IPSec Protocol State Change Identification Method Based on def-use Data Dependence Graph

Through the method based on the def-use data dependency graph, the binary program of the IPSec protocol is statically analyzed to identify protocol state changes, solving the problem of low efficiency of relying on manual analysis and testing in the existing technology, and achieving efficient and fine-grained protocol state change identification.

CN116566866BActive Publication Date: 2025-07-22Chinese People's Liberation Army Cyberspace Force Information Engineering University
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310548078.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-05-15
Publication Date
2025-07-22
Estimated Expiration
2043-05-15

AI Technical Summary

Technical Problem

The existing IPSec protocol state extraction method relies on manual analysis, insufficient penetration depth and low efficiency of tests, especially in fuzzy testing, it is difficult to effectively identify the working state of the protocol.

Method used

Using a method based on the def-use data dependency graph, the binary program of the IPSec protocol is rewritten instrumentation, and a pointer function dictionary and a def-use data dependency graph are generated to identify the location of the protocol state change operation.

Benefits of technology

No manual analysis is required, and it supports open source and closed source program analysis, which reduces memory and CPU overhead, improves testing efficiency and penetration depth, supports offline identification, is not affected by network communication delays, and can seamlessly integrate with existing fuzz testing platforms.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116566866B_ABST
    Figure CN116566866B_ABST
Patent Text Reader

Abstract

The present invention provides a method for identifying the state change of the IPSec protocol based on the def-use data dependence graph. The method includes: Step 1: Obtain the target binary program implementing the IPSec protocol; Step 2: Rewrite and instrument the target binary program to achieve the identification and positioning of basic blocks; Step 3: Scan the rewritten and instrumented target binary program to obtain all function pointer indirect call instructions, and generate a pointer function dictionary containing the location indexes of all function pointer indirect call instructions; Step 4: Traverse all functions in the target binary program to generate corresponding def-use data dependence graphs for each function; Step 5: Traverse all structure variable assignment instructions in the target binary program, and identify the location of the code where the protocol state change operation is located according to the def-use data dependence graph of the function where each assignment instruction is located and the pointer function dictionary.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular to a method for identifying the state change of the IPSec protocol based on the def-use data dependence graph. Background Art

[0002] IPSec (Internet Protocol Security) is a widely used technology in VPN (Virtual Private Network). It provides high-quality, interoperable, and cryptography-based security for IP datagrams, thereby achieving secure communication in the insecure Internet channel. Due to the requirements of different application scenarios, IPSec has different specific implementations, including open-source software such as StrongSwan, OpenSwan, LibreSwan, and closed-source products of many manufacturers such as Cisco and Juniper, and can run in multi-type device environments such as hosts, servers, routers, and firewall gateways.

[0003] IPSec is a protocol family composed of a series of sub-protocols such as IKE, AH, ESP, and IPSec DOI, which defines a set of complex protocol state transition relationships to achieve many security features such as IP packet data integrity detection, encryption protection, and authentication. For example, IKE is responsible for negotiating encryption keys and authentication keys to protect private data; the AH protocol provides data integrity verification but does not provide encryption services. The security of the design and implementation of these sub-protocols themselves is the cornerstone of the security of the entire IPSec VPN system. Therefore, researching the security of the IPSec protocol and exploring potential security vulnerabilities in the protocol is of great significance.

[0004] Currently, fuzz testing technology is the mainstream technology for IPSec protocol security testing and analysis. One of the major technical challenges it faces is how to effectively identify the working state of the IPSec protocol and provide feedback guidance, so as to improve the penetration depth of the protocol and the efficiency of fuzz testing.

