A static analysis method, system, chip and device for multi-language applications
Patent Information
- Application Number
- CN202311706298.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-12-12
- Publication Date
- 2026-09-29
- Estimated Expiration
- 2043-12-12
AI Technical Summary
[0006]本发明所要解决的技术问题在于针对上述现有技术中的不足,提供一种面向多语言应用的静态分析方法、系统、芯片及设备,用于解决现有静态分析软件只能对多语言项目的不同语言源代码进行独立分析,无法发现多语言项目中相互调用接口的技术问题,在多语言应用中提供全面的安全性分析和漏洞检测,提高安全性和可靠性
[0034]一种面向多语言应用的静态分析方法,可以有效处理多语言应用的静态分析需求,提高漏洞检测的准确性、全面性和可靠性,具体如下:
Smart Images

Figure CN117688573B_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of source code defect detection technology, specifically relating to a static analysis method, system, chip, and device for multi-language applications. Background Technology
[0002] As modern software grows in scale and functional requirements change, software projects often utilize different modules written in multiple languages to accomplish their respective functions. Some programming languages provide the ability for direct code calls between each other; for example, Java code can call Kotlin code, and Groovy code can directly call Java code. Modules from different languages are organized using build tools such as Gradle and Maven, and communicate with each other through API interfaces. This complexity also places higher demands on software vulnerability analysis programs.
[0003] Static source code analysis is a crucial technology for ensuring software security. It's a technique that analyzes source code to discover software vulnerabilities without running the program. Static analysis programs scan all source code, converting it into an abstract syntax tree (AST) and performing type analysis. The AST is then transformed into a generic intermediate representation. The AST is a structured representation of the source code; type analysis infers code behavior by identifying the types of variables and functions and the relationships between them; and the intermediate representation is language-independent data generated based on the language's AST and type information.
[0004] Static analysis is used to detect potential software problems based on a unified intermediate representation. More precise type analysis can more accurately infer the variables and functions used in the code, thus effectively improving the accuracy of static analysis.
[0005] However, in software projects involving multiple programming languages, currently widely used static analysis programs can only call the corresponding analysis engine separately for each language's source code. This approach cannot perform type analysis on cross-language program calls, resulting in an inability to accurately analyze the functionality of variables or functions called across languages. When potentially risky data is passed from an interface written in one language to an interface written in another language, existing static analysis methods cannot effectively analyze such cross-language situations, thus failing to detect potential code problems. Summary of the Invention
[0006] The technical problem to be solved by this invention is to address the shortcomings of the prior art by providing a static analysis method, system, chip, and device for multilingual applications. This invention solves the problem that existing static analysis software can only analyze the source code of different languages in multilingual projects independently and cannot discover the technical problem of mutual calling interfaces in multilingual projects. It provides comprehensive security analysis and vulnerability detection in multilingual applications, thereby improving security and reliability.
[0007] The present invention adopts the following technical solution:
[0008] A static analysis method for multilingual applications includes the following steps:
[0009] In a multilingual project, files in different programming languages are converted into abstract syntax trees (ASTs) and type-analyzed to obtain type analysis information; the ASTs are then converted into general and unified intermediate representation data.
[0010] The type analysis information is stored in a cached dataset;
[0011] The type analysis information in the cached dataset is divided into two states: parsed and unparsed.
[0012] If the type lookup is successful in both the parsed and unparsed states, then the function and property information related to the called object is supplemented and added to the intermediate representation data;
[0013] Based on the obtained intermediate representation data, a complete cross-language function call relationship is constructed, and the security risks of cross-language calls are discovered through the static analysis defect analysis module.
[0014] Preferably, converting files in different programming languages in a multilingual project into an abstract syntax tree specifically involves:
[0015] Collect files from different programming languages in the multilingual project based on file extensions. For each language file, use the corresponding compiler to convert the source code into an abstract syntax tree and perform type analysis.
[0016] More preferably, the different programming language files include source code files for Java, Kotlin, and Groovy, and the compilers include JDT compiler, Kotlin compiler, and Groovy compiler.
[0017] Preferably, storing type analysis information in the cached dataset specifically involves:
[0018] It stores all type analysis results, establishes a mapping relationship between all parsed types and intermediate representation data, and stores data structures including filename, language, type information, and the type representation in the intermediate representation data.
