Firmware Logic Vulnerability Detection Method, System, Electronic Device and Computer Readable Storage Medium Based on the Chain of Thought of Large Language Model

By building a business logic vulnerability knowledge base and large language model thinking chain technology, the problem of detection of variable business logic vulnerabilities in the IoT terminal firmware is solved, and efficient and accurate vulnerability detection of the IoT terminal firmware is achieved.

CN119691757BActive Publication Date: 2025-05-27SHANGHAI JIAOTONG UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510206888.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-02-25
Publication Date
2025-05-27
Estimated Expiration
2045-02-25

AI Technical Summary

Technical Problem

The types of business logic vulnerabilities in the firmware of IoT terminals are varied and there is a lack of general detection methods. It is difficult for the existing technology to effectively detect and defend against various attack methods.

Method used

Using a method based on the thinking chain of large language model, a business logic vulnerability knowledge base is built, firmware business programs are analyzed through large language models, multi-level prompt words and stain analysis are generated, and logical vulnerability detection is carried out in combination with the business object knowledge graph.

Benefits of technology

It realizes accurate detection of various business logic vulnerabilities in the firmware of IoT terminals, improves the accuracy and efficiency of vulnerability detection, is dynamically adaptable, and can identify potential security threats.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119691757B_ABST
    Figure CN119691757B_ABST
Patent Text Reader

Abstract

The present invention provides a firmware logic vulnerability detection method, system, electronic device and computer-readable storage medium based on the thought chain of large language models. The method includes: constructing a business logic vulnerability knowledge base using a first large language model; obtaining basic data of the business program of the firmware to be detected to construct a business object knowledge graph; based on the business logic vulnerability knowledge base, using a retrieval-augmented generation algorithm to obtain the sensitive control flow and business logic vulnerability paradigms corresponding to the business program of the firmware to be detected; based on the business logic vulnerability paradigms and sensitive control flow corresponding to the business program of the firmware to be detected, using the large language model thought chain technology to iteratively generate multi-level prompt words; and based on the multi-level prompt words and the business object knowledge graph, using a second large language model to obtain the logic vulnerability detection result. The present invention can realize the detection of various business logic vulnerabilities in the firmware of Internet of Things terminals.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular to a firmware logic vulnerability detection method, system, electronic device and computer-readable storage medium based on the chain of thought of large language models. Background Art

[0002] Business logic vulnerabilities in Internet of Things (IoT) terminal firmware usually involve improper design, implementation, and configuration, enabling attackers to bypass normal processes or obtain unauthorized access rights through specific operations. The types of business logic vulnerabilities in IoT terminal firmware include but are not limited to the following.

[0003] 1. Authentication bypass: Vulnerability description: Attackers achieve unauthorized access to devices or services by bypassing authentication mechanisms or abusing weak authentication. For example, bypassing the verification of passwords or tokens through some insufficiently verified interfaces. Common scenarios: The default passwords or hardcoded passwords of IoT devices are not changed, and attackers obtain administrator privileges through brute-force cracking or dictionary attacks.

[0004] 2. Privilege escalation: Vulnerability description: In the case of improper design of the privilege control mechanism, low-privilege users obtain higher privileges by operating or tampering with requests. Common scenarios: Ordinary users can access or operate settings under administrator privileges, or increase privileges by tampering with firmware configuration files or request parameters.

[0005] 3. Unauthorized access: Vulnerability description: Some interfaces or services of the device do not undergo sufficient authorization checks, allowing attackers to directly access sensitive data or control the device. Common scenarios: For example, remote access interfaces, device configurations, or log files store sensitive information (such as API keys, passwords, etc.), and attackers can directly access through interfaces exposed on the network.

[0006] 4. Command injection: Vulnerability description: Attackers can change the normal behavior of the device or even make the device execute arbitrary operations by injecting malicious commands or code. Common scenarios: Incorrect data validation may exist in the firmware of IoT devices, allowing malicious commands to be injected into the device's execution process.

[0007] 5. Improper data validation and processing: Vulnerability description: The device does not correctly verify the legality of input data, resulting in malicious tampering or incorrect processing of data, thereby affecting the normal operation of the device. Common scenarios: For example, command parameters input to the device are not correctly verified, and attackers can cause incorrect behavior or crashes of the device through malicious input.

[0008] 6. Business Process Bypass: Vulnerability Description: Attackers bypass restrictions or obtain unauthorized permissions or functions by bypassing the normal business processes of devices. Common Scenarios: Attackers modify the process control parameters in the device firmware to bypass certain business logics, such as avoiding multi-factor authentication or payment authentication by modifying the request order.

[0009] 7. Weak Security Configuration: Vulnerability Description: IoT devices may be exposed to attackers due to insufficient security considerations during design, using default configurations or easily guessable configurations. Common Scenarios: Using default settings, weak passwords, or unencrypted communication, attackers can easily obtain access to the device or its data.

[0010] 8. Firmware Update Abuse: Vulnerability Description: Attackers may implant malicious code or bypass security controls by abusing the firmware update mechanism of devices. Common Scenarios: The firmware update mechanism of IoT devices lacks verification or signature checks, allowing attackers to upload malicious firmware and replace the original firmware of the device.