[0005] There are mainly three categories of existing protocol state extraction methods. One category is the method based on pattern generation, such as Peach, BooFuzz, SPFuzz, PavFuzz, etc. By manually reading and analyzing the protocol specification documents, custom patterns (such as xml) are used to describe the message format and state transition relationships, and test cases are generated independently. Its limitation is that it relies on a large amount of expert knowledge and manual analysis, and the differences in the implementation details of different protocols lead to inaccurate description of the protocol state model. The second category is the method based on inference learning, such as AFLnet, SnapFuzz, SNPSFuzzer, ICS3Fuzzer, DTLS-Fuzzer, etc. Based on network traffic packet capture, active and passive learning methods are adopted to infer the protocol state change information from the interaction data. Its limitation is that in the black box testing mode, the penetration depth of protocol testing is insufficient, and at the same time, it relies on communication I / O data, and the network communication delay severely limits the test throughput. The third category is the method based on runtime information extraction, such as FirmHunter, StateAFL, StateInspector, etc. By means of runtime dynamic instrumentation or snapshot, context data such as memory, I / O, and registers are analyzed to obtain the protocol state change information. Its limitation is that runtime dynamic instrumentation increases the memory and CPU overhead and reduces the test efficiency. Summary of the Invention

[0006] To solve the problems existing in the existing protocol state extraction methods, such as relying on manual analysis, insufficient penetration depth of protocol testing, and low test efficiency, the present invention provides an IPsec protocol state change identification method based on the def-use data dependence graph.

[0007] The present invention provides an IPsec protocol state change identification method based on the def-use data dependence graph, including:

[0008] Step 1: Obtain the target binary program implementing the IPsec protocol;

[0009] Step 2: Rewrite and instrument the target binary program to achieve the identification and positioning of basic blocks;

[0010] Step 3: Scan the rewritten and instrumented target binary program to obtain all function pointer indirect call instructions, and generate a pointer function dictionary containing the location indexes of all function pointer indirect call instructions;

[0011] Step 4: Traverse all functions in the target binary program, and generate a corresponding def-use data dependence graph for each function;

[0012] Step 5: Traverse all the structure variable assignment instructions in the target binary program, and identify the location of the code where the protocol state change operation is located according to the def-use data dependence graph of the function where each assignment instruction is located and the pointer function dictionary.

[0013] Further, it is characterized in that step 2 specifically includes:

[0014] Disassemble the target binary program and generate intermediate language;

[0015] Based on the intermediate language, use a binary rewriting tool to insert a global shared array and a global integer variable in the data segment of the target binary program, and insert two characteristic instructions at the start position of each basic block in the code segment; one of the characteristic instructions is used to generate a random number for the basic block where it is located, and use this random number as the subscript to perform a counting operation on the global shared array to identify the basic block, and the other characteristic instruction assigns a magic number to the global integer variable to achieve basic block positioning.

[0016] Further, step 3 specifically includes:

[0017] Use a disassembler to disassemble the rewritten and instrumented target binary program to obtain assembly code;

[0018] Based on the assembly code, perform a full-space scan on the code segment, and search forward for an instruction statement with a preset feature as a function pointer indirect call instruction; among them, the instruction statement with a preset feature is " call[base+func_ offset] " type, base represents the address of the structure variable, func_offset represents the function pointer offset;

[0019] For each function pointer indirect call instruction, starting from its location, search backward and extract the random number corresponding to the basic block where the function pointer indirect call instruction is located, form a binary tuple information with the random number and the location where the function pointer indirect call instruction is located, and store the binary tuple information in the pointer function dictionary with the function pointer offset func_offset as the key value.

[0020] Further, in step 4, use the miasm plugin through IDAPython to traverse all functions in the target binary program and generate a def-use data dependence graph in units of functions.

[0021] Further, step 5 specifically includes:

[0022] Use the instruction statement that meets the preset constraint conditions as the structure variable assignment instruction, and the preset constraint conditions include: the instruction statement is " mov [base+dst_offset],src_value” type, and the destination operand [base+dst_ offset] in base the address value attribute is a memory address, dst_offset the value is a non-zero immediate number, and the source operand src_ value the value is an immediate number or the value is passed from an immediate number, and there is a structure variable referenced by [base+dst_ offset] as the address in the program control flow;

[0023] Judge the source operand src_value which mode among the three modes of initial definition inside the function, direct function call parameter passing, and indirect function pointer call parameter passing the value type belongs to;

[0024] According to the mode to which the value type of the source operand src_value belongs, adopt the corresponding identification method to identify the position of the code where the protocol state change operation is located.