[0019] Preferably, the two states, parsed and unparsed, are as follows:
[0020] Parsed data indicates that type inference has been completed and can be directly used for model detection; unparsed data enters the type inference module, which searches for relevant types in the cached data set based on the brief type information of the calling object to supplement the type information.
[0021] More preferably, based on the interoperability between programming languages, cached datasets of other languages used by the type or method are obtained.
[0022] More preferably, type inference is performed on all incompletely resolved types or methods, as follows:
[0023] Get the package name and class name of the incompletely resolved type; based on the language type, get the cached data set of other callable languages; look up the corresponding type information based on the obtained package name and class name; get the data of the corresponding type in the intermediate representation.
[0024] Secondly, embodiments of the present invention provide a static analysis system for multilingual applications, comprising:
[0025] The conversion module converts files from different programming languages in a multilingual project into abstract syntax trees and performs type analysis to obtain type analysis information.
[0026] The data module converts the abstract syntax tree into a universal and unified intermediate representation data;
[0027] The storage module stores the type analysis information into a cached dataset;
[0028] The state module categorizes type analysis information in the cached dataset into two states: parsed and unparsed.
[0029] The supplementary module, when the type lookup for the parsed and unparsed states obtained by the state module is successful, supplements the function and attribute information related to the called object and adds it to the intermediate representation data obtained by the data module;
[0030] The analysis module, based on the intermediate representation data obtained from the supplementary module, constructs a complete cross-language function call relationship and discovers security vulnerabilities in cross-language calls through the static analysis defect analysis module.
[0031] Thirdly, a chip includes a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor, when executing the computer program, implements the steps of the above-described static analysis method for multilingual applications.
[0032] Fourthly, embodiments of the present invention provide an electronic device including a computer program, which, when executed by the electronic device, implements the steps of the above-described static analysis method for multilingual applications.
[0033] Compared with the prior art, the present invention has at least the following beneficial effects:
[0034] A static analysis method for multilingual applications is proposed, which can effectively handle the static analysis needs of multilingual applications and improve the accuracy, comprehensiveness, and reliability of vulnerability detection. The specific details are as follows:
[0035] 1. Obtaining accurate type information: This method converts the source code into a syntax tree and performs type analysis to obtain accurate type information for each object and function. It also supplements the missing type information in the intermediate representations using a type inference module. This provides accurate type information to the static analysis and detection module, thereby improving the accuracy and comprehensiveness of vulnerability detection.
[0036] 2. Addressing Security Risks in Cross-Language Calls: Based on unified intermediate representation data to supplement missing types, the static analysis and detection module can not only identify vulnerabilities within a single language module but also address security risks in cross-language calls. It can analyze the interface security and data transmission correctness in cross-language calls, detecting potential security vulnerabilities. This comprehensive vulnerability detection capability enables the optimized static analysis program to comprehensively analyze security issues in multilingual applications, including the rationality and security of cross-language call interfaces.
[0037] It is understood that the beneficial effects of the second to fourth aspects mentioned above can be found in the relevant descriptions in the first aspect mentioned above, and will not be repeated here.
[0038] In summary, this invention can obtain accurate type information, address security risks associated with cross-language calls, and support the detection needs of complex code projects. This method comprehensively improves the static analysis capabilities of multilingual applications, enhances the accuracy, comprehensiveness, and reliability of vulnerability detection, thereby improving software security and reliability.
[0039] The technical solution of the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. Attached Figure Description
[0040] Figure 1 This is a schematic diagram of the process of the present invention;
[0041] Figure 2 Store the structure diagram for the compiler type analysis results;
[0042] Figure 3 A schematic diagram of a computer device provided in an embodiment of the present invention;
[0043] Figure 4 This is a block diagram of a chip according to an embodiment of the present invention;
[0044] Figure 5 This is a partial source code example of an embodiment of the present invention. Detailed Implementation
[0045] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0046] In the description of this invention, it should be understood that the terms "comprising" and "including" indicate the presence of the described features, integrals, steps, operations, elements and / or components, but do not exclude the presence or addition of one or more other features, integrals, steps, operations, elements, components and / or collections thereof.
