Pollution source identification method, device, equipment and storage medium
In static taint analysis, the objective function type constructed based on the code attribute graph and multivariate function parameters is traversed to identify the taint source, which solves the problem of low recognition accuracy caused by multivariate operations in the existing technology, and achieves more accurate taint source recognition.
Patent Information
- Application Number
- CN202411874929.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-19
- Publication Date
- 2025-05-09
- Estimated Expiration
- 2044-12-19
AI Technical Summary
In the prior art, when static stain analysis contains multiple operations in Source points, accurate information cannot be obtained, resulting in missed reports and low recognition accuracy.
By obtaining the code attribute diagram of the source code to be detected, obtain the taint data flow, and traverse the data flow nodes to determine whether its node type belongs to the objective function type built based on multivariate function parameters to determine the taint source.
It realizes the accurate identification of taint sources when multiple operations are included in Source points, improves the recognition accuracy and avoids missed reports.
Smart Images

Figure CN119323027B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of software security technology, and in particular to a taint source identification method, device, equipment and storage medium. Background Art
[0002] Static taint analysis is a code inspection technology based on data flow analysis, which is mainly used to identify and track the input and output data in the application and detect whether the data has been tampered or contaminated during the entire processing process. In the existing scheme, static taint analysis can be abstracted into a triple<Source,Sink,Sanitizers> In the form of, Source represents the taint source, that is, the entry point that introduces untrusted data; Sink represents the taint sink, that is, the exit point for operations or data leakage that may cause security issues; and Sanitizers represents the harmless processing module, which is used to eliminate potential harm to data. Since the Source point is usually the location in the program that receives external input, such as user input, network request, file reading, etc., detecting the Source point (i.e., the taint source) is a key step in static taint analysis.
[0003] At present, the traditional C# language can convert source code into a code property graph (CPG), and directly match the source points in the source code through the source point information configured in the code property graph. However, this method can usually only perform source point matching and identification when the source point has only one parameter. When the source point contains multiple operations, it is usually impossible to obtain accurate source point information, which makes it easy to miss the source point, resulting in low source point identification accuracy. Summary of the invention
[0004] The main purpose of the present application is to provide a stain source identification method, device, equipment and storage medium, aiming to solve the technical problem that when the Source point matching method in the prior art contains multivariate operations in the Source point, there will be omissions due to lack of accurate information about the Source point, resulting in low identification accuracy.
[0005] To achieve the above objectives, the present application proposes a method for identifying a stain source, the method comprising:
[0006] Obtain the code attribute graph corresponding to the source code to be detected;
[0007] Acquire a tainted data stream based on the code property graph;
[0008] Traversing all data flow nodes in the tainted data flow to determine whether the node type corresponding to each data flow node belongs to the target function type, where the target function type is constructed based on multivariate function parameters;
[0009] The taint source identification result of the source code to be detected is determined based on the judgment result.
[0010] In one embodiment, the step of obtaining the tainted data stream based on the code property graph includes:
[0011] Obtaining a taint convergence point in the source code to be detected;
[0012] Determine the command execution function to which the taint convergence point belongs;
[0013] A tainted data stream is obtained based on a target parameter in the command execution function and the code attribute graph.
[0014] In one embodiment, the step of determining the taint source identification result of the source code to be detected based on the judgment result includes:
[0015] Determine, according to the judgment result, a target data flow node belonging to the target function type as a candidate taint source of the source code to be detected;
[0016] Obtaining function information of the node function corresponding to the target data flow node;
[0017] The candidate taint source is identified based on the function information and the function configuration information corresponding to the preset rule function, and a taint source identification result of the source code to be detected is obtained.
[0018] In one embodiment, the step of identifying the candidate taint source based on the function information and the function configuration information corresponding to the preset rule function to obtain the taint source identification result of the source code to be detected includes:
[0019] Acquire a first class name, a first namespace, and a first method name corresponding to the node function according to the function information;
[0020] Obtaining a second class name, a second namespace, and a second method name corresponding to the preset rule function according to the function configuration information corresponding to the preset rule function;
[0021] Completely match the first class name, the first namespace, and the first method name with the second class name, the second namespace, and the second method name, respectively;
[0022] If the complete match is successful, the total number of parameters of the node function and the preset rule function are matched based on the function information and the function configuration information;
[0023] The taint source identification result of the source code to be detected is obtained based on the total number of parameter matching results.
[0024] In one embodiment, the step of matching the total number of parameters of the node function and the preset rule function based on the function information and the function configuration information includes:
[0025] Acquire the total number of first parameters corresponding to the node function according to the function information;
[0026] Acquire the total number of second parameters corresponding to the preset rule function according to the function configuration information;
[0027] Matching the total number of the first parameters with the total number of the second parameters;
[0028] The step of obtaining the taint source identification result of the source code to be detected based on the total number of parameter matching results includes:
[0029] If the result of the parameter total number matching is successful, performing parameter type matching on the node function and the preset rule function based on the function information and the function configuration information;
[0030] A taint source identification result of the source code to be detected is obtained based on the parameter type matching result.
