A control flow construction method and system based on auxiliary program execution feedback

CN117555523BActive Publication Date: 2026-10-09SOUTHEAST UNIV
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202311578339.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-11-24
Publication Date
2026-10-09
Estimated Expiration
2043-11-24

AI Technical Summary

Technical Problem

现有技术存在如下问题:(1)现有程序控制流可视化工作多基于以静态分析为基础实现的控制流图,没有支持动态执行中补完控制流图方法;(2)现有技术将动态执行中的控制流完整性检测抽象化,虽然能够识别不合法的执行,但是无法将具体执行位置并与静态分析控制流结合,并且无法定位间接调用信息,在控制流完整性校验上欠缺;(3)现有动静态方法只能提供基本块或边粒度的控制流信息,无法进一步提供路径粒度的控制流,导致需求高精度控制流的漏洞检测工作无法开展

Benefits of technology

[0027] (1) Control flow completion: Compared with the current control flow integrity based on static analysis, this invention adds supplementary information on program control flow integrity during dynamic execution. It uses unique basic block numbers and edge hashing algorithms to correspond one-to-one with the relationship between static analysis control flow and dynamic execution control flow. It uses process monitoring interface to detect the actual program execution flow and achieves accurate control flow completion.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117555523B_ABST
    Figure CN117555523B_ABST
Patent Text Reader

Abstract

The application discloses a control flow construction method and system based on auxiliary program execution feedback, uses a static analysis method to perform control flow analysis on a program to be tested to form a program control flow graph, compiles the program to be tested by using two kinds of inserted codes, calculates program records of edges as main binary files, and calculates program records of paths as auxiliary binary files; a fuzzy tester is used to continuously execute the main binary files and mutate input of the fuzzy test, and meanwhile, an auxiliary program is started to execute the auxiliary binary files by using the current input; path information fed back by the auxiliary program is combined with program control flow information obtained by the static analysis code to detect and supplement program control flow integrity. The method uses the auxiliary program in a low time consumption mode, realizes call position supplement combined with static analysis of the control flow graph and dynamic execution analysis, takes into account execution efficiency to excavate more potential indirect call edges, and improves accuracy and integrity of the program control flow graph.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the technical field of software security and relates to a method for constructing program control flow and improving the completeness and accuracy of program control flow graphs. It mainly relates to a control flow construction method and system based on auxiliary program execution feedback. Background Technology

[0002] In modern computer science, software development and maintenance have become an indispensable part of the information society. Control flow integrity refers to the fact that a program runs according to its predetermined logic and execution order throughout its lifecycle, without being subject to unauthorized interference or damage. However, with the increasing size and complexity of software, the program's control flow (i.e., the path of program execution) and control flow integrity (the ability to ensure that the program executes as expected) are of great significance for vulnerability finding, project maintenance, and other tasks in the software development cycle. Control flow integrity is particularly important in ensuring the reliability, security, and performance of software systems. Malicious software may exploit vulnerabilities in control flow incompleteness to perform unauthorized operations, thereby compromising system security. Furthermore, for software maintenance and debugging, accurate control flow graphs can help developers understand the program's logical structure and execution flow, thereby diagnosing and resolving problems more quickly.

[0003] One challenge in control flow graph generation is the graph incompleteness problem caused by indirect calls. In modern programming, indirect calls allow programs to dynamically choose which functions or methods to call at runtime as needed. However, this flexibility also makes it difficult for static analysis tools to determine the exact target of indirect calls, thus affecting the accuracy of the program's control flow graph.

[0004] The patent with publication number CN107194252A, entitled "A Fully Context-Sensitive Program Control Flow Integrity Protection Method," collects program control flow information through simulated execution in the static analysis section. During dynamic runtime, it tracks the execution path, tracing the execution paths of processes reaching the same indirect branch and matching them with the control flow information. If a match is successful, it indicates that the simulated execution path during static analysis is the same as the actual execution path during runtime. Based on the control flow information from the static analysis, the subsequent legitimate target address can be determined. If the target address during runtime differs from the legitimate target address, it is determined that a control flow hijacking attack has occurred, and the control flow inspection module notifies the process tracking module to terminate the process. However, this invention aims to determine whether calls during execution are captured by static analysis; it cannot determine the actual execution path, nor can it improve the control flow on the original program control flow graph. Furthermore, it uses taint analysis to judge instructions within the process for path tracing, incurring significant computational overhead.