[0025] Furthermore, the above-mentioned according to the mode to which the value type of the source operand src_value belongs, adopt the corresponding identification method to identify the position of the code where the protocol state change operation is located, specifically including:

[0026] Step A1: For the initial definition mode inside the function, continue to judge src_value the value type: if the value is an immediate number, directly record the position of this assignment instruction in the format of <basic block identifier, state variable offset, state value immediate number, assignment type, function name where it is located>, which is the position of the code where the protocol state change operation is located; if the value is passed from an immediate number, in the function code area, according to the def-use data dependence graph of the corresponding function, traverse all paths, starting from the position where this assignment instruction is located, trace back src_value the value passing process of, until the position where the initial value of the immediate number is defined is traced, then record the position where the initial value of this immediate number is defined in the format of <basic block identifier, state variable offset, state value immediate number, assignment type, function name where it is located>, which is the position of the code where the protocol state change operation is located;

[0027] Step A2: For the direct function call parameter passing mode, obtain the code cross-reference list of the function where this assignment instruction is located, traverse each call point code position in this code cross-reference list, enter the corresponding called function code space, and then go to Step A1 to process according to the initial definition mode inside the function;

[0028] Step A3: For the indirect function pointer call parameter passing mode, obtain the data cross-reference table of the function where this assignment instruction is located, locate to the data reference code position in this data cross-reference table, and search forward for " lea reg,fun_offset;mov [base+func_offset],reg "Two associated instructions are used func_offset as the key value to query the pointer function dictionary to obtain func_offset the code positions of all the corresponding function pointer indirect call instructions, and enter the code space of each function pointer indirect call instruction one by one for traversal and go to step A1 for processing according to the initial definition mode inside the function.

[0029] Advantages of the present invention:

[0030] (1) By obtaining the binary programs of different specific implementations of the IPSec protocol, the present invention performs static reverse analysis based on the binary programs to identify the protocol state change information therefrom; based on this design concept, on the one hand, the analysis is directly performed on the binary programs without the need to describe the protocol state model for different protocol implementation details, so there is no need to rely on a large amount of expert knowledge and manual analysis; on the other hand, performing static analysis on the binary programs instead of dynamic instrumentation reduces the overhead and improves the test efficiency.

[0031] (2) When obtaining the binary programs, if it is an open-source product, the binary program can be directly generated by compiling and linking the open-source source code. If it is a closed-source product, the binary program can be obtained by decompressing and extracting the closed-source product firmware; therefore, the present invention supports the analysis of open-source and closed-source programs.

[0032] (3) Since the present invention realizes the identification of IPSec protocol state changes based on the def-use data dependence graph, in theory, it supports the identification of all internal sub-states of the protocol, provides fine-grained state change information feedback, and improves the penetration depth of protocol testing.

[0033] (4) The present invention uses the binary programs of the IPSec protocol implementation to identify the protocol state changes, and the acquisition of the binary programs does not depend on network communication interaction. Therefore, the present invention supports the provision of offline IPSec protocol state change identification without being restricted by network communication latency.

[0034] (5) The present invention does not additionally increase the program burden and can be seamlessly combined with the existing mainstream network protocol fuzz testing platform, improving the fuzz testing efficiency of stateful protocols. BRIEF DESCRIPTION OF THE DRAWINGS

[0035] Figure 1 is one of the flowcharts of the method for identifying IPSec protocol state changes based on the def-use data dependence graph provided by an embodiment of the present invention;

[0036] Figure 2 is another flowchart of the method for identifying IPSec protocol state changes based on the def-use data dependence graph provided by an embodiment of the present invention;

[0037] Figure 3 It is a schematic diagram of static instrumentation of the target binary program provided by an embodiment of the present invention;

[0038] Figure 4 It is a schematic diagram of the function-level def-use data dependence graph provided by an embodiment of the present invention;

[0039] Figure 5 It is a schematic illustration of the initial definition mode assignment instruction inside a function provided by an embodiment of the present invention;