[0031] In one embodiment, the step of matching parameter types of the node function and the preset rule function based on the function information and the function configuration information includes:
[0032] Determine whether the parameter types of the first parameter corresponding to the node function and the second parameter corresponding to the preset rule function are consistent;
[0033] If not, obtaining the subordinate object corresponding to the first parameter according to the code attribute graph to obtain a subordinate object set;
[0034] Traversing the subordinate object set, and determining whether there is a target subordinate object in the subordinate object set that is consistent with the parameter type of the first parameter;
[0035] If so, it is determined that the candidate taint source successfully matches the preset rule function, and a parameter type matching result is obtained.
[0036] In one embodiment, after the step of completely matching the first class name, the first namespace, and the first method name with the second class name, the second namespace, and the second method name, respectively, the method further includes:
[0037] If the complete match fails, matching the first namespace with the second namespace;
[0038] If the match fails, matching the first method name with the second method name;
[0039] If the match is successful, return to the step of matching the total number of parameters of the node function and the preset rule function based on the function information and the function configuration information.
[0040] In addition, to achieve the above purpose, the present application also proposes a stain source identification device, the device comprising:
[0041] The property graph acquisition module is used to obtain the code property graph corresponding to the source code to be detected;
[0042] A data flow acquisition module, used for acquiring a tainted data flow based on the code attribute graph;
[0043] A type judgment module, used for traversing all data flow nodes in the tainted data flow to judge whether the node type corresponding to each data flow node belongs to the target function type, and the target function type is constructed based on multivariate function parameters;
[0044] The taint source identification module is used to determine the taint source identification result of the source code to be detected based on the judgment result.
[0045] In addition, to achieve the above-mentioned purpose, the present application also proposes a stain source identification device, which includes: a memory, a processor, and a computer program stored in the memory and executable on the processor, and the computer program is configured to implement the steps of the stain source identification method described above.
[0046] In addition, to achieve the above-mentioned purpose, the present application also proposes a storage medium, which is a computer-readable storage medium, and stores a computer program on the storage medium. When the computer program is executed by a processor, the steps of the stain source identification method described above are implemented.
[0047] The present application provides a taint source identification method, which discloses obtaining a code attribute graph corresponding to a source code to be detected; obtaining a tainted data stream based on the code attribute graph; traversing all data stream nodes in the tainted data stream to determine whether the node type corresponding to each data stream node belongs to a target function type, wherein the target function type is constructed based on multivariate function parameters; determining a taint source identification result of the source code to be detected based on the determination result; compared with the prior art in which Source point identification is performed by means of a code attribute graph corresponding to the source code, which can usually only be performed when the Source point has only one parameter, the present invention can construct a target function type based on multivariate function parameters, and determine whether there is a data stream node belonging to the target function type in the code attribute graph corresponding to the source code to be detected, and finally obtain a taint source identification result, thereby solving the technical problem that when the Source point matching method in the prior art contains multivariate operations in the Source point, there will be a situation where the Source point is missed due to a lack of accurate information about the Source point, resulting in low recognition accuracy. BRIEF DESCRIPTION OF THE DRAWINGS
[0048] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the present application.
[0049] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, for ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative labor.
[0050] Figure 1 A schematic diagram of a process flow provided for the first embodiment of the method for identifying a stain source of the present application;
[0051] Figure 2 This is an example diagram of the source code to be detected in the taint source identification method of this application;
[0052] Figure 3 This is an example flow chart of a data flow constructed with a code property graph in the taint source identification method of this application;
[0053] Figure 4 A flow chart of the second embodiment of the stain source identification method of the present application;
[0054] Figure 5 A flowchart of the third embodiment of the method for identifying a stain source of the present application is provided;
[0055] Figure 6 This is a schematic diagram of the module structure of the pollution source identification device according to an embodiment of the present application;
[0056] Figure 7 Schematic diagram of the device structure of the hardware operating environment involved in the stain source identification method in the embodiment of the present application.
[0057] The purpose, features and advantages of this application will be further described in conjunction with the embodiments and with reference to the accompanying drawings. DETAILED DESCRIPTION
[0058] It should be understood that the specific embodiments described herein are only used to explain the technical solutions of the present application and are not used to limit the present application.
[0059] In order to better understand the technical solution of the present application, a detailed description will be given below in conjunction with the accompanying drawings and specific implementation methods.
[0060] The main solution of the embodiment of the present application is: obtaining a code property graph corresponding to the source code to be detected; obtaining a tainted data stream based on the code property graph; traversing all data stream nodes in the tainted data stream to determine whether the node type corresponding to each data stream node belongs to a target function type, wherein the target function type is constructed based on multivariate function parameters; and determining a taint source identification result of the source code to be detected based on the determination result.
