Code Reachability Analysis Method, Device, Electronic Device, Product and Storage Medium
Through the construction of intermediate expression technology and the concrete function instruction information set, the problem of insufficient code accessibility analysis in the existing technology is solved, efficient and accurate code accessibility analysis is achieved, traceability of source code is enhanced, and a practical technical basis is provided for code vulnerability detection and security assessment.
Patent Information
- Application Number
- CN202510053265.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-14
- Publication Date
- 2025-06-27
- Estimated Expiration
- 2045-01-14
AI Technical Summary
When facing the complex language characteristics of modern programming languages, the prior art cannot provide high-precision and efficient code accessibility analysis, resulting in the inability to detect potential security risks and logical errors in a timely manner.
By introducing intermediate expression technology, the source code is compiled into intermediate expression instruction set, the function instruction set is determined and the abstract variable name is replaced with actual class names, the concrete function instruction information set is constructed, and the preset dangerous function instruction information is matched to determine the reachability of each function in the code.
Improves the accuracy and efficiency of code analysis, ensures that no potential calling paths are left out in complex inheritance and polymorphic calling scenarios, and provides reliable support for code vulnerability detection and security evaluation.
Smart Images

Figure CN119473309B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of code analysis, and particularly to a code reachability analysis method, device, electronic device, product, and storage medium. Background Art
[0002] In modern software development, with the wide application of object-oriented programming languages, many advanced features have been introduced into programming languages, such as inheritance, polymorphism, generics, etc. This means that programs are becoming increasingly complex. Without in-depth analysis of these advanced features, potential security risks and logical errors may exist in the code. Existing technologies usually rely on static analysis technologies such as control flow graph analysis technology, data flow analysis technology, and symbolic execution analysis technology to analyze the advanced features in programming languages.
[0003] However, these existing technologies also have certain defects. For example, the control flow graph analysis technology has low precision when dealing with polymorphism and indirect calls; the data flow analysis technology is difficult to handle complex reference relationships, especially dynamic types and polymorphism; the symbolic execution analysis technology cannot meet the analysis requirements of large-scale projects in terms of path explosion and state space expansion problems. It can be seen that existing technologies cannot provide high-precision and high-efficiency code reachability analysis when facing the complex language features in modern programming languages, and thus potential vulnerabilities in the program may not be discovered in time. Summary of the Invention
[0004] The present invention provides a code reachability analysis method, device, electronic device, product, and storage medium to solve the defect that existing technologies cannot provide high-precision and high-efficiency code reachability analysis when facing the complex language features in modern programming languages.
[0005] The present invention provides a code reachability analysis method, including:
[0006] Obtain source code, compile the source code to obtain an intermediate representation instruction set;
[0007] Determine a function instruction set from the intermediate representation instruction set, and replace the abstract variable names of each function instruction in the function instruction set with actual class names to obtain a concretized function instruction set; any function instruction in the function instruction set represents the execution logic of a function in the source code;
[0008] Based on the call information of each concretized function instruction in the concretized function instruction set, obtain a concretized function instruction information set, and any concretized function instruction information in the concretized function instruction information set represents the execution logic of a function in the source code and the call information of the function;
[0009] Based on the matching results of each concrete function instruction information in the concrete function instruction information set and each preset dangerous function instruction information in the preset dangerous function instruction information set, the reachability of each function in the source code is determined.
[0010] According to a code reachability analysis method provided by the present invention, before obtaining the specific function instruction information set based on the call information of each specific function instruction in the specific function instruction set, the method includes:
[0011] Based on the type information and parameter transfer path of each concrete function instruction in the concrete function instruction set, calling information of each concrete function instruction in the concrete function instruction set is determined.
[0012] According to a code reachability analysis method provided by the present invention, the type information of the specific function instruction includes a local function type, an inherited function type or an overloaded function type; the call information of the specific function instruction includes independent call information, inheritance chain call information or polymorphic call information;
[0013] The calling information of any of the specific function instructions is determined based on the following method:
[0014] If the type information of the specific function instruction is a local function type, determining the call information of the specific function instruction as independent call information;
[0015] If the type information of the specific function instruction is an inherited function type, determining the calling information of the specific function instruction as inheritance chain calling information;
[0016] If the type information of the specific function instruction is an overloaded function type, the calling information of the specific function instruction is determined to be polymorphic calling information.