[0011] 9. Improper Resource Management: Vulnerability Description: IoT devices mismanage internal resources (such as memory, storage, bandwidth, etc.), resulting in attackers being able to exhaust resources or occupy a large amount of computing power through specific operations, affecting the normal functions of the device. Common Scenarios: For example, the device does not limit the size of log files or traffic control, and attackers can take advantage of this to cause device overload.

[0012] Due to the highly variable paradigms of business logic vulnerabilities, which are closely related to the functional characteristics, application scenarios, and business designs of upper-layer applications, there are no common and fixed features and rules. Therefore, there is an urgent need for a detection method for business logic vulnerabilities in IoT terminal firmware.

[0013] It should be noted that the information disclosed in the background art section of this invention is only intended to deepen the understanding of the general background art of this invention, and should not be regarded as an admission or any form of implication that this information constitutes the prior art known to those skilled in the art. Summary of the Invention

[0014] The purpose of this invention is to provide a firmware logic vulnerability detection method, system, electronic device, and computer-readable storage medium based on the thought chain of large language models, which can achieve the detection of various business logic vulnerabilities in IoT terminal firmware.

[0015] To achieve the above object, the present invention provides a firmware logic vulnerability detection method based on the thought chain of a large language model, including: processing the collected firmware business program vulnerability data source by using a first large language model to construct a business logic vulnerability knowledge base, where the business logic vulnerability knowledge base includes the vulnerability information summary, vulnerability context information, vulnerability constraint conditions, logic vulnerability paradigms, and business functions corresponding to different types of business logic vulnerabilities; obtaining the basic data of the firmware business program to be detected, and constructing a business object knowledge graph according to the basic data of the firmware business program to be detected, where the basic data includes function descriptions, high-level function summaries, loop summaries, data dependency relationships, and program call graphs; based on the business logic vulnerability knowledge base, using a retrieval-augmented generation algorithm to obtain the sensitive control flow and business logic vulnerability paradigms corresponding to the firmware business program to be detected; based on the business logic vulnerability paradigms and sensitive control flow corresponding to the firmware business program to be detected, using the large language model thought chain technology to decompose the reasoning process of the logic vulnerability and the related taint analysis process to iteratively generate multi-level prompt words corresponding to the logic vulnerability analysis steps; based on the multi-level prompt words and the business object knowledge graph, using a second large language model to perform taint analysis to obtain the logic vulnerability detection result corresponding to the firmware business program to be detected.

[0016] Optionally, the obtaining the basic data of the firmware business program to be detected includes: analyzing the source code or decompiled code of the firmware business program to be detected by using a static analysis tool to obtain the static analysis result corresponding to the firmware business program to be detected, where the static analysis result includes data flow and control flow; analyzing the source code or decompiled code of the firmware business program to be detected by using a third large language model to obtain the large model analysis result corresponding to the firmware business program to be detected, where the large model analysis result includes vulnerability-related function summaries, business functions, business scenarios, and description information; combining the static analysis result and the large model analysis result corresponding to the firmware business program to be detected to obtain the basic data of the firmware business program to be detected.

[0017] Optionally, based on the business logic vulnerability knowledge base, the sensitive control flow and business logic vulnerability paradigm corresponding to the firmware business program to be detected are obtained by using a retrieval-augmented generation algorithm, including: based on the source code or decompiled code of the firmware business program to be detected, retrieving in a pre-created vector database through the retrieval-augmented generation algorithm to obtain a target vulnerability report associated with the target logic vulnerability in the firmware business program to be detected and the corresponding target vulnerability code; performing code semantic description on the target vulnerability code to construct the business logic vulnerability paradigm corresponding to the target logic vulnerability; performing similarity matching on the business logic vulnerability paradigm in the business logic vulnerability knowledge base to obtain the vulnerability function summary and sensitive control flow corresponding to the target logic vulnerability.

[0018] Optionally, the firmware logic vulnerability detection method based on the large language model's chain of thought provided by the present invention further includes: retrieving in the business logic vulnerability knowledge base based on the target vulnerability report to obtain a vulnerability information summary, business function, vulnerability constraint conditions, and vulnerability context information that match the target logic vulnerability.

[0019] Optionally, based on the business logic vulnerability paradigm and sensitive control flow corresponding to the firmware business program to be detected, using the large language model's chain of thought technology to decompose the reasoning process of the logic vulnerability and the related taint analysis process to iteratively generate multi-level prompt words corresponding to the logic vulnerability analysis steps, including: according to the business logic vulnerability paradigm and sensitive control flow corresponding to the firmware business program to be detected, as well as the vulnerability information summary, business function, vulnerability constraint conditions, and vulnerability context information that match the target logic vulnerability, using the large language model's chain of thought technology to decompose the reasoning process of the logic vulnerability and the related taint analysis process; iteratively generating multi-level prompt words corresponding to function call chain taint tracking analysis, security vulnerability judgment, and constraint solving.

[0020] Optionally, the firmware logic vulnerability detection method based on the large language model's chain of thought provided by the present invention further includes: analyzing the target vulnerability report using the first large language model to obtain the function description of the target vulnerability code associated with the target logic vulnerability and the root cause of the target logic vulnerability.