[0061] Because the prior art uses the code attribute graph corresponding to the source code to identify the Source point, it can usually only identify when the Source point has only one parameter. When the Source point contains multiple operations, it is usually impossible to obtain accurate information about the Source point, which makes it easy to miss reports, resulting in low Source point identification accuracy.
[0062] The present application provides a solution, which can construct a target function type based on multi-function parameters, and determine whether there is a data flow node belonging to the target function type in the code attribute graph corresponding to the source code to be detected, and finally obtain the taint source identification result, thereby solving the technical problem that when the Source point matching method in the prior art contains multi-operation in the Source point, there will be omissions due to lack of accurate information of the Source point, resulting in low recognition accuracy.
[0063] It should be noted that the execution subject of this embodiment may be a computing service device with data processing, network communication and program running functions, such as a tablet computer, a personal computer, a mobile phone, etc., or an electronic device capable of realizing the above functions, a taint source identification device, etc. The following takes the taint source identification device as an example (hereinafter referred to as the device) to illustrate this embodiment and the following embodiments.
[0064] Based on this, the present application embodiment provides a method for identifying a stain source, referring to Figure 1 , Figure 1This is a flow chart of the first embodiment of the pollution source identification method of the present application.
[0065] In this embodiment, the stain source identification method includes steps S10 to S40:
[0066] Step S10: Obtain a code attribute graph corresponding to the source code to be detected.
[0067] It can be understood that the source code to be detected can be any source code that needs to be subjected to static taint analysis.
[0068] It should be understood that the code property graph can be a graphical representation for describing the structure and properties of the source code to be detected, which can represent various elements (such as functions, variables, control flow, data flow, etc.) in the source code to be detected in the form of nodes, and represent the relationship between them through the connection between the nodes. The code property graph CPG combines multiple representation forms such as abstract syntax tree (AST), control flow graph (CFG) and program dependency graph (PDG) to form a unified data structure.
[0069] Step S20: Acquire the tainted data stream based on the code attribute graph.
[0070] It should be noted that the above-mentioned tainted data stream can be a data stream introduced by a tainted source in the source code to be detected. In practical applications, static taint analysis needs to observe whether the data introduced by the tainted source in the program code can be directly transmitted to the taint convergence point without being harmlessly processed. If not, it means that the system information flow is safe; if it can, it means that the system may have security issues such as privacy data leakage or dangerous data operation. Therefore, when identifying the taint source, this embodiment can obtain the data stream introduced by the tainted source in the source code to be detected.
[0071] Specifically, the step S20 includes: obtaining a taint convergence point in the source code to be detected; determining a command execution function to which the taint convergence point belongs; and obtaining a taint data flow based on a target parameter in the command execution function and the code attribute graph.
[0072] It is understandable that the command execution function can be a function used to execute commands in the source code to be detected. Correspondingly, the target parameter can be a parameter defined in the command execution function, such as the first parameter in the command execution function.
[0073] It should be noted that, refer to Figure 2 , Figure 2 This is an example diagram of the source code to be detected in the taint source identification method of this application. Figure 2The code to be detected is an example of a command line injection vulnerability in the C# language. In this code, the program can read information from a file and directly execute the read content as a command. Among them, because the file may contain malicious or dangerous information, this embodiment can define the link of reading information from the file as the "Source point": "StreamReader(filePath + "\\" + fileName)". If this information is directly used to execute commands without proper processing or verification, then the system may face the risk of being attacked. At the same time, this embodiment can define the function that executes the command (that is, the above-mentioned command execution function) as the Sink point: Process.Start(processStartInfo). Figure 2 In the example shown, there is no Sanitizers harmless processing, so only the Sink point and the Source point need to be matched to confirm that this is a command line injection. In actual applications, when identifying complex source points, such as the source point StreamReader (filePath + "\\" + fileName) in the following code, if a function type source point is matched according to the traditional matching method, it is usually required to accurately match the function name, parameter index, parameter type, and the number of function parameters. However, due to Figure 2 The parameter of the code is a binary operation, so the match will fail at this time. Therefore, this embodiment proposes a stain source identification method that can realize multi-parameters, so that the identification of Source points in complex scenes can be realized and the accuracy of Source point identification can be improved.
[0074] In the specific implementation, static taint analysis needs to configure the Sink point and Source point, and find the corresponding vulnerability through these configured feature points. Figure 3 , Figure 3 This is an example flow chart of the data flow constructed with the code attribute graph in the taint source identification method of this application. Figure 3 As shown, it can be Figure 2 The first parameter of the Process.Start function (i.e., the command execution function) on line 16 in the source code to be detected is used as the Sink point (taint convergence point), and the first parameter of the StreamReader function on line 9 is used as the Source point. Then, the first parameter processStartInfo in the Process.Start function can be determined as the above target parameter, and the parameter processStartInfo can be tracked in the code property graph corresponding to the source code to be detected, so as to obtain the corresponding tainted data flow.
[0075] Step S30: traverse all data flow nodes in the tainted data flow to determine whether the node type corresponding to each data flow node belongs to the target function type, and the target function type is constructed based on multivariate function parameters.