[0017] According to a code reachability analysis method provided by the present invention, after determining the call information of each concrete function instruction in the concrete function instruction set, the method further includes:
[0018] Classify and mark each concrete function instruction in the concrete function instruction set based on the calling information of each concrete function instruction in the concrete function instruction set.
[0019] According to a code reachability analysis method provided by the present invention, the reachability of each function in the source code is determined based on the matching results of each specific function instruction information in the specific function instruction information set and each preset dangerous function instruction information in the preset dangerous function instruction information set, including:
[0020] If the concretization function instruction information in the concretization function instruction information set matches the preset dangerous function instruction information in the preset dangerous function instruction information set, the concretization function instruction information to be analyzed is determined;
[0021] Analyze the concretization function instruction information to be analyzed to obtain a reachability analysis result;
[0022] Among them, the reachability analysis result is used to determine the reachability of the function represented by the concretization function instruction information to be analyzed in the source code.
[0023] According to a code reachability analysis method provided by the present invention, the reachability analysis result includes the location information of the function represented by the concretization function instruction information to be analyzed in the source code, an execution logic risk prompt, and a call information risk prompt.
[0024] The present invention also provides a code reachability analysis device, including:
[0025] A compilation module, which is used to obtain the source code, compile the source code, and obtain an intermediate expression instruction set;
[0026] A concretization function instruction set determination module, which is used to determine a function instruction set from the intermediate expression instruction set, and replace the abstract variable names of each function instruction in the function instruction set with actual class names to obtain a concretization function instruction set; any function instruction in the function instruction set represents the execution logic of the function in the source code;
[0027] A concretization function instruction information set determination module, which is used to obtain a concretization function instruction information set based on the call information of each concretization function instruction in the concretization function instruction set, and any concretization function instruction information in the concretization function instruction information set represents the execution logic of the function in the source code and the call information of the function;
[0028] A reachability analysis module, which is used to determine the reachability of each function in the source code based on the matching results of each concretization function instruction information in the concretization function instruction information set and each preset dangerous function instruction information in the preset dangerous function instruction information set.
[0029] The present invention also provides an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor, and when the processor executes the computer program, the code reachability analysis method described in any one of the above is implemented.
[0030] The present invention also provides a non-transitory computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the code reachability analysis method described in any one of the above is implemented.
[0031] The present invention also provides a computer program product, including a computer program which, when executed by a processor, implements the code reachability analysis method as described in any one of the above.
[0032] The code reachability analysis method, apparatus, electronic device, product and storage medium provided by the present invention. The method includes obtaining source code, compiling the source code to obtain an intermediate representation instruction set; determining a function instruction set from the intermediate representation instruction set, and replacing the abstract variable names of each function instruction in the function instruction set with actual class names to obtain a concretized function instruction set; any function instruction in the function instruction set represents the execution logic of a function in the source code; based on the call information of each concretized function instruction in the concretized function instruction set, a concretized function instruction information set is obtained, and any concretized function instruction information in the concretized function instruction information set represents the execution logic of a function in the source code and the call information of the function; based on the matching results of each concretized function instruction information in the concretized function instruction information set and each preset dangerous function instruction information in the preset dangerous function instruction information set, the reachability of each function in the source code is determined. By introducing the intermediate representation technology, the present invention transforms the complex code structure into an intermediate layer data structure convenient for analysis, and provides an effective solution to the problem of insufficient accuracy of the existing code reachability analysis technology in dealing with the advanced features of modern programming languages. Specifically, by concretizing the function instruction set in the intermediate representation, that is, replacing the abstract variable names of each function instruction with actual class names, the uncertainty caused by dynamic types and polymorphism is eliminated, and the actual call target of the function is clarified. This not only greatly improves the accuracy of code analysis, but also simplifies the analysis logic and improves the execution efficiency. Further, by constructing a concretized function instruction information set, the execution logic and call information of each function in the source code are completely mapped to the concretized structure of the intermediate representation, realizing the function of quickly tracing back from the analysis result to the source code, and then being able to efficiently and accurately determine the reachability of each function in the source code, ensuring that no potential call paths are missed in complex inheritance and polymorphic call scenarios; in addition, by matching each concretized function instruction information with each preset dangerous function instruction information in the preset dangerous function instruction information set, potential dangerous call paths are quickly identified, thereby providing reliable support for code vulnerability detection and security assessment. Compared with the prior art, the present invention not only improves the analysis accuracy and efficiency, but also enhances the traceability of the source code, providing a practical technical basis for code reachability analysis. Description of the Drawings
[0033] To more clearly illustrate the technical solutions in the present invention or the prior art, the following will briefly introduce the accompanying drawings required for the description of the embodiments or the prior art. Obviously, the accompanying drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can also be obtained based on these drawings.