[0021] Optionally, based on the multi-level prompt words and the business object knowledge graph, a second large language model is used for taint analysis to obtain the logical vulnerability detection result corresponding to the firmware service program to be detected, including: inputting the function description of the target vulnerability code and the root cause of the target logical vulnerability into the second large language model; sequentially inputting the multi-level prompt words, the business object knowledge graph, the sensitive control flow, and the data flow corresponding to the firmware service program to be detected into the second large language model; using a taint analysis algorithm to gradually infer whether each node function in the sensitive control flow violates the security policy to obtain the logical vulnerability detection result corresponding to the firmware service program to be detected.

[0022] To achieve the above object, the present invention further provides a firmware logical vulnerability detection system based on the large language model's chain of thought, including: a knowledge base construction module configured to use a first large language model to process the collected firmware service program vulnerability data sources to construct a business logic vulnerability knowledge base, where the business logic vulnerability knowledge base includes the vulnerability information summary, vulnerability context information, vulnerability constraint conditions, logical vulnerability paradigms, and business functions corresponding to different types of business logic vulnerabilities; a knowledge graph construction module configured to construct a business object knowledge graph according to the basic data of the firmware service program to be detected, where the basic data includes function descriptions, high-level function summaries, loop summaries, data dependency relationships, and program call graphs; a retrieval enhancement module configured to, based on the business logic vulnerability knowledge base, use a retrieval enhancement generation algorithm to obtain the sensitive control flow and business logic vulnerability paradigms corresponding to the firmware service program to be detected; a multi-level prompt word generation module configured to, based on the business logic vulnerability paradigms and sensitive control flow corresponding to the firmware service program to be detected, use the large language model's chain of thought technology to decompose the reasoning process of logical vulnerabilities and related taint analysis processes to iteratively generate multi-level prompt words corresponding to the logical vulnerability analysis steps; and a business logic vulnerability analysis module configured to, based on the multi-level prompt words and the business object knowledge graph, use a second large language model for taint analysis to obtain the logical vulnerability detection result corresponding to the firmware service program to be detected.

[0023] To achieve the above object, the present invention further provides an electronic device, including a processor and a memory, where a computer program is stored on the memory, and when the computer program is executed by the processor, the firmware logical vulnerability detection method based on the large language model's chain of thought described in any one of the above is implemented.

[0024] To achieve the above object, the present invention further provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the firmware logical vulnerability detection method based on the large language model's chain of thought described in any one of the above is implemented.

[0025] Compared with the prior art, the firmware logic vulnerability detection method, system, electronic device, and computer-readable storage medium provided by the present invention based on the chain of thought of large language models have the following beneficial effects: The firmware logic vulnerability detection method provided by the present invention processes the collected firmware business program vulnerability data sources by using a first large language model, which can make full use of the large language model's ability to understand the semantics of vulnerability codes, and construct a business logic vulnerability knowledge base covering various typical business logic vulnerability paradigms of logical vulnerability paradigms, so as to ensure that the present invention can detect various business logic vulnerabilities in Internet of Things terminal firmware; By constructing a business object knowledge graph based on basic data such as the function description, high-level function summary, loop summary, data dependency relationship, and program call graph of the firmware business program to be detected, the accuracy of the subsequent logical vulnerability detection results of the firmware business program to be detected can be further ensured; Based on the business logic vulnerability knowledge base, by using the retrieval augmented generation algorithm to obtain the sensitive control flow and business logic vulnerability paradigm corresponding to the firmware business program to be detected, a high-dimensional mapping between the control flow semantic representation and potential vulnerability types can be established, so as to dynamically and adaptively provide guiding examples for the large language model chain of thought technology; By using the large language model chain of thought technology, decomposing the reasoning process of logical vulnerabilities and related taint analysis processes, and generating multi-level prompts (Prompts) corresponding to the call chain data flow tracking analysis and security vulnerability existence judgment vulnerability analysis atomic operations, the context learning and fine-tuning of the large language model can be iteratively promoted; Based on the multi-level prompt words and the business object knowledge graph, by using a second large language model for taint analysis, the large language model can be driven to gradually infer whether each node function of the sensitive control flow of the firmware business program to be detected violates the security policy according to the taint analysis steps, so as to effectively ensure the accuracy of the logical vulnerability detection results of the firmware business program to be detected. In summary, by using the firmware logic vulnerability detection method provided by the present invention based on the chain of thought of large language models, the ability of large language models to understand, analyze, and discover logical vulnerabilities in Internet of Things terminal firmware business programs can be effectively promoted.

[0026] Since the firmware logic vulnerability detection system, electronic device, and computer-readable storage medium provided by the present invention based on the chain of thought of large language models belong to the same inventive concept as the firmware logic vulnerability detection method provided by the present invention, the firmware logic vulnerability detection system, electronic device, and computer-readable storage medium provided by the present invention have at least all the beneficial effects of the firmware logic vulnerability detection method provided by the present invention. For specific details, reference can be made to the relevant descriptions in the above text. Therefore, the beneficial effects of the firmware logic vulnerability detection system, electronic device, and computer-readable storage medium provided by the present invention will not be elaborated one by one here. Description of the Drawings

[0027] Figure 1 It is a flowchart of a firmware logic vulnerability detection method based on the chain of thought of a large language model provided by an embodiment of the present invention.