[0076] It should be noted that the above-mentioned target function type can be a function type used to verify the Source point. In this embodiment, the function type can be used as an example to verify the Source point, but the Source point is not limited to the function type. The Source point can also be other types, and the processing method of other types is consistent with the function type. Among them, the target function type can be constructed based on multiple function parameters. In this embodiment, the target function type can be defined as: namespace + class name + function name (namespace and class name can be empty) + parameter subscript + number of parameters + parameter type, for example, FunctionRule ("System.Diagnostics", "Process", "Start", 1, 1, "String").
[0077] Step S40: determining the taint source identification result of the source code to be detected based on the judgment result.
[0078] In actual applications, the device can traverse all data flow nodes in the tainted data flow to verify the type of each node in the tainted data flow. Specifically, the traversal can be started from the first node of the tainted data flow. If the data flow node does not belong to the target function type, the node is skipped and the traversal continues to the next node; if the data flow node belongs to the target function type, the data flow node is verified to determine whether it can match the Source point. If so, the traversal of the data flow node is terminated and true is returned, which means that the Source point is matched in the data flow node, and the tainted source identification result is finally obtained.
[0079] The present embodiment provides a taint source identification method, which discloses obtaining a code attribute graph corresponding to a source code to be detected; obtaining a tainted data stream based on the code attribute graph; traversing all data stream nodes in the tainted data stream to determine whether the node type corresponding to each data stream node belongs to a target function type, wherein the target function type is constructed based on multivariate function parameters; determining a taint source identification result of the source code to be detected based on the determination result; compared with the prior art in which Source point identification is performed by means of a code attribute graph corresponding to the source code, which can usually only be performed when the Source point has only one parameter, the present embodiment can construct a target function type based on multivariate function parameters, and determine whether there is a data stream node belonging to the target function type in the code attribute graph corresponding to the source code to be detected, and finally obtain a taint source identification result, thereby solving the technical problem that when the Source point matching method in the prior art contains multivariate operations in the Source point, there will be a situation where the Source point is missed due to a lack of accurate information about the Source point, resulting in low recognition accuracy.
[0080] Based on the first embodiment of the present application, in the second embodiment of the present application, the same or similar contents as those in the above-mentioned embodiment 1 can be referred to the above introduction, and will not be repeated in the following. Figure 4 , Figure 4 A flow chart of the second embodiment of the stain source identification method of the present application is provided.
[0081] In this embodiment, step S40 includes steps S41 to S43:
[0082] Step S41: according to the judgment result, the target data flow node belonging to the target function type is determined as a candidate taint source of the source code to be detected.
[0083] It should be understood that the target data flow node may be a node whose node type belongs to the target function type; correspondingly, the candidate taint source may be a node used to characterize a taint source in the tainted data flow that may match the source code to be detected.
[0084] In this embodiment, if the type of the target data flow node in the tainted data stream belongs to the target function type, it can be assumed that the real Source point can be matched in the currently traversed target data flow node: new StreamReader(filePath + "\\" + fileName), that is, at this time, the node belonging to the target function type can be determined as a candidate taint source of the source code to be detected.
[0085] Step S42: Obtain function information of the node function corresponding to the target data flow node.
[0086] It can be understood that the above-mentioned node function can be a function representing the target data flow node; accordingly, the above-mentioned function information, that is, the relevant information of the node function, includes: function name, function type, function namespace, class name, total number of function parameters, etc., and this embodiment does not impose any restrictions on this.
[0087] Step S43: Identify the candidate taint source based on the function information and the function configuration information corresponding to the preset rule function to obtain a taint source identification result of the source code to be detected.
[0088] It should be understood that the above-mentioned preset rule function can be a function used to verify Source and whose function type is the target function type, for example, FunctionRule("System.Diagnostics", "Process", "Start", 1, 1, "String"). Accordingly, the above-mentioned function configuration information can be relevant information of the preset rule function, including: the function name, function type, function namespace, class name, total number of function parameters, etc. of the preset rule function.
[0089] In this embodiment, the device can match the function information of the node function represented by the target data flow node with the function information of the preset rule function, and determine whether the Source point of the source code to be detected can be matched in the target data flow node based on the matching result of whether the two can be successfully matched, thereby obtaining the taint source identification result of the source code to be detected.
[0090] Furthermore, the step S43 includes:
[0091] Step S43a: Obtain the first class name, the first namespace and the first method name corresponding to the node function according to the function information.
[0092] It can be understood that the above-mentioned first class name, first namespace and first method name can be the class name, namespace and method name corresponding to the node function respectively.
[0093] Step S43b: Obtain the second class name, the second namespace and the second method name corresponding to the preset rule function according to the function configuration information corresponding to the preset rule function.
[0094] It can be understood that the above-mentioned second class name, second namespace and second method name can be the class name, namespace and method name corresponding to the preset rule function respectively.