[0005] The patent with publication number CN111898120A, entitled "Control Flow Integrity Protection Method and Device," first obtains the control flow graph of the program to be protected, determines all indirect branch instructions and their corresponding legal target addresses, inserts a NOP instruction with tag information before each legal target address, and points the jump target address of the corresponding indirect branch instruction to the address where the NOP instruction is located. The tag information is determined based on the address where the indirect branch instruction is located. The NOP instruction is used when executing indirect branch instructions; after verifying that the tag information in the NOP instruction matches the source address of the indirect branch instruction, the instruction after the jump is executed. However, this invention can only use the control flow graph obtained by static analysis of the control flow, and indirect calls obtained by static analysis, such as pointer analysis, often have certain inaccuracies and incompleteness.

[0006] The ultimate goal of the aforementioned patents is to improve control flow integrity detection methods through static or dynamic methods, thereby enhancing the accuracy of program analysis and understanding. Existing technologies have the following problems: (1) Existing program control flow visualization is mostly based on control flow graphs implemented using static analysis, and does not support methods for completing control flow graphs during dynamic execution; (2) Existing technologies abstract control flow integrity detection during dynamic execution. Although they can identify illegal executions, they cannot combine the specific execution location with the statically analyzed control flow, nor can they locate indirect call information, thus lacking in control flow integrity verification; (3) Existing dynamic and static methods can only provide control flow information at the basic block or edge granularity level, and cannot further provide control flow at the path granularity level, making it impossible to carry out vulnerability detection work requiring high-precision control flow. Summary of the Invention

[0007] This invention addresses the problems existing in the prior art by providing a control flow construction method and system based on auxiliary program execution feedback. First, a static analysis method is used to perform control flow analysis on the program under test, forming a program control flow graph. Two types of instrumented code are used to compile the program under test. The program recording for edge calculations is recorded in the main binary file, and the program recording for path calculations is recorded in the auxiliary binary file. A fuzzer is used to continuously execute the main binary file and mutate the fuzz test input. Simultaneously, an auxiliary program is started to execute the auxiliary binary file using the current input. Based on the path information fed back by the auxiliary program and the program control flow information obtained from the static analysis code, the integrity of the program control flow is detected and supplemented. This method utilizes a dynamic and static combination approach, leveraging the auxiliary program with low time overhead. It combines static analysis of the control flow graph with dynamic execution analysis to supplement call positions, balancing execution efficiency to uncover more potential indirect call edges, while improving the accuracy and completeness of the program control flow graph.

[0008] To achieve the above objectives, the technical solution adopted by the present invention is: a control flow construction system based on auxiliary program execution feedback, comprising at least a static analysis and instrumentation module, a fuzzy testing loop module, and a detection module.

[0009] The static analysis and instrumentation module uses static analysis code and source code-level instrumentation instructions to perform edge coverage and path coverage instrumentation compilation on the program under test, obtain the main binary file and auxiliary binary file, generate static analysis control flow information, and generate the static analysis control flow graph.

[0010] The fuzzing module includes a fuzzing loop and its auxiliary program. The fuzzing loop is responsible for executing the main binary executable file, generating input data with random mutations, and then inputting the mutated data into the main binary file for testing. The auxiliary program uses the mutated input generated by the fuzzing test to execute the auxiliary binary file using the current input. The fuzzing loop monitors the subprocesses and integrates the information into the detection module.

[0011] The detection module detects the path value fed back from the auxiliary binary file executed by the auxiliary program to the shared memory, compares it with the edge coverage fed back to another shared memory in the fuzz test, and identifies indirect call information.