[0047] It should also be understood that the terminology used in this specification is for the purpose of describing particular embodiments only and is not intended to limit the invention. As used in this specification and the appended claims, the singular forms “a,” “an,” and “the” are intended to include the plural forms unless the context clearly indicates otherwise.
[0048] It should also be further understood that the term "and / or" as used in this specification and the appended claims refers to any combination and all possible combinations of one or more of the associated listed items, and includes such combinations. For example, A and / or B can represent three cases: A alone, A and B simultaneously, and B alone. Additionally, the character " / " in this invention generally indicates that the preceding and following objects have an "or" relationship.
[0049] It should be understood that although terms such as first, second, third, etc., may be used in the embodiments of the present invention to describe the preset range, these preset ranges should not be limited to these terms. These terms are only used to distinguish the preset ranges from one another. For example, without departing from the scope of the embodiments of the present invention, the first preset range may also be referred to as the second preset range, and similarly, the second preset range may also be referred to as the first preset range.
[0050] Depending on the context, the word "if" as used here can be interpreted as "when," "when," "in response to determination," or "in response to detection." Similarly, depending on the context, the phrase "if determination" or "if detection (of the stated condition or event)" can be interpreted as "when determination," "in response to determination," "when detection (of the stated condition or event)," or "in response to detection (of the stated condition or event)."
[0051] The accompanying drawings illustrate various structural schematic diagrams according to embodiments disclosed in this invention. These drawings are not to scale, and some details have been enlarged for clarity, and some details may have been omitted. The shapes of the various regions and layers shown in the drawings, as well as their relative sizes and positional relationships, are merely exemplary and may deviate from reality due to manufacturing tolerances or technical limitations. Furthermore, those skilled in the art can design regions / layers with different shapes, sizes, and relative positions as needed.
[0052] This invention provides a static analysis method for multilingual applications. It uses a compiler to convert the source code of a multilingual project into an abstract syntax tree and type information, extracts summary information for all types, collects and stores this information in a unified summary information dataset, and abstracts the syntax tree into a language-independent intermediate representation. A type inference module infers incompletely parsed type and method information based on the summary information dataset, supplementing the intermediate representation with data. The analysis model then uses this supplemented intermediate representation to discover potential code security issues. This optimized method enables cross-language supplementation of interface information, allowing for comprehensive static analysis of the entire project and providing cross-language call analysis and vulnerability detection capabilities.
[0053] Source code transformation: The source code is transformed into an abstract syntax tree and type analyzed by compilers of various languages, and the type analysis results are cached.
[0054] Intermediate representation: The abstract syntax tree and type analysis results are further converted into a language-independent unified intermediate representation.
[0055] Type inference: The type inference module infers the missing type information from the inference step and translator type analysis and adds it to the intermediate representation.
[0056] Static analysis detection: Static analysis detection is performed based on the supplemented intermediate representation to improve the accuracy and comprehensiveness of vulnerability detection.
[0057] Please see Figure 1 This invention provides a static analysis method for multilingual applications, comprising the following steps:
[0058] S1. Collect files from different programming languages in the multi-language project based on file extensions. For each language file, use the corresponding compiler to convert the source code into an abstract syntax tree and perform type analysis.
[0059] Collect all source code files of the project to be analyzed, and distinguish the source code files of Java, Kotlin, and Groovy languages according to the file type; call the JDT compiler, Kotlin compiler, and Groovy compiler respectively to perform abstract syntax tree transformation and type analysis on the collected Java, Kotlin, and Groovy files.
[0060] S2. Transform the abstract syntax tree into a universal and unified intermediate representation;
[0061] S3. Store the type information obtained from the analysis of each language into the cached dataset;
[0062] Store all type analysis results and establish a mapping relationship between all parsed types and intermediate representation data.
[0063] The stored data structure consists of four items: filename, language, type information, and the representation of the type in the intermediate data.
[0064] Storage structure such as Figure 2 As shown, type information needs to be mapped to methods and fields. In Java, Kotlin, and Groovy, member methods and field definitions are necessarily included in the type definition. Additionally, Kotlin's top-level methods and fields are located in the type definition within the Kotlin filename with the .kt suffix, while Groovy's top-level methods and fields are located in the type definition within the Groovy filename.
