data flow dependencies in the JavaScript program dependency graph, the cross-language interaction API call points in the JavaScript program dependency graph are determined, and the WebAssembly program dependency graph is embedded at the above locations. Finally, the corresponding data dependencies are added to the newly generated program dependency graph, ultimately restoring the WebAssembly program semantics to the original JavaScript program.
[0094] Users can use malicious JavaScript detection methods such as JStap to directly detect the semantically restored JavaScript. Users can also make the restored results compatible with other malicious JavaScript detection methods by making simple format adjustments.
[0095] Based on the same inventive concept, the embodiments also propose a web malware detection system based on cross-language semantic analysis, including a JavaScript code static program dependency analysis module, a WebAssembly code static program analysis module, and a program semantic restoration module based on cross-language interaction information.
[0096] The JavaScript code static dependency analysis module performs static analysis on the JavaScript portion of cross-language web applications, effectively constructing a JavaScript program dependency graph. Its output is fed into the WebAssembly code static analysis module, providing cross-language interactive information. Notably, this module can run independently of the entire system, and its output dependency graph can perform various web application analysis tasks. Compared to previous work, this module is the first to consider the asynchronous function features introduced by ECMA6 syntax, enabling it to capture a more complete program flow.
[0097] WebAssembly code static analysis module: This module is used to perform static analysis on the WebAssembly part of a cross-language web application. The module statically captures the semantics of the WebAssembly application and constructs the corresponding WebAssembly application dependency graph, which is then output to the semantic restoration module.
[0098] The semantic restoration module based on cross-language interaction information: This module receives input from the first two modules, embeds the WebAssembly program dependency graph into the JavaScript program dependency graph according to the cross-language interaction information, and supplements the cross-language control flow and data flow dependencies to achieve semantic restoration.
[0099] For the system embodiments, since they basically correspond to the method embodiments, relevant details can be found in the descriptions of the method embodiments; the implementation methods of the remaining modules will not be repeated here. The system embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of the present invention according to actual needs. Those skilled in the art can understand and implement this without any creative effort.
[0100] The system embodiments of the present invention can be applied to any device with data processing capabilities, such as a computer or other similar device. The system embodiments can be implemented in software, hardware, or a combination of both. Taking software implementation as an example, as a logical device, it is formed by the processor of any data processing device loading the corresponding computer program instructions from non-volatile memory into memory for execution.
[0101] The embodiments described above provide a detailed explanation of the technical solutions and beneficial effects of the present invention. It should be understood that the above descriptions are merely specific embodiments of the present invention and are not intended to limit the present invention. Any modifications, additions, and equivalent substitutions made within the scope of the principles of the present invention should be included within the protection scope of the present invention.
Claims
1. A method for detecting web malware based on cross-language semantic analysis, characterized in that, Includes the following steps: (1) Obtain the JavaScript code of the program under test and generate a JavaScript program dependency graph; (2) Based on the predefined function labels, filter the cross-language interaction API call points in the JavaScript program dependency graph, and extract the parameters and dependencies through data flow relationships; (3) Determine the parameter type based on the parameters and dependencies obtained in step (2), decode the WebAssembly binary format program content of the program under test partition by partition, and extract the metadata of each partition. (4) Convert the metadata of each partition into a list data structure, perform fine-grained analysis of the WebAssembly partition code, construct the WebAssembly abstract syntax tree for each code instruction, and trace the control flow dependency and data flow dependency in the WebAssembly program; (5) Based on the WebAssembly abstract syntax tree, the control flow dependency relationship and data flow dependency relationship in the WebAssembly program, construct the WebAssembly program dependency graph based on ES6 syntax rules; (6) Embed the WebAssembly program dependency graph into the cross-language interactive API call point of the JavaScript program dependency graph, and fill in the cross-language control flow and data flow dependencies between the two parts of the dependency graph according to the parameters and dependencies of the cross-language interactive API call point. Restore the WebAssembly program semantics to the original JavaScript program, and perform Web malware detection on the restored JavaScript program.
2. The web malware detection method based on cross-language semantic analysis according to claim 1, characterized in that, Step (1) includes: (1-1) Obtain the JavaScript code of the program to be tested provided by the user; (1-2) Based on ES6 syntax rules, the JavaScript code is parsed into an abstract syntax tree. If the parsing is incorrect, the process will terminate, an alert will be issued and manual processing will be requested. If the parsing is successful, proceed to step (1-3). (1-3) Transform the JSON-formatted abstract syntax tree into a tree-like data structure, add control flow dependencies between syntax nodes, and output the JavaScript program control flow graph; (1-4) Traverse the JavaScript program control flow graph according to the depth-first rule, record the data flow dependencies between functions and variables in the program under test, and expand the JavaScript program control flow graph into a JavaScript program dependency graph.
3. The Web malware detection method based on cross-language semantic analysis according to claim 1, characterized in that, Step (2) includes: (2-1) Depth-first traversal of the JavaScript program dependency graph. During the traversal, when the node type is a function call, determine whether the function name belongs to the cross-language interaction API provided in the WebAssembly official documentation. If it does not belong to the cross-language interaction API, there is no need to record it. Otherwise, record the function call, parameters and return value to filter out the cross-language interaction API call points in the JavaScript program dependency graph. (2-2) Analyze the cross-language interaction API call points obtained in step (2-1) one by one, process them according to different API function types, and obtain parameters and dependencies.