[0012] To achieve the above objectives, the present invention also adopts the following technical solution: a control flow construction method based on auxiliary program execution feedback, comprising at least the following steps:

[0013] S1. Construct static analysis and two types of instrumentation code: Assign a unique number to each basic block in the program under test and record it. Combine the call relationship between basic blocks obtained through static analysis with the basic block number to obtain the static analysis control flow information; Copy the code containing the same static analysis into two copies and perform basic block-level instrumentation to calculate the edge and path coverage.

[0014] For instrumentation that computes edge coverage, the algorithm calculates and records the hash value of the executed edge based on the unique number of the basic block, and automatically records the hash value to shared memory.

[0015] For instrumentation that computes path coverage, the hash value of the execution path is calculated and recorded using an algorithm based on the unique number of the basic block, and its hash value is automatically recorded in another shared memory.

[0016] S2, compile and instrument the program under test: use static analysis and instrumentation code to assign a unique number to each basic block of the program under test at compile time, and instrument the program under test. The program compiled using edge overlay instrumentation code is called the main binary file, and the program compiled using path overlay instrumentation code is called the auxiliary binary file.

[0017] S3, Construct an auxiliary program to assist in the control flow integrity detection process: Use the fuzz tester to continuously execute the main binary file obtained after step S2 and mutate the fuzz test input. When the fuzz test first provides input and starts execution, start the auxiliary program to execute the auxiliary binary file obtained after step S2 using the current input. Based on the feedback in shared memory during its execution, and combined with the program control flow information obtained from the static analysis code obtained after step S1, detect and supplement the program control flow integrity.

[0018] As an improvement of the present invention, in step S1, static analysis uses a random function to assign a fixed-bit unique number to each basic block in the program under test, and records the correspondence between the basic block index and the basic block unique number according to the traversal order of the program from module to function to basic block level. The control flow obtained through the call relationship between basic blocks is combined with the basic block unique number to pre-calculate the jump edges in all programs as the static analysis control flow information of the program.

[0019] As another improvement of the present invention, in step S3, the fuzz tester continuously executes different input files and queries the shared memory after each execution. If a new hash value is found in the shared memory, it indicates that the current input file has discovered a new edge cover, and the auxiliary program is started to execute the auxiliary binary file using the current input. If no new edge cover is captured, the current seed of the fuzz test is used as a substitute for the test auxiliary binary file.

[0020] As another improvement of the present invention, the edge instrumentation uses the hash function Hash1(BBID) Current BBID Previous Perform the calculation:

[0021] EdgeHash = Hash1(BBID) Current BBID Previous EdgeSHMValue

[0022] Where EdgeHash is the hash value of the jump edge, representing the jump from the previous basic block to the current basic block; BBID Current BBID represents a unique identifier for the current basic block. Previous The unique identifier representing the preceding basic block, and BBID Current BBID previous The value is between 0 and MaxValue. EdgeSHMValue represents the maximum storable value for each bit of the shared memory, and MaxValue represents the maximum positive integer that the unique number of the basic block can take.

[0023] As another improvement of the present invention, the path instrumentation uses the hash function Hash2(BBID)Current The calculation is performed using PathHash.

[0024] PathHash = Hash2(BBID) Current ,PathHash)&PathSHMValue

[0025] Where PathHash is the hash value of the entire execution path, representing the complete execution flow of a single execution; BBID Current Represents the unique identifier of the current basic block, and BBID Current Located between 0 and MaxValue, the value of PathHash is located between 0 and PathSHMValue; PathSHMValue represents the maximum storable value for each bit of shared memory.

[0026] Compared with the prior art, the present invention has the following beneficial effects:

[0027] (1) Control flow completion: Compared with the current control flow integrity based on static analysis, this invention adds supplementary information on program control flow integrity during dynamic execution. It uses unique basic block numbers and edge hashing algorithms to correspond one-to-one with the relationship between static analysis control flow and dynamic execution control flow. It uses process monitoring interface to detect the actual program execution flow and achieves accurate control flow completion.