[0095] Step S43c: Completely match the first class name, the first namespace and the first method name with the second class name, the second namespace and the second method name respectively.
[0096] It should be noted that the above-mentioned complete match can be an operation of matching the function's namespace + class name + method name. In this embodiment, the first class name corresponding to the node function can be matched with the second class name corresponding to the preset rule function, and the first namespace corresponding to the node function can be matched with the second namespace corresponding to the preset rule function. At the same time, the first method name corresponding to the node function can be matched with the second method name corresponding to the preset rule function, thereby achieving a complete match of the node function and the preset rule function.
[0097] Step S43d: If the complete match is successful, the total number of parameters of the node function and the preset rule function are matched based on the function information and the function configuration information.
[0098] It should be understood that if the first class name and the second class name, the first namespace and the second namespace, and the first method name and the second method name can all be successfully matched, it means that the complete match is successful, otherwise it means that the complete match fails.
[0099] It should be noted that the above-mentioned total number of parameter matching may be a process of matching the total number of parameters in the node function and the preset rule function.
[0100] Step S43e: obtaining the taint source identification result of the source code to be detected based on the total number of parameter matching results.
[0101] Furthermore, after step S43c, it also includes: if the complete match fails, matching the first namespace and the second namespace; if the match fails, matching the first method name and the second method name; if the match succeeds, returning to the step of matching the total number of parameters of the node function and the preset rule function based on the function information and the function configuration information.
[0102] In actual applications, if the namespace, class name and method name between the node function and the preset rule function can be successfully matched, the total number of parameters in the function information of the node function and the function configuration information of the preset rule function can be matched, and the taint source identification result of the source code to be detected can be obtained based on the matching result. In addition, if the namespace, class name and method name between the node function and the preset rule function fail to match, the namespace between the node function and the preset rule function can be matched. If the match still fails, only the method name between the node function and the preset rule function is matched. If the match is successful, the step of matching the total number of parameters of the node function and the preset rule function based on the function information and the function configuration information can be returned to continue to match the node function and the preset rule function more accurately.
[0103] In the present embodiment, it is disclosed that a target data flow node belonging to a target function type is determined as a candidate taint source of a source code to be detected according to a judgment result; function information of a node function corresponding to the target data flow node is obtained; the candidate taint source is identified based on the function information and function configuration information corresponding to a preset rule function, and a taint source identification result of the source code to be detected is obtained. Since the present embodiment can match the function information between the node function corresponding to the target data flow node in the tainted data flow and the preset rule function, and accurately determine whether the candidate taint source is the taint source of the source code to be detected according to the matching result, the accuracy of taint source identification is improved.
[0104] Based on the first embodiment and / or the second embodiment of the present application, in the third embodiment of the present application, the same or similar contents as those in the above embodiments can be referred to the above introduction, and will not be described in detail later. Figure 5 , Figure 5 A flowchart diagram of the third embodiment of the stain source identification method of the present application is provided.
[0105] In this embodiment, step S43d also includes steps S431-S433:
[0106] Step S431: Obtain the total number of first parameters corresponding to the node function according to the function information.
[0107] It can be understood that the above-mentioned first total number of parameters may be the total number of parameters in the node function.
[0108] Step S432: Obtain the total number of second parameters corresponding to the preset rule function according to the function configuration information.
[0109] It can be understood that the above-mentioned second total number of parameters may be the total number of parameters in the preset rule function.
[0110] Step S433: Match the total number of the first parameters with the total number of the second parameters.
[0111] Correspondingly, the step S43e further includes steps S434-S435:
[0112] Step S434: If the result of the parameter total number matching is a successful match, parameter type matching is performed on the node function and the preset rule function based on the function information and the function configuration information.
[0113] It should be noted that the above parameter type matching may be a process of matching the types of parameters in the node function and the preset rule function.
[0114] In this embodiment, the device can first obtain the total number of first parameters corresponding to the node function according to the function information of the node function, and obtain the total number of second parameters corresponding to the preset rule function according to the function configuration information of the preset rule function. For example, if the total number of parameters corresponding to the node function StreamReader(filePath + "\\" + fileName) is 1, and the total number of parameters set by the preset rule function FunctionRule is also 1, it means that the node function and the preset rule function are matched successfully. At this time, the parameter type matching of the node function and the preset rule function can continue.
[0115] Furthermore, the step of continuing to match the parameter types of the node function and the preset rule function may include: determining whether the parameter types of the first parameter corresponding to the node function and the second parameter corresponding to the preset rule function are consistent; if not, obtaining the subordinate object corresponding to the first parameter according to the code attribute graph to obtain a subordinate object set; traversing the subordinate object set and determining whether there is a target subordinate object in the subordinate object set that is consistent with the parameter type of the first parameter; if so, determining that the candidate taint source is successfully matched with the preset rule function to obtain a parameter type matching result.
[0116] It should be noted that the above first parameter may be the first parameter in the node function.