[0034] Figure 1 It is a schematic flowchart of the code reachability analysis method provided by the present invention.
[0035] Figure 2 It is a schematic structural diagram of the code reachability analysis device provided by the present invention.
[0036] Figure 3 It is a schematic structural diagram of the electronic device provided by the present invention. Detailed implementation manners
[0037] To make the objectives, technical solutions and advantages of the present invention clearer, the following will clearly and completely describe the technical solutions in the present invention with reference to the accompanying drawings in the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. Based on the embodiments in the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present invention.
[0038] With the wide application of modern programming languages, especially the extensive use of advanced features in object-oriented programming languages, the complexity of code has been increasing day by day. Many codes generally have features such as inheritance, polymorphism, and dynamic types. Although these features improve the flexibility and reusability of the code, they also bring great challenges to the static analysis of the code, especially the code reachability analysis.
[0039] During the long-term research and analysis of code security by the applicant, it is found that the commonly used analysis methods in the prior art, such as control flow graph analysis technology, data flow analysis technology, and symbolic execution analysis technology, although play a role in dealing with these advanced features, still have certain limitations. That is, when performing reachability analysis on code containing advanced features, they often cannot provide high-precision results, especially when dealing with large and complex projects, the problem is particularly prominent. This lack of precision directly affects the reliability of code reachability analysis. Especially in the security analysis scenario, it is easy to miss potential dangerous call paths, resulting in incomplete code vulnerability detection results. For example, the control flow graph analysis technology is difficult to accurately handle polymorphism and indirect calls, the data flow analysis technology has insufficient precision when dealing with complex reference relationships, and the symbolic execution analysis technology is limited by the path explosion and state space expansion problems. The present invention is proposed based on this technical prejudice, aiming to overcome the above deficiencies and provide more reliable technical support for code vulnerability detection and security assessment.
[0040] In view of the above problems, the present invention proposes the following embodiments.
[0041] Figure 1 It is a schematic flowchart of the code reachability analysis method provided by the present invention. As Figure 1 shown, the method includes the following:
[0042] Step 110, obtain the source code, compile the source code to obtain an intermediate representation instruction set.
[0043] It should be noted that the compilation here does not directly generate an executable file or object code, but generates an intermediate representation (IR). IR is an abstract representation form, located between the source code and the machine code. It contains both the high-level logical structure of the source code and deletes language-specific syntax details. The compiler translates the source code into an intermediate representation instruction set. The instructions in the intermediate representation instruction set are a simplified and structured program representation form, which is convenient for further static analysis. Each instruction in the intermediate representation usually corresponds to an operation, such as variable assignment, function call, or conditional judgment.
[0044] Here, IR is an intermediate-level representation generated during the program compilation process, which is an abstract data form independent of specific programming languages and hardware platforms. The intermediate representation instruction set is a specific implementation of the intermediate representation.
[0045] Step 120, determine a function instruction set from the intermediate representation instruction set, and replace the abstract variable names of each function instruction in the function instruction set with actual class names to obtain a concretized function instruction set; any function instruction in the function instruction set represents the execution logic of the function in the source code.
[0046] Here, the abstract variable name of a function instruction refers to a variable identifier in the program without a specific type. It is necessary to concretize the abstract variable name into an actual class name to clarify the function logic and eliminate type uncertainty.
[0047] Here, the intermediate representation instruction set contains all the logic of the source code, including instructions such as variable assignment, conditional judgment, loop structure, and function call. The function instruction set is a subset of the intermediate representation instruction set, focusing on instructions that describe function calls and definitions, which are the key objects of code reachability analysis. The concretized function instruction set is a set after replacing the abstract variable names of each function instruction in the function instruction set with actual class names. Each concretized function instruction clearly marks the actual class name, accurately representing the execution logic and call target of the source code function.
[0048] Step 130, based on the calling information of each specific function instruction in the specific function instruction set, a specific function instruction information set is obtained, wherein any specific function instruction information in the specific function instruction information set represents the execution logic of the function in the source code and the calling information of the function.
[0049] It should be noted that each concrete function instruction information in the concrete function instruction information set contains the execution logic and calling information of each concrete function instruction, and the execution logic and calling information of the concrete function instruction correspond to the execution logic and calling information of the function mapped by the concrete function instruction in the source code, wherein the execution logic refers to the operation logic inside the function, including the executed statements and execution logic; the calling information refers to the relevant information of the function call, including the calling target, parameters, return value, calling path, etc.