[0028] (2) Integrity verification: Compared with the current method that can only detect whether the current execution is detected in the static analysis control flow, the present invention adds an auxiliary program during the fuzzing process to execute an instrumentation code that can monitor the execution path. It can judge the execution status through the feedback of fuzzing and auxiliary processes during the runtime phase, obtain the real execution position and execution order in the program control flow graph, and more accurately determine whether the execution process meets expectations during verification, thereby improving the control flow integrity of the software.

[0029] (3) Provides a basis for path-based fuzzing: Compared with the current method of using taint analysis within the main execution process, this invention constructs an auxiliary binary file and auxiliary program monitoring. By separating the execution process of the main fuzzing program and the path tracing process of the auxiliary program, it obtains path-granular control flow information based on the basic block granularity or edge granularity of previous work, providing a basis for fuzzing work guided by path coverage. Attached Figure Description

[0030] Figure 1 This is a schematic diagram of the steps of the method of the present invention;

[0031] Figure 2 This is a schematic diagram illustrating the application of the control flow construction system based on auxiliary program execution feedback in Embodiment 1 of the present invention. Detailed Implementation

[0032] The present invention will be further illustrated below with reference to the accompanying drawings and specific embodiments. It should be understood that the following specific embodiments are for illustrative purposes only and are not intended to limit the scope of the present invention.

[0033] Example 1

[0034] A control flow construction system based on auxiliary program execution feedback, its application state is as follows: Figure 2 As shown, it includes at least a static analysis and instrumentation module, a fuzzy testing loop module, and a detection module:

[0035] Static Analysis and Instrumentation Module: Includes instrumentation and static analysis code, with instrumentation code for edge coverage and path coverage respectively. It is responsible for instrumenting the program under test, generating the main binary file and auxiliary binary file, generating static analysis control flow information, and generating the control flow graph for static analysis.

[0036] Static analysis is used to trace function calls to obtain the program control flow graph, while instrumentation instructions are used to automatically provide feedback on information such as memory access during execution.

[0037] Static analysis uses a random function to assign a fixed-bit unique number to each basic block in the program under test, and records the correspondence between the basic block index and the unique number of the basic block according to the traversal order of the program from module to function to basic block level. The control flow obtained from the call relationships between basic blocks is combined with the unique number of the basic block to pre-calculate the jump edges in all programs, which serve as the static analysis control flow information of the program. For the instrumentation code that calculates edge and path coverage, a different algorithm than the edge coverage algorithm is used, with the unique number of the basic block as the parameter, to insert the code that calculates the edge and path representation values ​​in the program and record them in the corresponding shared memory location.

[0038] Using a compiler frontend and a compiler backend with static analysis and side-instrumentation / path-instrumentation code files, the program under test is instrumented and compiled. The instrumented binary executable file obtained using the side-instrumentation code is denoted as the main binary file, and the instrumented binary executable file obtained using the path-instrumentation code is denoted as the auxiliary binary file.

[0039] The fuzzing module includes a fuzzing loop and its auxiliary programs. The fuzzing loop is responsible for executing the main binary executable file, generating input data with random mutations through mutation methods, and then inputting this data into the main binary file for testing. At the same time, the auxiliary program uses the mutated input generated by fuzzing to execute the auxiliary binary file with the current input, monitors the subprocesses through the fuzzing loop, and integrates the information into the detection module.

[0040] The fuzz tester automatically discovers vulnerabilities and security issues in software programs. By generating input data with random variations and then inputting this data into the target program for testing, it can effectively explore different execution paths of the program. The fuzz tester seeks new inputs to explore new edge covers. The inputs are also used to assist program execution and detect path information to improve control flow integrity. The fuzz tester and the auxiliary program write the edge covers and path covers into two shared memory regions separated by physical addresses.

[0041] The fuzzer continuously executes the main binary file and mutates the fuzz test input. After each execution, the fuzzer queries the shared memory. If a new hash value is found in the shared memory, it indicates that the current input file has discovered a new edge cover, and an auxiliary program is started to execute the auxiliary binary file using the current input. If no new edge cover is captured, the current fuzz test seed is used as a substitute for the test auxiliary binary file. By comparing the shared memory affected by edge cover instrumentation and path cover instrumentation files, and combining the control flow information of the static analysis program obtained from the previously obtained static analysis code, newly discovered path execution information is added to the control flow graph that can be constructed with execution edges as the granularity, achieving a more complete and accurate control flow integrity detection.