[0028] Figure 2 It is a schematic diagram of a firmware logic vulnerability detection method based on the chain of thought of a large language model provided by an embodiment of the present invention.

[0029] Figure 3 It is a flowchart of obtaining sensitive control flow and business logic vulnerability paradigms provided by an embodiment of the present invention.

[0030] Figure 4 It is a flowchart of generating multi-level prompt words provided by an embodiment of the present invention.

[0031] Figure 5 It is a flowchart of obtaining a logic vulnerability detection result based on a second large language model provided by an embodiment of the present invention.

[0032] Figure 6 It is a block diagram of the structure of a firmware logic vulnerability detection system based on the chain of thought of a large language model provided by an embodiment of the present invention.

[0033] Figure 7 It is a block diagram of the structure of an electronic device provided by an embodiment of the present invention.

[0034] Among them, the description of the reference numerals is as follows: knowledge base construction module - 110; knowledge graph construction module - 120; retrieval enhancement module - 130; multi-level prompt word generation module - 140; business logic vulnerability analysis module - 150; processor - 210; communication interface - 220; memory - 230; communication bus - 240. Detailed Embodiments

[0035] The following further elaborates on the firmware logic vulnerability detection method, system, electronic device, and computer-readable storage medium based on the chain of thought of large language models proposed by the present invention in conjunction with the accompanying drawings and specific embodiments. According to the following description, the advantages and features of the present invention will be clearer. It should be noted that the accompanying drawings are in a very simplified form and use non-precise scales, only for conveniently and clearly assisting in explaining the purpose of the present invention. In order to make the purpose, features, and advantages of the present invention more obvious and understandable, please refer to the accompanying drawings. It should be noted that the structures, scales, sizes, etc. shown in the drawings of this specification are only used to cooperate with the content disclosed in the specification for those familiar with this technology to understand and read, and are not used to limit the limiting conditions for the implementation of the present invention. Any modification of the structure, change in the proportional relationship, or adjustment of the size, under the condition of being the same or similar to the effects that the present invention can produce and the purposes that can be achieved, should still fall within the scope covered by the technical content disclosed by the present invention.

[0036] The core idea of the present invention is to provide a firmware logic vulnerability detection method, system, electronic device, and computer-readable storage medium based on the chain of thought of large language models, which can realize the detection of various business logic vulnerabilities in the firmware of Internet of Things terminals.

[0037] It should be noted that the firmware logic vulnerability detection method based on the chain of thought of large language models provided by the present invention can be applied to the firmware logic vulnerability detection system based on the chain of thought of large language models provided by the present invention. The firmware logic vulnerability detection system based on the chain of thought of large language models can be configured on an electronic device. Among them, the electronic device can be a personal computer, a mobile terminal, etc. The mobile terminal can be a hardware device such as a mobile phone or a tablet computer with various operating systems.

[0038] To achieve the above idea, the present invention provides a firmware logic vulnerability detection method based on the chain of thought of large language models. Please refer to Figure 1 , which is a flowchart of the firmware logic vulnerability detection method based on the chain of thought of large language models provided by an embodiment of the present invention. As Figure 1 shown, the firmware logic vulnerability detection method based on the chain of thought of large language models includes the following steps S100 to step S500.

[0039] Step S100: Process the collected firmware business program vulnerability data sources using a first large language model to construct a business logic vulnerability knowledge base. The business logic vulnerability knowledge base includes the vulnerability information summaries, vulnerability context information, vulnerability constraint conditions, logical vulnerability paradigms, and business functions corresponding to different types of business logic vulnerabilities.

[0040] Step S200: Obtain the basic data of the firmware business program to be detected, and construct a business object knowledge graph based on the basic data of the firmware business program to be detected. The basic data includes function descriptions, high-level function summaries, loop summaries, data dependencies, and program call graphs.

[0041] Step S300: Based on the business logic vulnerability knowledge base, use the retrieval-augmented generation algorithm to obtain the sensitive control flow and business logic vulnerability paradigms corresponding to the firmware business program to be detected.

[0042] Step S400: Based on the business logic vulnerability paradigms and sensitive control flow corresponding to the firmware business program to be detected, use the large language model thought chain technology to decompose the reasoning process of logical vulnerabilities and related taint analysis processes, so as to iteratively generate multi-level prompt words corresponding to the logical vulnerability analysis steps.

[0043] Step S500: Based on the multi-level prompt words and the business object knowledge graph, use the second large language model to perform taint analysis to obtain the logical vulnerability detection results corresponding to the firmware business program to be detected.