[0050] Specifically, through the detailed calling information of each concrete function instruction information, the calling relationship between functions becomes clear, especially in the case of polymorphism and dynamic types, the actual calling target of the function can be clearly identified to avoid misjudgment or missed judgment.
[0051] The specific operation of how to obtain the specific function instruction information set based on the calling information of each specific function instruction can be referred to the following embodiment, which will not be elaborated here.
[0052] Step 140 : Determine the reachability of each function in the source code based on the matching results of each concrete function instruction information in the concrete function instruction information set and each preset dangerous function instruction information in the preset dangerous function instruction information set.
[0053] Here, the preset dangerous function instruction information set contains the information of known potentially dangerous function instructions. Each preset dangerous function instruction information includes possible security vulnerabilities or dangerous behaviors, such as memory leaks, infinite callbacks, and null pointer references. Memory leaks refer to the failure of a function to properly release the allocated memory during operation, resulting in excessive memory resources being occupied, which may eventually cause the program to crash or system performance to degrade. Infinite callbacks refer to the continuous calling of a function or the called function to trigger the same operation again during execution, forming an infinite loop, which may cause a stack overflow or program crash. Null pointer references refer to accessing a pointer that has not been initialized or has been released, which may cause a crash or undefined behavior. The preset dangerous function instruction information set provides information that needs to be paid attention to in security analysis. Through automated analysis and matching, it can timely discover possible security vulnerabilities in the source code.
[0054] Here, function reachability refers to whether the functions in the source code can be successfully executed. By determining that a function is reachable, its security can be analyzed, especially to judge whether the function contains potential dangerous operations.
[0055] For the specific operations of determining the reachability of each function in the source code, reference can be made to the following embodiments, and details will not be elaborated here.
[0056] The code reachability analysis method provided by the embodiments of the present invention converts complex code structures into intermediate-layer data structures that are convenient for analysis by introducing intermediate representation technology, and provides an effective solution to the problem of insufficient accuracy in existing code reachability analysis technologies when dealing with advanced features of modern programming languages. Specifically, the present invention concretizes the function instruction set in the intermediate representation, that is, replaces the abstract variable names of each function instruction with actual class names, eliminates the uncertainty caused by dynamic types and polymorphism, clarifies the actual call targets of functions, not only greatly improves the accuracy of code analysis, but also simplifies the analysis logic and improves the execution efficiency. Further, by constructing a concretized function instruction information set, the execution logic and call information of each function in the source code are completely mapped to the concretized structure of the intermediate representation, realizing the function of quickly tracing back from the analysis results to the source code, and then being able to efficiently and accurately determine the reachability of each function in the source code, ensuring that no potential call paths are missed in complex inheritance and polymorphic call scenarios; in addition, each concretized function instruction information is matched with each preset dangerous function instruction information in the preset dangerous function instruction information set to quickly identify potential dangerous call paths, thereby providing reliable support for code vulnerability detection and security assessment. Compared with the prior art, the present invention not only improves the analysis accuracy and efficiency, but also enhances the traceability of the source code, providing a practical technical basis for code reachability analysis.
[0057] Based on any of the above embodiments, in this method, before obtaining the concretized function instruction information set based on the call information of each concretized function instruction in the concretized function instruction set, the method includes:
[0058] Based on the type information and parameter passing paths of each concretized function instruction in the concretized function instruction set, determine the call information of each concretized function instruction in the concretized function instruction set.
[0059] It should be noted that the type information of a concretized function instruction refers to the specific characteristics and execution methods of the function represented by the concretized function instruction in the source code. Through this information, the call method of the function can be inferred; further, the call order of the function, the call relationship between the function and other functions, the parameters and return values passed when the function is called, etc. can be inferred, and then the call information of the concretized function instruction can be determined.
[0060] Here, the parameter passing path refers to the path of parameter flow when the function represented by the concretized function instruction is called, which can be value passing or reference passing, depending on the function definition and call method. The parameter passing path is the key to determining the function call context.