[0117] In practical applications, this embodiment can obtain the code attribute graph corresponding to the source code to be detected. Figure 2 The first parameter of the StreamReader function in the code is obtained by taking filePath + "\\" + fileName, which is the first parameter mentioned above. Then, it can be determined whether the parameter type of the first parameter is consistent with the parameter type defined in the predefined preset rule function (that is, the parameter type of the second parameter mentioned above). If not, the first parameter can be further parsed and matched. Specifically, first, all subordinate objects of the first parameter can be obtained according to the code attribute graph, that is, all objects under the first parameter in the code attribute graph, so as to obtain the object set of filePath and fileName (that is, the above-mentioned subordinate object set), and then traverse the obtained object set to match the object type, that is, it can be determined whether there is a target subordinate object in the subordinate object set that is consistent with the parameter type of the first parameter. If so, it means that the Source point is matched, and the parameter type matching result is a successful match.
[0118] Step S435: obtaining a taint source identification result of the source code to be detected based on the parameter type matching result.
[0119] In this embodiment, if the parameter type matching result is a successful match, it means that the Source point is matched, that is, the target data flow node in the data flow node is the taint source of the source code to be detected, thereby realizing the taint source identification of the source code to be detected.
[0120] In the present embodiment, it is disclosed that the total number of first parameters corresponding to the node function is obtained according to the function information; the total number of second parameters corresponding to the preset rule function is obtained according to the function configuration information; the total number of first parameters and the total number of second parameters are matched; if the result of the total number of parameters matching is a successful match, the node function and the preset rule function are matched with parameter types based on the function information and the function configuration information; the taint source identification result of the source code to be detected is obtained based on the parameter type matching result. Since the present embodiment can continue to match the node function and the preset rule function more accurately when the complete match between the node function and the preset rule function is successful, the accuracy of taint source identification can be further improved.
[0121] It should be noted that the above examples are only used to understand the present application and do not constitute a limitation on the stain source identification method of the present application. More simple transformations based on this technical concept are all within the protection scope of the present application.
[0122] This application also provides a stain source identification device, please refer to Figure 6 , the stain source identification device comprises:
[0123] The property graph acquisition module 10 is used to acquire a code property graph corresponding to the source code to be detected;
[0124] A data flow acquisition module 20, used for acquiring a tainted data flow based on the code attribute graph;
[0125] A type determination module 30, used for traversing all data flow nodes in the tainted data flow to determine whether the node type corresponding to each data flow node belongs to the target function type, and the target function type is constructed based on multivariate function parameters;
[0126] The taint source identification module 40 is used to determine the taint source identification result of the source code to be detected based on the judgment result.
[0127] The stain source identification device provided by the present application adopts the stain source identification method in the above embodiment, which can solve the technical problem that when the matching method of the Source point in the prior art includes multivariate operations in the Source point, there will be omissions due to lack of accurate information of the Source point, resulting in low identification accuracy. Compared with the prior art, the beneficial effects of the stain source identification device provided by the present application are the same as the beneficial effects of the stain source identification method provided by the above embodiment, and the other technical features of the stain source identification device are the same as the features disclosed in the above embodiment method, which will not be repeated here.
[0128] The present application provides a taint source identification device, which includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the taint source identification method in the above-mentioned embodiment 1.
[0129] Reference below Figure 7 , which shows a schematic diagram of the structure of a stain source identification device suitable for implementing the embodiment of the present application. The stain source identification device in the embodiment of the present application may include but is not limited to mobile terminals such as mobile phones, laptop computers, digital broadcast receivers, PDAs (Personal Digital Assistants), PADs (Portable Application Descriptions), PMPs (Portable Media Players), vehicle-mounted terminals (such as vehicle-mounted navigation terminals), etc., and fixed terminals such as digital TVs, desktop computers, etc. Figure 7 The pollution source identification device shown is merely an example and should not bring any limitation to the functions and scope of use of the embodiments of the present application.
[0130] like Figure 7As shown, the stain source identification device may include a processing device 1001 (such as a central processing unit, a graphics processor, etc.), which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM: Read Only Memory) 1002 or a program loaded from a storage device 1003 to a random access memory (RAM: Random Access Memory) 1004. In RAM1004, various programs and data required for the operation of the stain source identification device are also stored. The processing device 1001, ROM1002 and RAM1004 are connected to each other through a bus 1005. An input / output (I / O) interface 1006 is also connected to the bus. Generally, the following systems can be connected to the I / O interface 1006: an input device 1007 including, for example, a touch screen, a touch pad, a keyboard, a mouse, an image sensor, a microphone, an accelerometer, a gyroscope, etc.; an output device 1008 including, for example, a liquid crystal display (LCD: Liquid Crystal Display), a speaker, a vibrator, etc.; a storage device 1003 including, for example, a magnetic tape, a hard disk, etc.; and a communication device 1009. The communication device 1009 can allow the stain source identification device to communicate with other devices wirelessly or by wire to exchange data. Although the stain source identification device with various systems is shown in the figure, it should be understood that it is not required to implement or have all the systems shown. More or fewer systems can be implemented or have alternatively.