[0044] Therefore, the firmware logic vulnerability detection method based on the chain of thought of large language models provided by the present invention can process the collected firmware business program vulnerability data sources by using a first large language model, make full use of the large language model's ability to understand the semantics of vulnerability codes, and construct a business logic vulnerability knowledge base covering logical vulnerability paradigms of various typical business logic vulnerabilities, so as to ensure that the present invention can detect various business logic vulnerabilities in Internet of Things terminal firmware; by constructing a business object knowledge graph based on basic data such as the function description, high-level function summary, loop summary, data dependency relationship, and program call graph of the firmware business program to be detected, the accuracy of the subsequent logical vulnerability detection results of the firmware business program to be detected can be further ensured; by using the retrieval augmented generation algorithm based on the business logic vulnerability knowledge base to obtain the sensitive control flow and business logic vulnerability paradigms corresponding to the firmware business program to be detected, a high-dimensional mapping between the control flow semantic representation and potential vulnerability types can be established, so as to dynamically and adaptively provide guiding examples for the large language model chain of thought technology; by using the large language model chain of thought technology to decompose the reasoning process of logical vulnerabilities and related taint analysis processes, and generate multi-level prompts (Prompts) corresponding to the call chain data flow tracking analysis and security vulnerability existence judgment vulnerability analysis atomic operations, the context learning and fine-tuning of the large language model can be iteratively advanced; by using a second large language model for taint analysis based on the multi-level prompts and the business object knowledge graph, the large language model can be driven to gradually reason whether each node function of the sensitive control flow of the firmware business program to be detected violates the security policy according to the taint analysis steps, so as to effectively ensure the accuracy of the logical vulnerability detection results of the firmware business program to be detected. In summary, by using the firmware logic vulnerability detection method based on the chain of thought of large language models provided by the present invention, the ability of the large language model to understand, analyze, and discover the logical vulnerabilities of Internet of Things terminal firmware business programs can be effectively promoted.

[0045] Please continue to refer to Figure 2 , which is the schematic diagram of the firmware logic vulnerability detection method based on the chain of thought of large language models provided by an embodiment of the present invention. As Figure 2 shown, logical vulnerability cases (i.e., firmware business program vulnerability data sources, that is, multi-source vulnerability information) of Internet of Things terminal firmware business programs can be collected from public vulnerability databases (such as CVE, NVD, CNVD, etc.), open source projects (such as the security vulnerability dataset ReposVul, etc.), patches, and PoCs (vulnerability verification programs), covering common security vulnerabilities such as unauthorized access and information leakage. It should be noted that Figure 2 in

[0046] Furthermore, based on the above - collected information (i.e., the firmware business program vulnerability data source), the first large - language model (such as ChatGPT, Claude, DeepSeek) can be used to normalize the vulnerability descriptions, vulnerability source code contexts, vulnerability patches, and security vulnerability detection rule libraries in the public vulnerability database, and summarize and generalize the different source information of the vulnerabilities.

[0047] Based on the patches and PoCs (vulnerability verification programs) related to the vulnerabilities, the first large - language model is used to understand the vulnerability principle at the code semantic level to generate a comprehensive vulnerability information summary, understand the vulnerability logic at the business level to generate accurate business constraint conditions, and construct a logical vulnerability paradigm. This paradigm includes the code functions related to the logical vulnerability, the attributes or operations of the vulnerable code, and other vulnerability code semantic information. The vulnerability information summaries, vulnerability context information, vulnerability constraint conditions, logical vulnerability paradigms, and business functions corresponding to different types of business logic vulnerabilities are uniformly stored in the business logic vulnerability knowledge base to construct the business logic vulnerability knowledge base.

[0048] Furthermore, the vulnerability information summary is a short and concise generalization of the key information of the vulnerability. It usually includes the type of the vulnerability (such as SQL injection, cross - site scripting attack, buffer overflow, etc.), the severity of the vulnerability (such as low, medium, high, critical), the systems or components affected, and the main consequences that the vulnerability may cause (such as data leakage, system crash, privilege escalation, etc.).

[0049] The business function refers to the specific business operations or services involved in the code containing the vulnerability in the entire business system. It describes the tasks that this part of the code should originally complete from a business perspective, such as specific business processes like user registration, order processing, data query, etc.

[0050] The vulnerability constraint conditions refer to the limiting factors for the functional module where the vulnerable code is located during the code implementation and business operation processes. These limitations may come from multiple aspects such as business rules, security policies, performance requirements, and compatibility requirements. For example, the password length must be between 8 - 16 digits, the file upload size cannot exceed 2MB, and the system must be compatible with a specific version of the browser, etc.

[0051] The vulnerability context information refers to the broader information environment related to the vulnerability, including the system architecture where the vulnerable code is located, other modules it interacts with, the environment where the code runs (such as the operating system, database system, etc.), and the location and conditions where the vulnerability is triggered in the business process. It provides a more comprehensive perspective to help understand how the vulnerability is integrated into the entire system and under what circumstances it will be exploited.

[0052] In some exemplary embodiments, obtaining the basic data of the firmware service program to be detected includes: analyzing the source code or decompiled code of the firmware service program to be detected using a static analysis tool to obtain the static analysis result corresponding to the firmware service program to be detected, where the static analysis result includes data flow and control flow; analyzing the source code or decompiled code of the firmware service program to be detected using a third large language model to obtain the large model analysis result corresponding to the firmware service program to be detected, where the large model analysis result includes vulnerability-related function summaries, service functions, service scenarios, and description information; combining the static analysis result and the large model analysis result corresponding to the firmware service program to be detected to obtain the basic data of the firmware service program to be detected.