[0042] Detection module: Detects the path value fed back from the auxiliary binary file executed by the auxiliary program to shared memory, compares it with the edge coverage fed back to another shared memory in fuzzing, and identifies indirect call information. Edge instrumentation will use the hash function Hash1(BBID) Current BBID Previous The calculation is performed, and a bitwise AND operation is performed with the maximum storable value EdgeSHMValue for each bit of the shared memory. The purpose is to limit the edge hash value to between 0 and MaxValue, ensuring that the overhead caused by multiple reads of shared memory does not exceed an expected range. The calculation method is as follows:

[0043] EdgeHash = Hash1(BBID) Current BBID Previous EdgeSHMValue

[0044] Where EdgeHash is the hash value of the jump edge, representing the jump from the previous basic block to the current basic block; BBID Current BBID represents a unique identifier for the current basic block. Previous The unique identifier representing the preceding basic block, and BBID Current BBID Previous The value belongs to the fixed range.

[0045] Path instrumentation uses the hash function Hash2(BBID) Current The path hash is calculated using the PathHash function and then ANDed with the maximum storable value PathSHMValue for each bit in the shared memory. The purpose is to limit the path hash value to between 0 and PathSHMValue. The specific calculation function is as follows:

[0046] PathHash = Hash2(BBID) Current ,PathHash)&PathSHMValue

[0047] Where PathHash is the hash value of the entire execution path, representing the complete execution flow of a single execution; BBID Current Represents the unique identifier of the current basic block, and BBID Current Both PathHash and PathHash fall within the aforementioned fixed numerical range.

[0048] This system includes static analysis and two types of instrumentation code. Each basic block in the program under test is assigned a unique number and recorded. The control flow and basic block order obtained through static analysis are used to record the coverage information at the edge and path granularities in the program. The program under test is compiled using the two types of instrumentation code. The program calculating edge coverage is recorded as the main binary file, and the program calculating path coverage is recorded as the auxiliary binary file. A fuzzer continuously executes the main binary file and mutates the fuzzing input. Simultaneously, an auxiliary program is started to execute the auxiliary binary file using the current input. Based on the path information fed back by the auxiliary program, combined with the program control flow information obtained from the static analysis code, the system detects and supplements the program control flow integrity. This system achieves the capture of indirect call locations and execution paths, providing a data foundation for control flow graph completion in visualization work. It demonstrates the feasibility of a fuzzing method guided by path coverage. Combined with error detection by a path-based fuzzer, it ensures that machine code instruction transfer control can only transfer to valid targets, guaranteeing the accuracy of control flow integrity verification on the basis of completion.

[0049] Example 2

[0050] A control flow construction method based on auxiliary program execution feedback, such as Figure 1 As shown, it includes the following steps:

[0051] (1) First, prepare the static analysis code, create an LLVM Pass file, and pre-calculate the BBID by traversing all the basic blocks in a Module. Current =Random(2 32-1) Create a 32-bit ID for each basic block and store it in a list BBList. If this ID conflicts with any value in BBList, reassign a new ID to the current basic block. Use static analysis to pre-construct the program control flow and assign BBIDs to each basic block according to the order of the constructed control flow. Current Represents the current basic block number, assigned BBID Previous This represents the number of the preceding basic block. The formula is EdgeHash = ((BBID) Current >>1)^BBID Previous Edge hashing is performed using BBList and EdgeList, assigning a fixed edge hash value to each executed edge and storing it in EdgeList. BBList and EdgeList extract control flow information to construct the directed acyclic control flow graph of the static analysis program, enabling the location of basic blocks and edges and their correspondences using unique basic block numbers and edge hashes. Next, instrumentation code is prepared. In the LLVMPass file, a second round of traversal at the basic block level is performed, searching for the corresponding information of the current basic block in BBList, and performing the logic as shown in the formula EdgeHash = ((BBID)). Current >>1)^BBID Previous The instrumentation code performs the operation of 65535 and stores the result in the shared memory EdgeSHM. The instrumentation code is inserted into the basic block of the program under test during compilation and will only be executed when the program under test reaches the instrumentation code.