[0065] S4. After type analysis by the compiler, types and methods are divided into two states: resolved and unresolved. Resolved types indicate that type inference has been completed and no further processing is required. They can be directly used for model detection. Unresolved types enter the type inference module, which searches for relevant types in the cached data set based on the brief type information of the calling object to supplement the type information.
[0066] Select the cache dataset to be analyzed. First, based on the interoperability between programming languages, obtain the cache datasets of other languages used by the types or methods. For example, Java can call Kotlin and Groovy code, Kotlin can call Java code, and Groovy can call Java code. Select the corresponding cache datasets according to the interoperability relationships.
[0067] Type inference is performed on all incompletely resolved types or methods, as follows:
[0068] S401. Obtain the package name and class name of the incompletely resolved type:
[0069] The JDT compiler obtains incompletely resolved types from Java code type analysis, only the type name. It is necessary to combine the import information obtained by CompilationUnit's imports method to obtain the complete package name and type name.
[0070] For incompletely resolved types, the Kotlin compiler can only obtain the type name. The complete package name and type name need to be obtained by analyzing the import information through the importList property of the KtFile object.
[0071] The Groovy compiler can directly obtain the full package name and type name for incompletely resolved types.
[0072] S402. Based on the language type, obtain the cached data set of other callable languages, and find the corresponding type information based on the package name and class name of the type obtained in step S401.
[0073] S403. Retrieve the data of the corresponding type in the intermediate representation.
[0074] S5. If the type lookup is successful, supplement the function and property information related to the called object and add it to the intermediate representation;
[0075] The data obtained after type inference is supplemented into the unified intermediate representation data.
[0076] S6. Based on the intermediate representation data after type lookup and supplementation, construct a complete cross-language function call relationship, and discover security risks in cross-language calls through the static analysis defect analysis module.
[0077] The static analysis engine performs defect analysis based on intermediate representation data and reports the analysis results.
[0078] In another embodiment of the present invention, a static analysis system for multilingual applications is provided. This system can be used to implement the above-mentioned static analysis method for multilingual applications. Specifically, the static analysis system for multilingual applications includes a conversion module, a data module, a storage module, a status module, a supplementary module, and an analysis module.
[0079] The conversion module converts files in different programming languages in a multilingual project into abstract syntax trees and performs type analysis.
[0080] The data module converts the abstract syntax tree obtained by the transformation module into a universal and unified intermediate representation data;
[0081] The storage module stores the type analysis information obtained by the conversion module into the cache dataset;
[0082] The status module categorizes the type analysis information obtained from the storage module into two states: parsed and unparsed.
[0083] The supplementary module, when the type lookup for the parsed and unparsed states obtained by the state module is successful, supplements the function and attribute information related to the called object and adds it to the intermediate representation data obtained by the data module;
[0084] The analysis module, based on the intermediate representation data obtained from the supplementary module, constructs a complete cross-language function call relationship and discovers security vulnerabilities in cross-language calls through the static analysis defect analysis module.
[0085] In another embodiment of the present invention, a terminal device is provided, comprising a processor and a memory. The memory stores a computer program, the computer program including program instructions, and the processor executes the program instructions stored in the computer storage medium. The processor may be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. It is the computing and control core of the terminal, suitable for implementing one or more instructions, specifically suitable for loading and executing one or more instructions to implement a corresponding method flow or corresponding function. The processor described in this embodiment of the present invention can be used for the operation of static analysis methods for multilingual applications, including:
[0086] In a multilingual project, files in different programming languages are converted into abstract syntax trees (ASTs) and type analyzed. The ASTs are then converted into a unified intermediate representation. Type analysis information is stored in a cached dataset. This type analysis information is categorized into parsed and unparsed states. If a type lookup is successful in either parsed or unparsed state, relevant function and attribute information related to the called object is added to the intermediate representation. Based on this intermediate representation, a complete cross-language function call relationship is constructed, and a static analysis defect analysis module is used to identify security vulnerabilities in cross-language calls.
[0087] Please see Figure 3The terminal device is a computer device. In this embodiment, the computer device 60 includes a processor 61, a memory 62, and a computer program 63 stored in the memory 62 and executable on the processor 61. When executed by the processor 61, the computer program 63 implements the fluid composition calculation method in the reservoir stimulation wellbore of this embodiment. To avoid repetition, details are omitted here. Alternatively, when executed by the processor 61, the computer program 63 implements the functions of each model / unit in the static analysis system for multilingual applications of this embodiment. To avoid repetition, details are omitted here.
