一种基于反汇编语义信息的可执行软件溢出漏洞预测方法

By designing overflow vulnerability behavior patterns from disassembled semantic information, utilizing the transformation features of convolutional neural networks and temporal convolutional networks, and combining them with a multilayer perceptron model, the problem of insufficient generalization ability in overflow vulnerability detection in existing technologies is solved, achieving accurate prediction and efficient detection of overflow vulnerabilities in executable software.

CN117874762BActive Publication Date: 2026-07-17YANSHAN UNIV

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
YANSHAN UNIV
Filing Date
2023-12-15
Publication Date
2026-07-17

AI Technical Summary

Technical Problem

Existing vulnerability detection methods are unable to comprehensively detect overflow vulnerabilities in executable software or fail under complexity and encryption measures, and the diversity of features after disassembly leads to insufficient generalization ability.

Method used

The design incorporates overflow vulnerability behavior patterns from disassembled semantic information. By converting binary and assembly code features using convolutional neural networks and temporal convolutional networks, and combining this with a multilayer perceptron model, overflow vulnerability features are accurately extracted and input to improve prediction generalization capabilities.

Benefits of technology

It achieves accurate prediction of executable software overflow vulnerabilities, improves the generalization ability and applicability of prediction, and reduces the consumption of computing resources.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117874762B_ABST
    Figure CN117874762B_ABST
Patent Text Reader

Abstract

本发明公开了一种基于反汇编语义信息的可执行软件溢出漏洞预测方法,属于计算机安全技术和漏洞检测技术领域,包括以下步骤:S1:设计反汇编语义信息中的多种溢出漏洞行为模式;S2:设计可执行软件中的溢出漏洞特征;S3:将集合ESVF中包含的二进制代码特征通过卷积神经网络(CNN)转换为特征矩阵;S4:将集合ESVF中包含寄存器信息的汇编代码特征通过时间卷积网络(TCN)转换为特征矩阵;S5:设计预测可执行软件中的溢出漏洞模型。本发明能够针对可执行软件准确提取溢出漏洞特征和溢出漏洞特征中的语义信息,能够依据多种反汇编语义信息保存软件中的执行特征并精准输入到预测模型中提高预测溢出漏洞的泛化能力。
Need to check novelty before this filing date? Find Prior Art