[0052] (2) Using LLVMPass described in step (1) in conjunction with the compiler front-end Clang, instrumentation and static analysis are performed on the program under test to obtain the control flow information of the static analysis (including the BBList and EdgeList mentioned above). For edge coverage instrumentation, the EdgeHash is calculated using the algorithm described in step (1), and the main binary file MFile with instrumentation code for each basic block is compiled. For path coverage instrumentation, BBID is used as the basis for the instrumentation. Previous and BBID Current Based on this, use PathHash = ((BBID) during the first storage. Current >>1)^BBID Previous )&65535, after the second and subsequent uses of PathHash, use PathHash=((BBID) Current >>1)^PathHash)&65535, iterates each time instrumentation code is encountered, restores PathHash after each execution, and compiles to obtain an auxiliary binary file SFile with instrumentation code for each basic block.

[0053] (3) Use Clang as the compiler front end and LLVM as the compiler back end, and combine it with LLVMPass to instrument the program under test. The instrumented binary executable file is obtained by overriding the instrumentation code with the edge, and is called the main binary file; the instrumented binary executable file is obtained by overriding the instrumentation code with the path, and is called the auxiliary binary file.

[0054] (4) As in Algorithm 1, for the main binary file described in step (2), the fuzzer described above is used to perform a loop execution. In this embodiment, AFL is used as the fuzzer. The initial test case enters AFL and is executed once. Since the instrumentation code is executed, the edge hash value is automatically written into the shared memory EdgeSHM. Therefore, in subsequent executions, the changes in EdgeSHM are used to determine whether a new edge coverage has been triggered. At the same time, the auxiliary program is opened. The auxiliary program prioritizes the execution of test cases that trigger a new edge coverage. When no new edge coverage is triggered, the input of the current fuzzer is used for execution. The auxiliary program executes the current test case. When the instrumentation is reached, the path hash value is automatically recorded in the shared memory PathSHM. After completing the above series of operations, the fuzzing process performs seed mutation to generate new test cases and enters the next loop until the system times out.

[0055]

[0056] (5) As in Algorithm 1, the information detection module combines the control flow information obtained in step (1) with the EdgeSHM and PathSHM obtained in step (4) to analyze and compare the two, obtain control flow information with the same edge coverage but different path coverage, and add the comparison information to IndPathList as the basis for indirectly calling the control flow.

[0057] This invention's method analyzes control flow during dynamic execution using static analysis combined with an auxiliary program. This not only obtains accurate and accurate control flow information but also completes the program's control flow graph. Secondly, it uncovers indirect call information, which can be used to implement security measures, such as checking and verifying function pointers. This helps prevent potential security vulnerabilities, such as buffer overflow attacks or code injection. Finally, it provides a feasible foundation for fuzzing based on path coverage, helping to increase test coverage, ensuring that all parts of the program are adequately tested, and helping to discover vulnerabilities that only trigger under specific input conditions, thus improving software quality and stability.

[0058] It should be noted that the above content merely illustrates the technical concept of the present invention and should not be construed as limiting the scope of protection of the present invention. For those skilled in the art, various improvements and modifications can be made without departing from the principle of the present invention, and all such improvements and modifications fall within the scope of protection of the claims of the present invention.