[0131] In particular, according to the embodiments disclosed in the present application, the process described above with reference to the flowchart can be implemented as a computer software program. For example, the embodiments disclosed in the present application include a computer program product, which includes a computer program carried on a computer-readable medium, and the computer program includes a program code for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from a network through a communication device, or installed from a storage device 1003, or installed from a ROM 1002. When the computer program is executed by the processing device 1001, the above-mentioned functions defined in the method of the embodiment disclosed in the present application are executed.
[0132] The stain source identification device provided by the present application adopts the stain source identification method in the above embodiment to solve the technical problem of stain source identification. Compared with the prior art, the beneficial effects of the stain source identification device provided by the present application are the same as the beneficial effects of the stain source identification method provided by the above embodiment, and other technical features in the stain source identification device are the same as the features disclosed in the method of the previous embodiment, which will not be repeated here.
[0133] It should be understood that the various parts disclosed in this application can be implemented by hardware, software, firmware or a combination thereof. In the description of the above embodiments, specific features, structures, materials or characteristics can be combined in any one or more embodiments or examples in a suitable manner.
[0134] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art who is familiar with the present technical field can easily think of changes or substitutions within the technical scope disclosed in the present application, which should be included in the protection scope of the present application. Therefore, the protection scope of the present application should be based on the protection scope of the claims.
[0135] The present application provides a computer-readable storage medium having computer-readable program instructions (ie, computer programs) stored thereon, and the computer-readable program instructions are used to execute the stain source identification method in the above-mentioned embodiment.
[0136] The computer-readable storage medium provided in the present application may be, for example, a USB flash drive, but is not limited to electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, systems or devices, or any combination of the above. More specific examples of computer-readable storage media may include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM: Random Access Memory), a read-only memory (ROM: Read Only Memory), an erasable programmable read-only memory (EPROM: Erasable Programmable Read Only Memory or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM: CD-Read Only Memory), an optical storage device, a magnetic storage device, or any suitable combination of the above. In this embodiment, the computer-readable storage medium may be any tangible medium containing or storing a program, which may be used by or in combination with an instruction execution system, system or device. The program code contained on the computer-readable storage medium may be transmitted using any appropriate medium, including but not limited to: wires, optical cables, RF (Radio Frequency: Radio Frequency), etc., or any suitable combination of the above.
[0137] The computer-readable storage medium may be included in the stain source identification device; or may exist independently without being assembled into the stain source identification device.
[0138] The computer-readable storage medium carries one or more programs. When the one or more programs are executed by a taint source identification device, the taint source identification device: obtains a code property graph corresponding to the source code to be detected; obtains a taint data stream based on the code property graph; traverses all data stream nodes in the taint data stream to determine whether the node type corresponding to each data stream node belongs to a target function type, wherein the target function type is constructed based on multivariate function parameters; and determines a taint source identification result of the source code to be detected based on the determination result.
[0139] Computer program code for performing the operations of the present application may be written in one or more programming languages or a combination thereof, including object-oriented programming languages such as Java, Smalltalk, C++, and conventional procedural programming languages such as "C" or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, as a separate software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., via the Internet using an Internet service provider).
[0140] The flow chart and block diagram in the accompanying drawings illustrate the possible architecture, function and operation of the system, method and computer program product according to various embodiments of the present application. In this regard, each square box in the flow chart or block diagram can represent a module, a program segment or a part of a code, and the module, the program segment or a part of the code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the square box can also occur in a sequence different from that marked in the accompanying drawings. For example, two square boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each square box in the block diagram and / or flow chart, and the combination of the square boxes in the block diagram and / or flow chart can be implemented with a dedicated hardware-based system that performs a specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.
[0141] The modules involved in the embodiments described in this application may be implemented by software or hardware, wherein the name of the module does not constitute a limitation on the unit itself in some cases.
[0142] The readable storage medium provided by the present application is a computer-readable storage medium, which stores computer-readable program instructions (i.e., computer programs) for executing the above-mentioned taint source identification method, and can solve the technical problem that when the matching method of the Source point in the prior art includes multivariate operations in the Source point, there will be omissions due to lack of accurate information of the Source point, resulting in low identification accuracy. Compared with the prior art, the beneficial effects of the computer-readable storage medium provided by the present application are the same as the beneficial effects of the taint source identification method provided by the above-mentioned embodiment, and will not be repeated here.
[0143] The above descriptions are only some embodiments of the present application, and are not intended to limit the patent scope of the present application. All equivalent structural changes made using the contents of the present application specification and drawings under the technical concept of the present application, or direct / indirect applications in other related technical fields are included in the patent protection scope of the present application.