[0053] Thus, by combining the static analysis result and the large model analysis result corresponding to the firmware service program to be detected, basic data such as the function description, high-level function summary, loop summary, data dependency relationship, and program call graph of the firmware service program to be detected can be obtained, thereby further ensuring the accuracy of the constructed business object knowledge graph and laying a good foundation for obtaining accurate logical vulnerability detection results in the subsequent process.

[0054] Specifically, a third large language model (such as DeepSeek) can be used to automatically analyze the source code or disassembly code (decompiled code) of the firmware service program to be detected, automatically identify and extract the functions of each function in the code, especially vulnerability-related functions (functions that often have vulnerabilities, such as logical judgment functions), analyze each code block, especially the service scenarios related to vulnerabilities (such as the application scenarios of the authentication function), and at the same time generate vulnerability-related function summaries, service functions, service scenarios, and description information (including vulnerability descriptions, service function descriptions, and service scenario descriptions). At the same time, use a static analysis tool to analyze the above-mentioned firmware service program to be detected to generate key information such as data flow and control flow.

[0055] Please continue to refer to Figure 3 , which is a flowchart of obtaining sensitive control flow and business logic vulnerability paradigms provided by an embodiment of the present invention. As Figure 3 shown, in some exemplary embodiments, step S300, based on the business logic vulnerability knowledge base, using a retrieval-augmented generation algorithm to obtain the sensitive control flow and business logic vulnerability paradigms corresponding to the firmware service program to be detected, includes the following steps S310 to step S330.

[0056] Step S310: Based on the source code or decompiled code of the firmware business program to be detected, retrieve in the pre-created vector database through a retrieval-augmented generation algorithm to obtain a target vulnerability report associated with the target logic vulnerability in the firmware business program to be detected and the corresponding target vulnerability code.

[0057] Step S320: Perform code semantic description on the target vulnerability code to construct a business logic vulnerability paradigm corresponding to the target logic vulnerability.

[0058] Step S330: Perform similarity matching on the business logic vulnerability paradigm in the business logic vulnerability knowledge base to obtain the vulnerability function summary and sensitive control flow corresponding to the target logic vulnerability.

[0059] Thus, by using a retrieval-augmented generation algorithm (RAG) to retrieve in the pre-created vector database, it can effectively ensure the accuracy of the retrieved target vulnerability report associated with the target logic vulnerability and the corresponding target vulnerability code, and further ensure the accuracy of the obtained vulnerability function summary and sensitive control flow information, thereby laying a good foundation for obtaining accurate logic vulnerability detection results in the subsequent process.

[0060] Specifically, the creation process of the vector database includes: First, collect the vulnerability reports generated after detecting the firmware business program and the corresponding vulnerability codes based on the firmware business program vulnerability data sources mentioned above. These vulnerability reports detail various vulnerability information existing in the business object program (firmware business program), including descriptions of the type, location, potential impact, etc. of the vulnerabilities. The corresponding vulnerability codes specifically point to the program code segments with vulnerabilities, providing a key basis for further analyzing and processing the vulnerabilities.

[0061] Next, perform vectorization processing on the collected vulnerability reports and vulnerability codes. During the vectorization process, use natural language processing techniques and code analysis algorithms to transform the text information in the vulnerability reports and the structural and semantic features of the vulnerability codes into high-dimensional vector representations. This vectorization processing can effectively capture the essential features of the vulnerability reports and vulnerability codes, enabling them to be efficiently stored and retrieved in the vector space.

[0062] Finally, store the vectorized vulnerability reports and vulnerability codes in a dedicated vector database. This vector database has efficient data storage and retrieval capabilities and can quickly respond to subsequent queries and analysis requirements for vulnerability information. The vulnerability report and vulnerability code vectors stored in the vector database can be conveniently associated and analyzed with other relevant data, providing strong support for the vulnerability repair and security reinforcement of the business object program.

[0063] When the target code segment in the source code or decompiled code of the firmware business program to be detected is retrieved, the most similar code segment (target vulnerability code) can be directly searched in the vector database, and the corresponding vulnerability (target logic vulnerability) can be associated. After the retrieval of the target code segment is completed, the associated vulnerability report (target vulnerability report) can be used as the basic vulnerability knowledge for subsequent analysis.

[0064] Based on the retrieved vulnerability code (target vulnerability code) above, use the semantics of the code (e.g., function summary of the code, data dependency relationships, and sensitive control flow information) to describe the vulnerability and construct a business logic vulnerability paradigm. This paradigm includes vulnerability code semantic information such as the code functions that may generate logic vulnerabilities, the attributes or operations of the vulnerability code, etc. Then, by matching similar logic vulnerability paradigms in the business logic vulnerability knowledge base (an association relationship between the logic vulnerability paradigm and the vulnerability function summary and sensitive control flow was established when constructing the logic vulnerability paradigms in the business logic vulnerability knowledge base), the function summary (vulnerability function summary) and sensitive control flow of the business logic vulnerability (i.e., the target logic vulnerability) can be obtained.