4. The Web malware detection method based on cross-language semantic analysis according to claim 3, characterized in that, Step (2-2) includes: (2-2a) If the function type is WebAssembly.Module or WebAssembly.Instantiate, it means that the parameter type is WebAssembly binary format. Pass the parameter to the next stage for WebAssembly binary program parsing. (2-2b) If the function type is WebAssembly.Instantiate or WebAssembly.Instance, it means that the function returns a WebAssembly.Instance type variable, which can derive WebAssembly functions. Therefore, it is necessary to perform backward data flow analysis on the return value to supplement the data flow from WebAssembly to the JavaScript module. (2-2c) If the function type is WebAssembly.Table, WebAssembly.Memory, or WebAssembly.Global, it means that the function returns a WebAssembly.element type variable, which can be imported into the WebAssembly module. Therefore, it is necessary to perform backward data flow analysis on the return value to supplement the data flow from JavaScript to the WebAssembly module.
5. The Web malware detection method based on cross-language semantic analysis according to claim 1, characterized in that, Step (3) includes: (3-1) Determine the parameter type based on the parameters and dependencies obtained in step (2). For WebAssembly binary type parameters, use the parsing function to parse the WebAssembly binary program content partition by partition. If the parsing fails, terminate, issue an alarm and request manual processing. If the parsing is successful, proceed to step (3-2). (3-2) Store the parsed readable metadata according to the WebAssembly partition type, which includes custom section, type section, import section, function section, table section, memory section, global section, export section, start section, element section, code section, data section and data count section.
6. The Web malware detection method based on cross-language semantic analysis according to claim 4, characterized in that, Step (4) includes: (4-1) Determine the partition type. If the partition type is not code, store the corresponding partition metadata as auxiliary data in a list and convert each partition metadata into a list data structure. If the partition type is code, proceed to step (4-2). (4-2) Perform fine-grained analysis on the WebAssembly partition code, construct an abstract syntax tree for each code instruction, and simulate the WebAssembly stack virtual machine to trace the control flow dependencies and data flow dependencies in the WebAssembly program.
7. The Web malware detection method based on cross-language semantic analysis according to claim 6, characterized in that, Step (4-2) includes: (4-2a) If the code instruction references a global type variable, then read the global type list stored in step (4-1) and perform push and pop operations on the relevant parameters; similarly, if the code instruction references a local type variable, then read the local type list stored in step (4-1) and perform push and pop operations on the relevant parameters. (4-2b) If the code instruction is a control flow block-level instruction, a new program node is created for the block-level instruction, and step (4-2) is repeated for the lower-level instructions belonging to the block-level instruction, and the block-level instruction type is recorded. (4-2c) If the code instruction is a numeric variable type, first determine the number of parameters pushed onto the stack and the number of parameters popped from the stack corresponding to the instruction. Based on the analysis results, simulate the parameter push and pop process, and then construct the control flow dependency and data flow dependency between instructions.
8. The Web malware detection method based on cross-language semantic analysis according to claim 1, characterized in that, Step (5) includes: (5-1) Obtain the WebAssembly abstract syntax tree, control flow dependencies, and data flow dependencies in the WebAssembly program obtained in step (4); (5-2) Based on the ES6 syntax rules, the WebAssembly abstract syntax tree is converted into a program dependency graph consistent with the JavaScript syntax rules layer by layer, and the control flow dependency relationship and data flow dependency relationship are added to the program dependency graph in turn to construct a complete WebAssembly program dependency graph.
9. A web malware detection method based on cross-language semantic analysis according to claim 4, characterized in that, Step (6) includes: (6-1) Obtain the JavaScript program dependency graph obtained in step (1), the WebAssembly program dependency graph obtained in step (5), and the cross-language interaction API call point obtained in step (2); (6-2) Based on the backflow analysis results in step (2-2b), determine the WebAssembly function export point in the JavaScript program dependency graph, and replace the subgraph with the function export point as the root node with the corresponding WebAssembly program dependency graph. (6-3) Based on the backward data flow analysis results in step (2-2c), determine the import point of the WebAssembly function in the JavaScript program, add the corresponding data dependency relationship to the newly generated program dependency graph, and finally restore the semantics of the WebAssembly program to the original JavaScript program.
10. A web malware detection system based on cross-language semantic analysis, characterized in that, include: The JavaScript code static dependency analysis module is used to obtain the JavaScript code of the program under test and generate a JavaScript program dependency graph. Additionally, based on predefined function labels, cross-language interactive API call points in the JavaScript program dependency graph are filtered, and parameters and dependencies are extracted through data flow relationships; The WebAssembly code static analysis module is used to determine the parameter type based on the parameters and dependencies obtained from the JavaScript code static dependency analysis module, decode the WebAssembly binary format program content of the program under test partition by partition, extract the metadata of each partition, convert the metadata of each partition into a list data structure, perform fine-grained analysis of the WebAssembly partition code, construct the WebAssembly abstract syntax tree for each code instruction, and track the control flow dependencies and data flow dependencies in the WebAssembly program. Furthermore, based on the WebAssembly abstract syntax tree, the control flow dependencies and data flow dependencies in the WebAssembly program, a WebAssembly program dependency graph is constructed using ES6 syntax rules; The semantic restoration module based on cross-language interaction information is used to embed the WebAssembly program dependency graph into the cross-language interaction API call point of the JavaScript program dependency graph, and to complete the cross-language control flow and data flow dependencies between the two parts of the dependency graph according to the parameters and dependencies of the cross-language interaction API call point, restore the semantics of the WebAssembly program to the original JavaScript program, and perform web malware detection on the restored JavaScript program.
Citation Information
Patent Citations
Code homology detection method based on code fingerprint and device thereof
CN107169358A
Method for detecting attack by using WebAssembly
CN115473744A