[0061] The code reachability analysis method provided by the embodiments of the present invention determines the call information of the concretized function instruction based on the type information of the concretized function instruction and the parameter passing path, can deeply understand the specific characteristics and execution methods of the function represented by each concretized function instruction in the source code, and helps to clarify the actual call path of the function. In addition, combined with the type information, the parameters and return values passed when the function is called can also be inferred, providing a more detailed and accurate basis for the code reachability analysis. Through these steps, the accuracy and efficiency of code analysis can be improved. Especially in complex systems and large projects, it can efficiently reduce the uncertainty in the analysis process and quickly locate potential security risks and code vulnerabilities. This method not only enhances the reliability of code reachability analysis, but also provides strong support for code optimization and vulnerability detection.
[0062] Based on any of the above embodiments, in this method, the type information of the concretized function instruction includes local function type, inherited function type or overloaded function type; the call information of the concretized function instruction includes independent call information, inheritance chain call information or polymorphic call information;
[0063] The call information of any of the concretized function instructions is determined based on the following method:
[0064] If the type information of the concretized function instruction is the local function type, the call information of the concretized function instruction is determined as independent call information;
[0065] If the type information of the concretized function instruction is the inherited function type, the call information of the concretized function instruction is determined as inheritance chain call information;
[0066] If the type information of the concretized function instruction is the overloaded function type, the call information of the concretized function instruction is determined as polymorphic call information.
[0067] Here, the local function type refers to an independent function that is independently defined in the current scope without involving inheritance and has no direct association with other classes or parent classes; if the type information of the concretized function instruction shows that it is a local function type, the call information of the concretized function instruction can be directly determined as independent call information, that is, the call of the function represented by the concretized function instruction in the source code has no complex dependencies with other functions.
[0068] Here, the inherited function type refers to a function that has an inheritance relationship, is not defined in the subclass, and is directly inherited from the parent class or superclass; if the type information of the concretized function instruction indicates that it is of the inherited function type, then the call information of the concretized function instruction can be determined as inheritance chain call information, and the inheritance chain call information of the concretized function instruction clearly reflects the source and call relationship of the function represented by the concretized function instruction in the inheritance chain in the source code.
[0069] Here, the overloaded function type refers to a function that has an inheritance relationship, but the function inherited from the parent class or superclass is redefined in the subclass; if the type information of the concretized function instruction indicates that it is of the overloaded function type, then the call information of the concretized function instruction can be determined as polymorphic call information, and the polymorphic call information of the concretized function instruction clearly reflects the parameter matching rules and dynamic dispatch results of the overloaded function represented by the concretized function instruction in the source code.
[0070] The code reachability analysis method provided by the embodiments of the present invention realizes the accurate parsing and classification of function call relationships by distinguishing the type information of the concretized function instructions and determining the call information of the concretized function instructions based on this. For the call characteristics of different function types, the classification of call information is refined to ensure that the call path is clear and accurate, effectively handle complex inheritance levels, and completely display the inheritance relationship between classes and their call logic, making the code reachability analysis more targeted and accurate, thereby greatly improving the efficiency and reliability of modern programming language code analysis.
[0071] Based on any of the above embodiments, in this method, after determining the call information of each concretized function instruction in the set of concretized function instructions, the method further includes:
[0072] Classifying and marking each concretized function instruction in the set of concretized function instructions based on the call information of each concretized function instruction in the set of concretized function instructions.
[0073] It should be noted that the classification and marking refer to assigning a clear label to each concretized function instruction to describe the call information of the instruction. This kind of marking not only facilitates the distinction of different call characteristics, but also can significantly improve the efficiency of code analysis and processing.
[0074] Exemplarily, by classifying the function tags represented by each concretization function instruction in the concretization function instruction set into three attribute categories: local functions, overloaded functions, and inherited functions in the source code, the function definition and call relationships between subclasses and their parent classes and grandparent classes are clearly shown; the independent marking of local functions ensures that the function characteristics defined by the subclass itself are accurately captured; the explicit marking of overloaded functions makes the overriding behavior of the subclass on the parent class function traceable, facilitating the further identification of polymorphic calls; the annotation of inherited functions completely presents the functions inherited from the parent class or superclass, making the call information of the entire inheritance chain transparent.
[0075] The code reachability analysis method provided by the embodiments of the present invention, through classification marking, can not only clarify the call relationships and inheritance chains between the functions represented by each concretization function instruction in the concretization function instruction set in the source code, but also quickly identify polymorphic calls and potential overriding behaviors, laying a solid foundation for subsequent context analysis, vulnerability detection, and execution path analysis. In addition, this classification marking also improves the tracking ability of function call behaviors, enhances the comprehensiveness and efficiency of the analysis, and further improves the practicality and accuracy of code reachability analysis in complex software.