[0065] In some exemplary embodiments, the firmware logic vulnerability detection method based on the thought chain of the large language model provided by the present invention further includes: retrieving in the business logic vulnerability knowledge base based on the target vulnerability report to obtain a vulnerability information summary, business function, vulnerability constraint conditions, and vulnerability context information that match the target logic vulnerability.

[0066] Specifically, based on the vulnerability name and vulnerability number in the target vulnerability report, the associated vulnerability (target logic vulnerability) can be retrieved, so as to obtain the vulnerability information summary, business function, constraint conditions, and vulnerability context information that match the target logic vulnerability in the vulnerability knowledge base.

[0067] Please continue to refer to Figure 4 , which is a flowchart of generating multi-level prompt words provided by an embodiment of the present invention. As Figure 4 shown, in some exemplary embodiments, step S400, based on the business logic vulnerability paradigm and sensitive control flow corresponding to the firmware business program to be detected, uses the large language model thought chain technology to decompose the reasoning process of the logic vulnerability and the related taint analysis process to iteratively generate multi-level prompt words corresponding to the logic vulnerability analysis steps, including step S410 and step S420 described below.

[0068] Step S410, according to the business logic vulnerability paradigm and sensitive control flow corresponding to the firmware business program to be detected, as well as the vulnerability information summary, business function, vulnerability constraint conditions, and vulnerability context information that match the target logic vulnerability, uses the large language model thought chain technology to decompose the reasoning process of the logic vulnerability and the related taint analysis process.

[0069] Step S420: Iteratively generate multi-level prompting words corresponding to function call chain taint tracking analysis, security vulnerability judgment, and constraint solving.

[0070] Thus, based on the vulnerability information summary, business functions, vulnerability constraint conditions, and vulnerability context information retrieved from the business logic vulnerability knowledge base, as well as the business logic vulnerability paradigm, vulnerability function summary, and sensitive control flow corresponding to the business program of the firmware to be detected, by using the automated chain of thought, the logical vulnerability reasoning and related taint analysis processes can be decomposed, and multi-level prompting words corresponding to common vulnerability analysis steps such as function call chain taint tracking analysis, security vulnerability judgment, and constraint solving can be effectively iteratively generated. As a result, the business logic and other related functional characteristics of the vulnerability can be extracted using the prompting words in the large language model, and then the functional background of the vulnerable code can be accurately obtained.

[0071] Specifically, since the vulnerability paradigms of different business logic vulnerabilities vary greatly, different chains of thought need to be established for different types of business logic vulnerabilities. For example, the lack of authentication vulnerability refers to the situation where no authentication mechanism is implemented in the system or application program, resulting in users or attackers being able to directly access certain sensitive resources or perform certain operations without verifying their identities or permissions; the authentication bypass vulnerability refers to the situation where there is an authentication mechanism in the system or application program, but due to design or implementation defects, attackers can bypass the permission check through specific means and access or operate resources that are not within their permission scope.

[0072] In some exemplary embodiments, the firmware logic vulnerability detection method based on the chain of thought of the large language model provided by the present invention further includes: analyzing the target vulnerability report using the first large language model to obtain the functional description of the target vulnerable code associated with the target logic vulnerability and the root cause of the target logic vulnerability.

[0073] The functional description of the target vulnerable code refers to the elaboration of the tasks and responsibilities assumed by the code with vulnerabilities in the entire program system. It mainly describes the functions that the code should implement when running normally, including how the code receives input, what processing is performed on the input, how it interacts with other components (such as databases, external interfaces, etc.), and what output is finally generated.

[0074] The root cause of the vulnerability is the defect existing in the design, implementation, or configuration process of the code, which enables attackers to utilize the vulnerability of the system to achieve unintended purposes, such as obtaining sensitive information, performing malicious operations, etc.

[0075] Please continue to refer to Figure 5 , which is a flowchart of obtaining the logical vulnerability detection result based on the second large language model provided by an embodiment of the present invention. AsFigure 5 As shown, in some exemplary embodiments, in step S500, based on the multi-level prompt words and the business object knowledge graph, a second large language model is used for taint analysis to obtain the logical vulnerability detection result corresponding to the firmware service program to be detected, including steps S510 to S530 below.

[0076] Step S510: Input the function description of the target vulnerability code and the root cause of the target logical vulnerability into the second large language model.

[0077] Step S520: Input the multi-level prompt words, the business object knowledge graph, the sensitive control flow, and the data flow corresponding to the firmware service program to be detected into the second large language model in sequence.

[0078] Step S530: Use the taint analysis algorithm to gradually infer whether each node function in the sensitive control flow violates the security policy to obtain the logical vulnerability detection result corresponding to the firmware service program to be detected.

[0079] Thus, by inputting the function description of the target vulnerability code and the root cause of the target logical vulnerability into the second large language model (such as Llama3), it can help the second large language model better understand the logical vulnerability to be analyzed; by inputting the multi-level prompt words, the business object knowledge graph, the sensitive control flow, and the data flow corresponding to the firmware service program to be detected into the second large language model in sequence, the large language model can be used to gradually infer each node function in the sensitive control flow according to the taint analysis steps to determine whether it violates the security policy, thereby effectively ensuring the accuracy of the obtained logical vulnerability detection result.