[0040] Figure 6 It is a schematic illustration of the direct call parameter passing mode assignment instruction of a function provided by an embodiment of the present invention;

[0041] Figure 7 It is a schematic illustration of the function pointer indirect call parameter passing mode assignment instruction provided by an embodiment of the present invention. Detailed implementation manners

[0042] To make the objectives, technical solutions and advantages of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are some but not all of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0043] Embodiment 1

[0044] As Figure 1 shown, an embodiment of the present invention provides an IPSec protocol state change identification method based on a def-use data dependence graph, including the following steps:

[0045] S101: Obtain a target binary program implementing the IPSec protocol;

[0046] Specifically, since the specific implementation of the IPSec protocol exists in the form of open-source products and closed-source products, when it is in the form of an open-source product, a binary program can be generated by compiling and linking the open-source code of the open-source product, which is the target binary program; when it is in the form of a closed-source product, a binary program can be obtained by decompressing and extracting the closed-source product firmware, which is the target binary program.

[0047] It should be noted that due to the difference in instruction sets, only the specific manifestation forms of the characteristic instructions are different, and the analysis principle of the target binary program is the same. Therefore, the embodiments of the present invention support target binary programs of different processor architecture types, and the mainstream ones include three instruction set program forms: Intel x86_64-bit, ARM aarch64-bit, and MIPS 64-bit.

[0048] S102: Rewrite and instrument the target binary program to identify and locate basic blocks;

[0049] S103: Scan the rewritten and instrumented target binary program to obtain all function pointer indirect call instructions, and generate a pointer function dictionary containing the location indexes of all function pointer indirect call instructions;

[0050] S104: Traverse all functions in the target binary program, and generate a corresponding def-use data dependence graph for each function;

[0051] Specifically, use the def-use data dependence graph to depict the data flow information of internal variables of a function, and establish the path relationship between data value definitions and data value uses.

[0052] Among them, data value definitions occur at positions such as variable initialization, assignment, or receiving parameter passing; data value uses occur at positions such as conditional branches and function call parameter passing. As Figure 4 shown, each node in the figure represents a data value definition of a variable, and the edges between nodes represent the transfer of data values between different variables. Therefore, given the use position of a variable, the initial defined value of the variable can be traced back. By generating a def-use data dependence graph for each function, it is convenient to locate the position of the code where the protocol state change operation is located later. In this embodiment, the def-use data dependence graph is stored in a file named after the function name in dot format.

[0053] S105: Traverse all structure variable assignment instructions in the target binary program, and identify the position of the code where the protocol state change operation is located according to the def-use data dependence graph of the function where each assignment instruction is located and the pointer function dictionary.

[0054] Specifically, to standardize the development, expansion, and popularization of IPSec applications, the IETF (Internet Engineering Task Force) has developed standard tracking specifications and defined state modes, exchange types, payload formats, message parameters, and naming conventions for security-related information; therefore, all IPSec protocol implementations follow the specification conventions during source code programming and development. Based on this, by observing the coding common characteristics in the specific programming practice of the IPSec protocol implementation program, the following characteristics can be found: (1) To achieve communication synchronization between session parties, named constants are usually defined in the enum or define way to represent different protocol states; for example, QUICK_MODE = 32, IKE_SA_INIT = 34, IKE_AUTH = 35. (2) At the source code level, the form of protocol state value change is this->state=new_stateThe form of the assignment operation; (3) At the level of assembly instructions, the form in which the protocol state value changes is mov [base+dst_offset],new_state The form of the assignment operation; among them, different dst_offset represent different state variables (such as key exchange state, task management state), new_state and the numerical type is an immediate constant. From the above content, it can be seen that when a protocol state change operation occurs, there must be a structure variable assignment instruction operation. Therefore, in the embodiments of the present invention, by traversing all the structure variable assignment instructions of the target binary program, the code positions where all the state change operations in the target binary program are located can be obtained.