[0076] Based on any of the above embodiments, in this method, determining the reachability of each function in the source code based on the matching results between each concretization function instruction information in the concretization function instruction information set and each preset dangerous function instruction information in the preset dangerous function instruction information set includes:
[0077] If the concretization function instruction information in the concretization function instruction information set matches the preset dangerous function instruction information in the preset dangerous function instruction information set successfully, then the concretization function instruction information to be analyzed is determined;
[0078] Analyze the concretization function instruction information to be analyzed to obtain a reachability analysis result;
[0079] Among them, the reachability analysis result is used to determine the reachability of the function represented by the concretization function instruction information to be analyzed in the source code.
[0080] Here, the concretization function instruction information to be analyzed refers to the concretization function instruction information that matches the preset dangerous function instruction information in the preset dangerous function instruction information set, which means that this concretization function instruction information may be associated with the preset dangerous function instruction information and needs to further verify its call logic and security. The successful match is only a preliminary mark, and subsequent in-depth analysis of the call path, execution logic, and potential impact on the overall behavior of the program of the concretization function instruction information to be analyzed is required to confirm the actual risk level.
[0081] Exemplarily, the concretized function instruction information to be analyzed is analyzed to determine the reachability of the function in the program. Specifically, this analysis process involves in-depth analysis of the function call path and control flow.
[0082] Exemplarily, when analyzing the concretized function instruction information to be analyzed, if the call information of the concretized function instruction information to be analyzed is inheritance chain call information, it indicates that the call information of the function represented by the concretized function instruction information to be analyzed in the source code is also inheritance chain call information; specifically, if the function in the subclass inherits the function of the parent class and there is a known vulnerability in the version of the function in the parent class, the function will be identified and marked as a potentially dangerous function, and then deeply analyzed to determine the reachability analysis result.
[0083] Exemplarily, when analyzing the concretized function instruction information to be analyzed, the parameter passing path of the function represented by the concretized function instruction information to be analyzed in the source code will also be analyzed. By tracing the parameter passing process, the actual call type of the function can be dynamically determined. If there is uncertainty in the passed parameter type during the passing process, or the resolution of the dynamic type becomes complex, the analysis scope will be expanded to cover function calls in the parent class or superclass. Especially in the case of polymorphism, the passed parameter may cause the actual call behavior of the function to change. In this case, the relevant function call will be marked as "potentially dangerous" to avoid potential vulnerabilities caused by polymorphism or dynamic type changes. For example, if the function in the parent class or superclass has been marked as a dangerous function, but the actual call type cannot be determined due to polymorphic calls, the risk that the function call may bring will be inferred based on the parameter passing situation and marked as a "dangerous call". In this way, potential security risks caused by polymorphism or type uncertainty can be effectively identified.
[0084] The code reachability analysis method provided by the embodiments of the present invention can efficiently identify functions that may cause security problems by matching the concretized function instruction information with the preset dangerous function instruction information. By performing reachability analysis on the concretized function instruction information to be analyzed, it can be further determined whether the function represented by the concretized function instruction information to be analyzed in the source code can be actually called, so as to determine whether there are vulnerabilities.
[0085] Based on any of the above embodiments, in this method, the reachability analysis result includes the location information of the function represented by the concretized function instruction information to be analyzed in the source code, the execution logic risk prompt, and the call information risk prompt.
[0086] Here, since there is a synchronous mapping relationship between each intermediate expression instruction in the intermediate expression instruction set and the code block in the source code, the position information of the function represented by the concrete function instruction information to be analyzed in the source code can be determined; this helps developers locate the code segments with potential problems and repair possible vulnerabilities in a timely manner.
[0087] Specifically, the execution logic risk prompt refers to generating a prompt message indicating that the function may trigger an exception or cause a vulnerability in certain situations based on the execution path and runtime behavior of the function represented by the concrete function instruction information to be analyzed in the source code. For example, the function may cause memory leakage, buffer overflow, or undefined behavior when the input parameters are improper, and at this time, the logic risk prompt of the function is generated by analyzing its execution logic.
[0088] Exemplarily, the call information risk prompt refers to generating a risk prompt message based on the call chain of the function represented by the concrete function instruction information to be analyzed in the source code. For example, if the function has polymorphism and the type of the passed parameter is uncertain, a call information risk prompt for the function will be generated.