[0088] Computer device 60 can be a desktop computer, laptop, handheld computer, cloud server, or other computing device. Computer device 60 may include, but is not limited to, a processor 61 and a memory 62. Those skilled in the art will understand that... Figure 3 This is merely an example of computer device 60 and does not constitute a limitation on computer device 60. It may include more or fewer components than shown, or combine certain components, or different components. For example, computer device may also include input / output devices, network access devices, buses, etc.
[0089] The processor 61 may be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor may be a microprocessor or any conventional processor.
[0090] The memory 62 can be an internal storage unit of the computer device 60, such as a hard disk or RAM of the computer device 60. The memory 62 can also be an external storage device of the computer device 60, such as a plug-in hard disk, smart media card (SMC), secure digital (SD) card, flash card, etc. equipped on the computer device 60.
[0091] Furthermore, the memory 62 may include both internal storage units of the computer device 60 and external storage devices. The memory 62 is used to store computer programs and other programs and data required by the computer device. The memory 62 can also be used to temporarily store data that has been output or will be output.
[0092] Please see Figure 4 The terminal device is a chip. In this embodiment, the chip 600 includes a processor 622, which may be one or more, and a memory 632 for storing computer programs executable by the processor 622. The computer program stored in the memory 632 may include one or more modules, each corresponding to a set of instructions. Furthermore, the processor 622 may be configured to execute the computer program to perform the static analysis method for multilingual applications described above.
[0093] Additionally, chip 600 may also include a power supply component 626 and a communication component 650. The power supply component 626 can be configured to perform power management of chip 600, and the communication component 650 can be configured to enable communication of chip 600, such as wired or wireless communication. Furthermore, chip 600 may also include an input / output (I / O) interface 658. Chip 600 can operate on an operating system stored in memory 632.
[0094] In another embodiment of the present invention, a storage medium is also provided, specifically a computer-readable storage medium (memory). This computer-readable storage medium is a memory device in a terminal device used to store programs and data. It is understood that the computer-readable storage medium here can include both the built-in storage medium in the terminal device and extended storage media supported by the terminal device. The computer-readable storage medium provides storage space that stores the terminal's operating system. Furthermore, this storage space also stores one or more instructions suitable for loading and execution by a processor. These instructions can be one or more computer programs (including program code). It should be noted that the computer-readable storage medium here can be high-speed RAM or non-volatile memory, such as at least one disk storage device.
[0095] One or more instructions stored in a computer-readable storage medium can be loaded and executed by a processor to implement the corresponding steps of the static analysis method for multilingual applications in the above embodiments; one or more instructions in the computer-readable storage medium are loaded and executed by the processor in the following steps:
[0096] In a multilingual project, files in different programming languages are converted into abstract syntax trees (ASTs) and type analyzed. The ASTs are then converted into a unified intermediate representation. Type analysis information is stored in a cached dataset. This type analysis information is categorized into parsed and unparsed states. If a type lookup is successful in either parsed or unparsed state, relevant function and attribute information related to the called object is added to the intermediate representation. Based on this intermediate representation, a complete cross-language function call relationship is constructed, and a static analysis defect analysis module is used to identify security vulnerabilities in cross-language calls.
[0097] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of the present invention. The components of the embodiments of the present invention described and shown in the accompanying drawings can generally be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of the present invention provided in the accompanying drawings is not intended to limit the scope of the claimed invention, but merely to illustrate selected embodiments of the invention. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without inventive effort are within the scope of protection of the present invention.
[0098] Application Examples
[0099] Comparing the analysis results of a project containing mixed Java and Kotlin code before and after applying the technology of this invention using the same static analysis tool.
[0100] like Figure 5 As shown, the Java code file Test.java contains calls to the createThing method of the Kotlin code file ThingFactory.kt and the doSomething method of ThingInterface.kt.