[0055] The IPSec protocol state change identification method provided by the embodiments of the present invention maps the IPSec protocol state migration change to the program assembly instruction level. By locating the assignment instructions related to the protocol state change, and then according to the data dependence graph of the function where the assignment instruction is located and the pointer function dictionary containing the instruction position index, the basic block position where the protocol state is located and the state value corresponding to the protocol state change can be traced back and extracted.

[0056] Embodiment 2

[0057] Based on the above Embodiment 1, as Figure 2 shown, the present invention also provides an IPSec protocol state change identification method based on the def-use data dependence graph, which mainly includes a preprocessing stage and a scanning and identification stage, and specifically includes the following steps:

[0058] S201: Obtain the target binary program that implements the IPSec protocol;

[0059] S202: Rewrite and instrument the target binary program to implement the identification and positioning of basic blocks; the process of implementing the identification and positioning of basic blocks in this embodiment is specifically as follows:

[0060] Disassemble the target binary program and generate an intermediate language. In this embodiment, LLVM IR is used as the intermediate language;

[0061] Based on the intermediate language, use the mainstream binary rewriting tool Zipr. In the Transformation module of this tool, through the User-specified Transformtions function, add an instrumentation custom transformation, so as to insert a global shared array of unsigned character type SHM_State[] and a global variable of unsigned integer type g_Magic ;

[0062] Also, insert two characteristic instructions at the start position of each basic block in the code segment; one of the characteristic instructions is used to generate a random number for the basic block where it is located, and use this random number as an index to perform a counting operation on the global shared array to identify the basic block, and the other characteristic instruction uses a magic number to assign a value to the global integer variable to achieve basic block positioning. The pseudo-codes of the two characteristic instructions are as follows:

[0063] mov g_Magic=0xbeefbeef,

[0064] add SHM_State[Rand_ID],1

[0065] Among them, 0xbeefbeef in the first instruction is the magic number, which is used for positioning and matching in code search; the second instruction is used for code basic block hit statistics, and the extracted subscript Rand_ID value (random number) can be used as the code basic block identifier; the effect is as Figure 3 shown.

[0066] S203: Scan the rewritten and instrumented target binary program to obtain all function pointer indirect call instructions, and generate a pointer function dictionary containing the location indexes of all function pointer indirect call instructions;

[0067] Specifically, first, use a disassembler to disassemble the rewritten and instrumented target binary program to obtain assembly code; then, based on the assembly code, perform a full-space scan on the code segment, and search forward for instruction statements with preset characteristics as function pointer indirect call instructions; among them, the instruction statements with preset characteristics are of the type " call[base+ func_offset] ", base represents the address of the structure variable, func_offset represents the function pointer offset, that is, the position offset of the function pointer variable in the structure, and different func_offset represent different function pointer variables; then, for each function pointer indirect call instruction, starting from its location (denoted as Instr_Add ), search backward and extract the random number corresponding to the basic block where the function pointer indirect call instruction is located (that is, Rand_ID ), and form a binary tuple information < Rand_ID, Instr_Add > with this random number and the location where the function pointer indirect call instruction is located, and store the binary tuple information < Rand_ ID, Instr_Add > into the pointer function dictionary with the function pointer offset func_offset as the key value.

[0068] It should be noted that at the assembly level, function calls are divided into two types: direct calls and function pointer indirect calls; among them, generally speaking, direct call instructions are in the form of call cs:set_state; The indirect call instruction of the function pointer is in the form of call [base+08h] ; It can be seen that there are obvious differences between the two instruction forms. Therefore, the instruction statements of the type “ call[base+func_ offset] ” can be used as the indirect call instructions of the function pointer.