[0089] The code reachability analysis method provided by the embodiments of the present invention can help developers efficiently discover and repair vulnerabilities through the position information, execution logic risk prompt, and call information risk prompt of the concrete function instruction represented by the reachability analysis result in the function represented by the source code, thereby improving the security and robustness of the source code.
[0090] Next, the code reachability analysis device provided by the present invention will be described. The code reachability analysis device described below can be correspondingly referred to the code reachability analysis method described above.
[0091] FIG. 2 is a schematic structural diagram of the code reachability analysis device provided by the present invention. As shown in FIG. 2, the code reachability analysis device includes:
[0092] A compilation module 210, which is used to obtain the source code, compile the source code, and obtain an intermediate expression instruction set;
[0093] A concrete function instruction set determination module 220, which is used to determine a function instruction set from the intermediate expression instruction set, and replace the abstract variable names of each function instruction in the function instruction set with actual class names to obtain a concrete function instruction set; any function instruction in the function instruction set represents the execution logic of the function in the source code.
[0094] A concretization function instruction information set determination module 230, which is configured to obtain a concretization function instruction information set based on the call information of each concretization function instruction in the concretization function instruction set, and any concretization function instruction information in the concretization function instruction information set represents the execution logic of the function in the source code and the call information of the function;
[0095] An accessibility analysis module 240, which is configured to determine the accessibility of each function in the source code based on the matching results between each concretization function instruction information in the concretization function instruction information set and each preset dangerous function instruction information in the preset dangerous function instruction set.
[0096] Figure 3 An example of the physical structure diagram of an electronic device is shown as Figure 3 shown. The electronic device may include: a processor 310, a communication interface 320, a memory 330, and a communication bus 340. Among them, the processor 310, the communication interface 320, and the memory 330 complete communication with each other through the communication bus 340. The processor 310 may call the logical instructions in the memory 330 to execute the code accessibility analysis method, and the method includes: obtaining the source code, compiling the source code to obtain an intermediate representation instruction set; determining a function instruction set from the intermediate representation instruction set, and replacing the abstract variable names of each function instruction in the function instruction set with actual class names to obtain a concretization function instruction set; any function instruction in the function instruction set represents the execution logic of the function in the source code; obtaining a concretization function instruction information set based on the call information of each concretization function instruction in the concretization function instruction set, and any concretization function instruction information in the concretization function instruction information set represents the execution logic of the function in the source code and the call information of the function; determining the accessibility of each function in the source code based on the matching results between each concretization function instruction information in the concretization function instruction information set and each preset dangerous function instruction information in the preset dangerous function instruction set.
[0097] In addition, when the logical instructions in the above-mentioned memory 330 can be implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks, or optical discs that can store program codes.
[0098] On the other hand, the present invention also provides a computer program product. The computer program product includes a computer program that can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can execute the code reachability analysis method provided by the above-mentioned various methods. The method includes: obtaining source code, compiling the source code to obtain an intermediate representation instruction set; determining a function instruction set from the intermediate representation instruction set, and replacing the abstract variable names of each function instruction in the function instruction set with actual class names to obtain a concretized function instruction set; any function instruction in the function instruction set represents the execution logic of a function in the source code; based on the call information of each concretized function instruction in the concretized function instruction set, obtaining a concretized function instruction information set, and any concretized function instruction information in the concretized function instruction information set represents the execution logic of a function in the source code and the call information of the function; based on the matching results of each concretized function instruction information in the concretized function instruction information set and each preset dangerous function instruction information in the preset dangerous function instruction information set, determining the reachability of each function in the source code.
[0099] In another aspect, the present invention further provides a non-transitory computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it implements a code reachability analysis method provided by the above-mentioned various methods. The method includes: obtaining source code, compiling the source code to obtain an intermediate representation instruction set; determining a function instruction set from the intermediate representation instruction set, and replacing the abstract variable names of each function instruction in the function instruction set with actual class names to obtain a concretized function instruction set; any function instruction in the function instruction set represents the execution logic of a function in the source code; based on the call information of each concretized function instruction in the concretized function instruction set, a concretized function instruction information set is obtained, and any concretized function instruction information in the concretized function instruction set represents the execution logic of a function in the source code and the call information of the function; based on the matching results of each concretized function instruction information in the concretized function instruction information set and each preset dangerous function instruction information in the preset dangerous function instruction information set, the reachability of each function in the source code is determined.
[0100] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. Those of ordinary skill in the art can understand and implement it without creative efforts.
[0101] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a necessary general hardware platform, and of course, it can also be implemented by hardware. Based on such an understanding, the essence of the above technical solution, or the part that contributes to the prior art, can be embodied in the form of a software product. The computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.