[0101] The propagation path of taint data not output by the static analysis tool of this invention:
[0102] request->
[0103] param=request.getHeader("vector")->
[0104] param=URLDecoder.decode(param, "UTF-8")
[0105] After applying this invention, the propagation path of taint data output by the static analysis tool is as follows:
[0106] request->
[0107] param=request.getHeader("vector")->
[0108] param=URLDecoder.decode(param,"UTF-8")->
[0109] bar=thing.doSomething(param)->
[0110] sql="INSERT INTO users(username,password)VALUES('foo','"+bar+"')"->
[0111] statement.executeUpdate(sql,new String[]{"USERNAME","PASSWORD"});
[0112] As can be seen, the static analysis tool after applying this invention, through complete type information, completed the path analysis of cross-language function calls and discovered the SQL injection risk in the example code;
[0113] The specific operating steps are as follows:
[0114] 1. Use the JDT compiler to parse the Test.java file and convert it into an intermediate representation, and store the Test type information.
[0115] 2. Use the Kotlin compiler to parse the ThingInterface.kt, Thing1.kt, and ThingFactory.kt files, convert them into their corresponding intermediate representations, and store the type information of ThingInterface, Thing1, and ThingFactory.
[0116] 3. Analysis of the intermediate representation corresponding to the Test file revealed unresolved types ThingInterface and ThingFactory, as well as unresolved methods doSomething and createThing.
[0117] 4. Obtain the complete package name and class name through the import statements `import test.kotlin.ThingFactory` and `import test.kotlin.ThingInterface` in the Test.java file. Look up the types `test.kotlin.ThingFactory` and `test.kotlin.ThingInterface` in the pre-stored data collection and fill in the corresponding type information in the Test intermediate representation.
[0118] 5. Using static analysis tools, construct the method call graph and perform data flow analysis based on complete type information.
[0119] 6. The defect analysis module of the static analysis tool revealed a risk of SQL injection in the sample code.
[0120] As can be seen, without using the static analysis tool of this invention, the data flow analysis was interrupted when analyzing the Test.java file because the ThingInterface and ThingFactory type information could not be obtained, thus failing to accurately detect the SQL injection risk in the example code. However, by applying the technology of this invention, different languages are converted into a unified intermediate representation data in advance, and the missing type information is supplemented, thereby completing the analysis of cross-language data flow transmission and accurately detecting the SQL injection problem.
[0121] In summary, this invention provides a static analysis method, system, chip, and device for multi-language applications. It uses different compilers to convert source code from multiple languages into a unified intermediate representation, caches type information from different languages, and uses type inference to supplement the missing type and method information for cross-language interface calls in the intermediate representation. This method enables static analysis programs to analyze program problems existing in cross-language interface calls.
[0122] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the above-described division of functional units and modules is merely an example. In practical applications, the above functions can be assigned to different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above. The functional units and modules in the embodiments can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit. Furthermore, the specific names of the functional units and modules are only for easy differentiation and are not intended to limit the scope of protection of this application. The specific working process of the units and modules in the above system can be referred to the corresponding process in the foregoing method embodiments, and will not be repeated here.
[0123] In the above embodiments, the descriptions of each embodiment have different focuses. For parts that are not described in detail or recorded in a certain embodiment, please refer to the relevant descriptions of other embodiments.
[0124] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed in this invention can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementations should not be considered beyond the scope of this invention.
[0125] In the embodiments provided by this invention, it should be understood that the disclosed devices / terminals and methods can be implemented in other ways. For example, the device / terminal embodiments described above are merely illustrative. For instance, the division of modules or units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between devices or units may be electrical, mechanical, or other forms.
[0126] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0127] Furthermore, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.
[0128] If the integrated module / unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, all or part of the processes in the methods of the above embodiments can also be implemented by a computer program instructing related hardware. The computer program can be stored in a computer-readable storage medium, and when executed by a processor, it can implement the steps of the various method embodiments described above. The computer program includes computer program code, which can be in the form of source code, object code, executable files, or certain intermediate forms. The computer-readable medium can include: any entity or device capable of carrying the computer program code, recording media, USB flash drives, portable hard drives, magnetic disks, optical disks, computer memory, read-only memory (ROM), random-access memory (RAM), electrical carrier signals, telecommunication signals, and software distribution media, etc. It should be noted that the content included in the computer-readable medium can be appropriately added or removed according to the requirements of legislation and patent practice in the jurisdiction. For example, in some jurisdictions, according to legislation and patent practice, computer-readable media do not include electrical carrier signals and telecommunication signals.