[0069] S204: Traverse all functions in the target binary program, and generate a corresponding def-use data dependence graph for each function;

[0070] S205: Traverse all structure variable assignment instructions in the target binary program, and identify the location of the code where the protocol state change operation is located according to the def-use data dependence graph of the function where each assignment instruction is located and the pointer function dictionary. Specifically, it includes the following steps:

[0071] Use the instruction statements that meet the preset constraint conditions as the structure variable assignment instructions. The preset constraint conditions include: the instruction statement is of the type “ mov [base+dst_offset],src_value ”, and the destination operand [base+dst_ offset] Among them, base The address value attribute is a memory address, dst_offset The value is a non-zero immediate number, and the source operand src_ value The value is an immediate number or the value is passed from an immediate number, and there is a structure variable referenced by [base+dst_ offset] as the address in the program control flow;

[0072] Judge which mode the value type of the source operand src_value belongs to among the three modes of internal initial definition in the function, direct call parameter passing in the function, and indirect call parameter passing of the function pointer;

[0073] According to the mode to which the value type of the source operand src_value belongs, adopt the corresponding identification method to identify the location of the code where the protocol state change operation is located, specifically as follows:

[0074] Step A1: As Figure 5 shown, for the internal initial definition mode in the function, continue to judge src_value The value type of, and it is divided into the following two situations:

[0075] (1) If the value is an immediate number, directly record the position of the assignment instruction in the format of <basic block identifier, state variable offset, state value immediate number, assignment type, function name where it is located>, which is the position of the code where the protocol state change operation is located;

[0076] (2) If the value is passed from an immediate number, within the function code area, traverse all paths according to the def-use data dependence graph of the corresponding function. Starting from the position where the assignment instruction is located, trace back the value passing process until the position where the initial value of the immediate number is defined is traced. Then record the position where the initial value of the immediate number is defined according to <basic block identifier, state variable offset, state value immediate number, assignment type, function name where it is located>, which is the position of the code where the protocol state change operation is located; src_value The value passed is recorded according to <basic block identifier, state variable offset, state value immediate number, assignment type, function name where it is located>, which is the position of the code where the protocol state change operation is located;

[0077] Step A2: As Figure 6 shown, for the parameter passing mode of direct function call, since the src_ value value in this assignment instruction comes from the parameter passing of the direct function call, cross-function backtracking needs to be performed. At this time, the IDA idautil module Xrefsto function can be used to obtain the code cross-reference list of the function where this assignment instruction is located. Traverse each call point code position in this code cross-reference list, enter the code space of the corresponding called function, and then go to Step A1 to process according to the internal initial definition mode of the function;

[0078] Step A3: As Figure 7 shown, for the parameter passing mode of indirect function pointer call, since the src_value value in this assignment instruction comes from the parameter passing of the indirect function pointer call, cross-function backtracking also needs to be performed. At this time, the IDA idautil module Xrefsto function can be used to obtain the data cross-reference table of the function where this assignment instruction is located. Locate the data reference code position in this data cross-reference table, and search forward lea reg,fun_offset;mov [base+func_offset],reg2 associated instructions, use func_offset as key value, query the pointer function dictionary to obtain func_offset the code positions of all indirect function pointer call instructions corresponding to it, and enter the code space of each indirect function pointer call instruction one by one for traversal and go to Step A1 to process according to the internal initial definition mode of the function to search for the position where the initial value of the immediate number is defined and the state value immediate number.

[0079] Finally, it should be noted that: the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that: they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. An IPSec protocol state change identification method based on a def-use data dependence graph, characterized in that Including: Step 1: Obtain the target binary program implementing the IPSec protocol; Step 2: Rewrite and instrument the target binary program to achieve the identification and location of basic blocks; Step 3: Scan the rewritten and instrumented target binary program to obtain all function pointer indirect call instructions, and generate a pointer function dictionary containing the location indexes of all function pointer indirect call instructions; Step 4: Traverse all functions in the target binary program to generate a corresponding def-use data dependence graph for each function; Step 5: Traverse all structure variable assignment instructions in the target binary program, and identify the location of the code where the protocol state change operation is located according to the def-use data dependence graph of the function where each assignment instruction is located and the pointer function dictionary.

2. The method for identifying the state change of the IPSec protocol based on the def-use data dependence graph according to claim 1, wherein Step 2 specifically includes: Disassemble the target binary program to generate intermediate language; Based on the intermediate language, use a binary rewriting tool to insert a globally shared array and a global integer variable in the data segment of the target binary program, and insert two characteristic instructions at the start position of each basic block in the code segment; one characteristic instruction is used to generate a random number for the basic block where it is located, and use this random number as an index to perform a counting operation on the globally shared array to identify the basic block, and the other characteristic instruction assigns a magic number to the global integer variable to achieve basic block location.