[0102] Finally, it should be noted that: the above embodiments are only used to illustrate the technical solutions of the present invention, and are not intended to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that: they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A code reachability analysis method, characterized in that: include: Obtaining source code, compiling the source code to obtain an intermediate expression instruction set; Determine a function instruction set from the intermediate expression instruction set, replace the abstract variable name of each function instruction in the function instruction set with the actual class name to obtain a specific function instruction set; any function instruction in the function instruction set represents the execution logic of the function in the source code; Determining the calling information of each specific function instruction in the specific function instruction set based on the type information and parameter transfer path of each specific function instruction in the specific function instruction set; Based on the calling information of each specific function instruction in the specific function instruction set, a specific function instruction information set is obtained, wherein any specific function instruction information in the specific function instruction information set represents the execution logic of the function in the source code and the calling information of the function; Determining the reachability of each function in the source code based on the matching results of each specific function instruction information in the specific function instruction information set and each preset dangerous function instruction information in the preset dangerous function instruction information set; The calling information of any of the specific function instructions is determined based on the following method: If the type information of the specific function instruction is a local function type, determining the call information of the specific function instruction as independent call information; If the type information of the specific function instruction is an inherited function type, determining the calling information of the specific function instruction as inheritance chain calling information; If the type information of the specific function instruction is an overloaded function type, the calling information of the specific function instruction is determined to be polymorphic calling information.
2. The code reachability analysis method according to claim 1, characterized in that: After determining the calling information of each concrete function instruction in the concrete function instruction set, the method further includes: Classify and mark each concrete function instruction in the concrete function instruction set based on the calling information of each concrete function instruction in the concrete function instruction set.
3. The code reachability analysis method according to claim 1, characterized in that: The determining the reachability of each function in the source code based on the matching results of each specific function instruction information in the specific function instruction information set and each preset dangerous function instruction information in the preset dangerous function instruction information set includes: If the specific function instruction information in the specific function instruction information set matches the preset dangerous function instruction information in the preset dangerous function instruction information set, then determining the specific function instruction information to be analyzed; Analyze the specific function instruction information to be analyzed to obtain a reachability analysis result; The reachability analysis result is used to determine the reachability of the function represented by the specific function instruction information to be analyzed in the source code.
4. The code reachability analysis method according to claim 3, characterized in that: The reachability analysis result includes the location information of the function represented by the concrete function instruction information to be analyzed in the source code, the execution logic risk prompt and the call information risk prompt.
5. A code reachability analysis device, characterized in that: include: A compiling module, which is used to obtain source code, compile the source code, and obtain an intermediate expression instruction set; A concrete function instruction set determination module is used to determine a function instruction set from the intermediate expression instruction set, and replace the abstract variable name of each function instruction in the function instruction set with an actual class name to obtain a concrete function instruction set; any function instruction in the function instruction set represents the execution logic of the function in the source code; A specific function instruction information set determination module, which is used to determine the call information of each specific function instruction in the specific function instruction set based on the type information and parameter transfer path of each specific function instruction in the specific function instruction set; based on the call information of each specific function instruction in the specific function instruction set, obtain the specific function instruction information set, any specific function instruction information in the specific function instruction information set represents the execution logic of the function in the source code and the call information of the function; A reachability analysis module, which is used to determine the reachability of each function in the source code based on the matching results of each specific function instruction information in the specific function instruction information set and each preset dangerous function instruction information in the preset dangerous function instruction information set; The calling information of any of the specific function instructions is determined based on the following method: If the type information of the specific function instruction is a local function type, determining the call information of the specific function instruction as independent call information; If the type information of the specific function instruction is an inherited function type, determining the calling information of the specific function instruction as inheritance chain calling information; If the type information of the specific function instruction is an overloaded function type, the calling information of the specific function instruction is determined to be polymorphic calling information.
6. An electronic device comprising a memory, a processor, and a computer program stored in the memory and running on the processor, characterized in that: When the processor executes the computer program, the code reachability analysis method according to any one of claims 1 to 4 is implemented.
7. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the code reachability analysis method according to any one of claims 1 to 4 is implemented.
8. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, the code reachability analysis method according to any one of claims 1 to 4 is implemented.
Citation Information
Patent Citations
Component and vulnerability reachability analysis method and device, equipment and storage medium
CN117272310A
Warehouse-level code defect automatic repairing method based on large language model
CN117851101A