[0129] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart... Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0130] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0131] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0132] The above content is only for illustrating the technical concept of the present invention and should not be construed as limiting the scope of protection of the present invention. Any modifications made to the technical solution based on the technical concept proposed in this invention shall fall within the scope of protection of the claims of this invention.
Claims
1. A static analysis method for multilingual applications, characterized in that, Includes the following steps: In a multilingual project, files in different programming languages are converted into abstract syntax trees (ASTs) and type-analyzed to obtain type analysis information; the ASTs are then converted into general and unified intermediate representation data. The type analysis information is stored in the cached dataset, specifically as follows: Store all type analysis results, establish a mapping relationship between all parsed types and intermediate representation data, and the stored data structure is divided into file name, language, type information, and the representation of type in intermediate representation data; The type analysis information in the cached dataset is divided into two states: parsed and unparsed. Specifically: Parsed data indicates that type inference has been completed and can be directly used for model detection; unparsed data enters the type inference module, which searches for relevant types in the cached data set based on the brief type information of the calling object to supplement the type information. Type inference is performed on all incompletely parsed types or methods, as follows: Retrieve the package name and class name of incompletely resolved types; based on the language type, retrieve the cached data set of other callable languages; find the corresponding type information based on the retrieved package name and class name; retrieve the data of the corresponding type in the intermediate representation; If the type lookup is successful in both the parsed and unparsed states, then the function and property information related to the called object is supplemented and added to the intermediate representation data; Based on the obtained intermediate representation data, a complete cross-language function call relationship is constructed, and the security risks of cross-language calls are discovered through the static analysis defect analysis module.
2. The static analysis method for multilingual applications according to claim 1, characterized in that, Converting files in different programming languages in a multilingual project into an abstract syntax tree specifically involves: Collect files from different programming languages in the multilingual project based on file extensions. For each language file, use the corresponding compiler to convert the source code into an abstract syntax tree and perform type analysis.
3. The static analysis method for multilingual applications according to claim 2, characterized in that, The files include source code files for different programming languages such as Java, Kotlin, and Groovy, and the compilers include the JDT compiler, Kotlin compiler, and Groovy compiler.
4. The static analysis method for multilingual applications according to claim 1, characterized in that, Based on interoperability between programming languages, obtain cached datasets of other languages used by types or methods.
5. A static analysis system for multilingual applications, characterized in that, include: The conversion module converts files from different programming languages in a multilingual project into abstract syntax trees and performs type analysis to obtain type analysis information. The data module converts the abstract syntax tree into a universal and unified intermediate representation data; The storage module stores the type analysis information into a cached dataset, specifically as follows: Store all type analysis results, establish a mapping relationship between all parsed types and intermediate representation data, and the stored data structure is divided into file name, language, type information, and the representation of type in intermediate representation data; The state module categorizes type analysis information in the cached dataset into two states: parsed and unparsed. Specifically: Parsed data indicates that type inference has been completed and can be directly used for model detection; unparsed data enters the type inference module, which searches for relevant types in the cached data set based on the brief type information of the calling object to supplement the type information. Type inference is performed on all incompletely parsed types or methods, as follows: Retrieve the package name and class name of incompletely resolved types; based on the language type, retrieve the cached data set of other callable languages; find the corresponding type information based on the retrieved package name and class name; retrieve the data of the corresponding type in the intermediate representation; The supplementary module, when the type lookup for the parsed and unparsed states obtained by the state module is successful, supplements the function and attribute information related to the called object and adds it to the intermediate representation data obtained by the data module; The analysis module, based on the intermediate representation data obtained from the supplementary module, constructs a complete cross-language function call relationship and discovers security vulnerabilities in cross-language calls through the static analysis defect analysis module.
6. A chip, characterized in that, A memory on which computer programs are stored; A processor for executing the computer program in the memory to implement the steps of the method according to any one of claims 1-4.
7. An electronic device, characterized in that, Includes the chip as described in claim 6.
Citation Information
Patent Citations
Method and device for detecting defects of program source file
CN109857641A
Compiling-independent vulnerability scanning method and device and storage medium
CN114021130A