3. The method for identifying the state change of the IPSec protocol based on the def-use data dependence graph according to claim 2, wherein Step 3 specifically includes: Use a disassembler to disassemble the rewritten and instrumented target binary program to obtain assembly code; Perform a full-space scan of the code segment based on the assembly code, and forward search for instruction statements with preset features as function pointer indirect call instructions; among them, the instruction statements with preset features are of the type " call[base+func_offset] ", base represents the address of the structure variable, func_offset represents the function pointer offset; For each function pointer indirect call instruction, starting from its location, search backward and extract the random number corresponding to the basic block where the function pointer indirect call instruction is located. Combine the random number and the location of the function pointer indirect call instruction to form a binary tuple information, and store the binary tuple information into a pointer function dictionary with the function pointer offset func_offset as the key value.

4. The method for identifying the state change of the IPSec protocol based on the def-use data dependence graph according to claim 1, wherein In Step 4, use the miasm plugin through IDAPython to traverse all functions in the target binary program to generate a def-use data dependence graph in units of functions.

5. The method for identifying the state change of the IPSec protocol based on the def-use data dependence graph according to claim 3, wherein Step 5 specifically includes: Take the instruction statement that meets the preset constraint conditions as the structure variable assignment instruction, and the preset constraint conditions include: the instruction statement is of the type " mov [base+dst_offset],src_value ", and the destination operand [base+dst_offset] in base the address value attribute is a memory address, dst_offset the value is a non-zero immediate number, and the source operand src_value the value is an immediate number or the value is passed from an immediate number, and there is a structure variable referenced by [base+dst_offset] as the address in the program control flow; Determine the source operand src_value to determine which of the three modes its value type belongs to: initial definition within the function, direct function call with parameter passing, or indirect function pointer call with parameter passing; According to the mode to which the value type of the source operand belongs, the position of the code where the protocol state change operation is located is identified by a corresponding identification method. src_value ​ 6. The method for identifying the state change of the IPSec protocol based on the def-use data dependence graph according to claim 5, wherein According to the source operand src_value Based on the mode to which the value type belongs, the position of the code where the protocol state change operation is located is identified by a corresponding identification method, specifically including: Step A1: For the initial definition pattern inside the function, continue to judge src_value the value type: If the value is an immediate number, directly record the position of this assignment instruction in the format of a five-tuple <basic block identifier, state variable offset, state value immediate number, assignment type, function name where it is located>, which is the position of the code where the protocol state change operation is located; If the value is passed from an immediate number, in the function code area, according to the def-use data dependency graph of the corresponding function, traverse all paths, starting from the position of this assignment instruction, trace back src_value the value passing process of the value until the position where the initial value of the immediate number is defined is traced, and then record the position where the initial value of this immediate number is defined in the format of <basic block identifier, state variable offset, state value immediate number, assignment type, function name where it is located>, which is the position of the code where the protocol state change operation is located; Step A2: For the function direct call parameter passing mode, obtain the code cross-reference table of the function where this assignment instruction is located, traverse each call point code location in this code cross-reference table, enter the corresponding called function code space, and then go to Step A1 to process according to the initial definition mode inside the function; Step A3: For the function pointer indirect call parameter passing mode, obtain the data cross-reference table of the function where the assignment instruction is located, locate the data reference code position in this data cross-reference table, and search forward for " lea reg,fun_ offset;mov [base+func_offset],reg " 2 associated instructions, and use func_offset as the key value to query the pointer function dictionary to obtain func_offset the code positions of all corresponding function pointer indirect call instructions, enter the code space of each function pointer indirect call instruction one by one for traversal, and go to Step A1 to process according to the initial definition mode inside the function.

Citation Information

Patent Citations

  • Method and system for detecting system performance change of computer by utilizing application

    CN108415836A

  • Network protocol side channel detection method and system based on static taint analysis

    CN114389978A