Claims
1. A method for identifying a stain source, characterized in that: The method includes: Obtain the code attribute graph corresponding to the source code to be detected; Acquire a tainted data stream based on the code property graph; Traversing all data flow nodes in the tainted data flow to determine whether the node type corresponding to each data flow node belongs to the target function type, where the target function type is constructed based on multivariate function parameters; Determine the taint source identification result of the source code to be detected based on the judgment result; The step of determining the taint source identification result of the source code to be detected based on the judgment result includes: Determine, according to the judgment result, a target data flow node belonging to the target function type as a candidate taint source of the source code to be detected; Obtaining function information of the node function corresponding to the target data flow node; Acquire a first class name, a first namespace, and a first method name corresponding to the node function according to the function information; Obtaining a second class name, a second namespace, and a second method name corresponding to the preset rule function according to the function configuration information corresponding to the preset rule function; Completely match the first class name, the first namespace, and the first method name with the second class name, the second namespace, and the second method name, respectively; If the complete match is successful, the total number of parameters of the node function and the preset rule function are matched based on the function information and the function configuration information; Obtaining a taint source identification result of the source code to be detected based on the total number of parameter matching results; The step of matching the total number of parameters of the node function and the preset rule function based on the function information and the function configuration information comprises: Acquire the total number of first parameters corresponding to the node function according to the function information; Acquire the total number of second parameters corresponding to the preset rule function according to the function configuration information; Matching the total number of the first parameters with the total number of the second parameters; The step of obtaining the taint source identification result of the source code to be detected based on the total number of parameter matching results includes: If the result of the parameter total number matching is successful, performing parameter type matching on the node function and the preset rule function based on the function information and the function configuration information; A taint source identification result of the source code to be detected is obtained based on the parameter type matching result.
2. The method according to claim 1, characterized in that The step of obtaining the tainted data stream based on the code property graph includes: Obtaining a taint convergence point in the source code to be detected; Determine the command execution function to which the taint convergence point belongs; A tainted data stream is obtained based on a target parameter in the command execution function and the code attribute graph.
3. The method according to claim 1, characterized in that The step of matching parameter types of the node function and the preset rule function based on the function information and the function configuration information includes: Determine whether the parameter types of the first parameter corresponding to the node function and the second parameter corresponding to the preset rule function are consistent; If not, obtaining the subordinate object corresponding to the first parameter according to the code attribute graph to obtain a subordinate object set; Traversing the subordinate object set, and determining whether there is a target subordinate object in the subordinate object set that is consistent with the parameter type of the first parameter; If so, it is determined that the candidate taint source successfully matches the preset rule function, and a parameter type matching result is obtained.
4. The method according to claim 1, characterized in that After the step of completely matching the first class name, the first namespace, and the first method name with the second class name, the second namespace, and the second method name respectively, the method further includes: If the complete match fails, matching the first namespace with the second namespace; If the match fails, matching the first method name with the second method name; If the match is successful, return to the step of matching the total number of parameters of the node function and the preset rule function based on the function information and the function configuration information.
5. A stain source identification device, characterized in that: The device comprises: The property graph acquisition module is used to obtain the code property graph corresponding to the source code to be detected; A data flow acquisition module, used for acquiring a tainted data flow based on the code attribute graph; A type judgment module, used for traversing all data flow nodes in the tainted data flow to judge whether the node type corresponding to each data flow node belongs to the target function type, and the target function type is constructed based on multivariate function parameters; A taint source identification module, used to determine a taint source identification result of the source code to be detected based on the judgment result; The taint source identification module is further used to determine the target data flow node belonging to the target function type as the candidate taint source of the source code to be detected according to the judgment result; obtain the function information of the node function corresponding to the target data flow node; obtain the first class name, the first namespace and the first method name corresponding to the node function according to the function information; obtain the second class name, the second namespace and the second method name corresponding to the preset rule function according to the function configuration information corresponding to the preset rule function; fully match the first class name, the first namespace and the first method name with the second class name, the second namespace and the second method name respectively; if the complete match is successful, match the total number of parameters of the node function and the preset rule function based on the function information and the function configuration information; obtain the taint source identification result of the source code to be detected based on the total number of parameters matching result; The taint source identification module is also used to obtain the total number of first parameters corresponding to the node function according to the function information; obtain the total number of second parameters corresponding to the preset rule function according to the function configuration information; match the first total number of parameters with the second total number of parameters; if the parameter total number matching result is a successful match, perform parameter type matching on the node function and the preset rule function based on the function information and the function configuration information; and obtain the taint source identification result of the source code to be detected based on the parameter type matching result.
6. A pollution source identification device, characterized in that: The device comprises: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the computer program is configured to implement the steps of the pollution source identification method according to any one of claims 1 to 4.
7. A storage medium, characterized in that: The storage medium is a computer-readable storage medium, and a computer program is stored on the storage medium. When the computer program is executed by a processor, the steps of the pollution source identification method according to any one of claims 1 to 4 are implemented.
Citation Information
Patent Citations
Application program vulnerability detection method and device, computer equipment and storage medium
CN112560045A
Dynamic and static ANDROID privacy leakage detection method and system based on data flow analysis
CN116881907A