Claims

1. A control flow construction method based on auxiliary program execution feedback, characterized in that... It should include at least a static analysis and instrumentation module, a fuzzy testing loop module, and a detection module. The static analysis and instrumentation module uses static analysis code and source code-level instrumentation instructions to perform edge coverage and path coverage instrumentation compilation on the program under test, obtain the main binary file and auxiliary binary file, generate static analysis control flow information, and generate the static analysis control flow graph. The fuzzy testing loop module includes a fuzzy testing loop and its auxiliary program. The fuzzy testing loop is responsible for executing the main binary executable file, generating input data with random mutations, and then inputting the mutated data into the main binary file for testing. The auxiliary program uses the mutated input generated by the fuzzy test to execute the auxiliary binary file using the current input. The fuzzy testing loop monitors the subprocesses and integrates the information into the detection module. The detection module detects the path value fed back from the auxiliary binary file executed by the auxiliary program to the shared memory, compares it with the edge coverage fed back to another shared memory in the fuzz test, and identifies indirect call information. The method includes at least the following steps: S1. Construct static analysis and two types of instrumentation code: Assign a unique number to each basic block in the program under test and record it. Combine the call relationship between basic blocks obtained through static analysis with the basic block number to obtain the static analysis control flow information; Copy the code containing the same static analysis into two copies and perform basic block-level instrumentation to calculate the edge and path coverage. For instrumentation that computes edge coverage, the algorithm calculates and records the hash value of the executed edge based on the unique number of the basic block, and automatically records the hash value to shared memory. For instrumentation that computes path coverage, the hash value of the execution path is calculated and recorded using an algorithm based on the unique number of the basic block, and its hash value is automatically recorded in another shared memory. S2, compile and instrument the program under test: use static analysis and instrumentation code to assign a unique number to each basic block of the program under test at compile time, and instrument the program under test. The program compiled using edge overlay instrumentation code is called the main binary file, and the program compiled using path overlay instrumentation code is called the auxiliary binary file. S3, Construct an auxiliary program to assist in the control flow integrity detection process: Use the fuzz tester to continuously execute the main binary file obtained after step S2 and mutate the fuzz test input. When the fuzz test first provides input and starts execution, start the auxiliary program to execute the auxiliary binary file obtained after step S2 using the current input. Based on the feedback in shared memory during its execution, and combined with the program control flow information obtained from the static analysis code obtained after step S1, detect and supplement the program control flow integrity.

2. The control flow construction method based on auxiliary program execution feedback as described in claim 1, characterized in that: In step S1, static analysis uses a random function to assign a fixed-bit unique number to each basic block in the program under test, and records the correspondence between the basic block index and the basic block unique number according to the traversal order of the program from module to function to basic block level. The control flow obtained through the call relationship between basic blocks is combined with the basic block unique number to pre-calculate the jump edges in all programs as the static analysis control flow information of the program.

3. The control flow construction method based on auxiliary program execution feedback as described in claim 1, characterized in that: In step S3, the fuzz tester continuously executes different input files and queries the shared memory after each execution. If a new hash value is found in the shared memory, it means that the current input file has discovered a new edge cover. The auxiliary program is then started to execute the auxiliary binary file using the current input. If no new edge overlays are captured, the current seed is fuzzed as an alternative to the test auxiliary binary.

4. The control flow construction method based on auxiliary program execution feedback as described in claim 3, characterized in that: In step S1, edge instrumentation is performed using a hash function. , Perform the calculation: , ; in, The hash value of the jump edge represents the jump from the previous basic block to the current basic block; Represents the unique identifier of the current basic block. A unique identifier representing the preceding basic block, and , This represents the maximum storable value for each bit of the shared memory. This represents the largest positive integer that can be taken as the unique identifier of a basic block.

5. The control flow construction method based on auxiliary program execution feedback as described in claim 4, characterized in that: In step S1, path instrumentation is performed using a hash function. , Perform the calculation: , ; in, The hash value of the entire execution path represents the complete execution flow of a single execution. Represents the unique identifier of the current basic block, and The value is located at , The value is between 0 and between; The maximum value that can be stored per bit of shared memory.

Citation Information

Patent Citations

  • Full context-sensitive program control flow integrity protection method and system

    CN107194252A

  • Control flow integrity protection method and device

    CN111898120A

  • Multi-level hybrid vulnerability automatic mining method

    CN111859388A

  • System and method of analyzing interpreted programs

    US20050125777A1