[0080] Specifically, the logical vulnerability detection result output by the second large language model includes the vulnerability location, vulnerability type, vulnerability verification program (PoC), and vulnerability principle.

[0081] Furthermore, the context business features of the vulnerability location can be extracted based on the multi-level prompt words and combined with the existing vulnerability information in the public dataset to form a complete vulnerability sample dataset, so that when the large language model responds to a vulnerability attack, it can autonomously locate the vulnerability location and repair the vulnerability code.

[0082] Based on the same inventive concept, the present invention also provides a firmware logical vulnerability detection system based on the thought chain of a large language model. Please refer to Figure 6 , which is the structural block diagram of the firmware logical vulnerability detection system based on the thought chain of a large language model provided by an embodiment of the present invention. As Figure 6As shown in the figure, the firmware logic vulnerability detection system based on the chain of thought of large language models provided by the present invention includes a knowledge base construction module 110, a knowledge graph construction module 120, a retrieval enhancement module 130, a multi-level prompt word generation module 140, and a business logic vulnerability analysis module 150. The knowledge base construction module 110 is configured to process the collected firmware business program vulnerability data sources using a first large language model to construct a business logic vulnerability knowledge base. The business logic vulnerability knowledge base includes vulnerability information summaries, vulnerability context information, vulnerability constraint conditions, logic vulnerability paradigms, and business functions corresponding to different types of business logic vulnerabilities. The knowledge graph construction module 120 is configured to construct a business object knowledge graph based on the basic data of the firmware business program to be detected. The basic data includes function descriptions, high-level function summaries, loop summaries, data dependency relationships, and program call graphs. The retrieval enhancement module 130 is configured to obtain the sensitive control flow and business logic vulnerability paradigms corresponding to the firmware business program to be detected based on the business logic vulnerability knowledge base using a retrieval enhancement generation algorithm. The multi-level prompt word generation module 140 is configured to decompose the reasoning process of the logic vulnerability and the related taint analysis process based on the business logic vulnerability paradigm and the sensitive control flow corresponding to the firmware business program to be detected using the large language model chain of thought technology, and iteratively generate multi-level prompt words corresponding to the logic vulnerability analysis steps. The business logic vulnerability analysis module 150 is configured to perform taint analysis using a second large language model based on the multi-level prompt words and the business object knowledge graph to obtain the logic vulnerability detection result corresponding to the firmware business program to be detected.

[0083] It should be noted that the firmware logic vulnerability detection system based on the chain of thought of large language models provided by the present invention can be used to execute the firmware logic vulnerability detection method based on the chain of thought of large language models described above. The technical principles, the technical problems solved, and the technical effects produced by the two are similar. Those skilled in the art of this technology can clearly understand that for the convenience and conciseness of description, more content about the firmware logic vulnerability detection system based on the chain of thought of large language models provided by the present invention can refer to the content described in the above firmware logic vulnerability detection method based on the chain of thought of large language models provided by the present invention, and will not be elaborated here.

[0084] Based on the same inventive concept, the present invention also provides an electronic device. Please refer to Figure 7 which is the structural block diagram of the electronic device provided by an embodiment of the present invention. As Figure 7As shown, the electronic device may include: a processor 210, a communication interface 220, a memory 230, and a communication bus 240. Among them, the processor 210, the communication interface 220, and the memory 230 complete mutual communication through the communication bus 240. The processor 210 may call the computer program in the memory 230 to execute the firmware logic vulnerability detection method based on the large language model thought chain described above. Since the electronic device provided by the present invention and the firmware logic vulnerability detection method based on the large language model thought chain provided by the present invention belong to the same inventive concept, the electronic device provided by the present invention has at least all the beneficial effects of the firmware logic vulnerability detection method based on the large language model thought chain provided by the present invention. For specific reference, please refer to the relevant descriptions above. Therefore, the beneficial effects of the electronic device provided by the present invention will not be elaborated one by one here.

[0085] It should be noted that the computer program in the memory 230 can be implemented in the form of a software functional unit and sold or used as an independent product. It can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the firmware logic vulnerability detection method based on the large language model thought chain described in the present invention. The aforementioned storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks, or optical discs that can store program codes.

[0086] Based on the same inventive concept, the present invention also provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it implements the firmware logic vulnerability detection method based on the large language model thought chain described above. Since the computer-readable storage medium provided by the present invention and the firmware logic vulnerability detection method based on the large language model thought chain provided by the present invention belong to the same inventive concept, the computer-readable storage medium provided by the present invention has at least all the beneficial effects of the firmware logic vulnerability detection method based on the large language model thought chain provided by the present invention. For specific reference, please refer to the relevant descriptions above. Therefore, the beneficial effects of the computer-readable storage medium provided by the present invention will not be elaborated one by one here.

[0087] In summary, compared with the prior art, the firmware logic vulnerability detection method, system, electronic device, and computer-readable storage medium provided by the present invention based on the chain of thought of large language models have the following beneficial effects: By using the first large language model to process the firmware business program vulnerability data source collected, the present invention can make full use of the large language model's ability to understand the semantics of vulnerability code, construct a business logic vulnerability knowledge base covering various typical business logic vulnerability paradigms, so as to ensure that the present invention can detect various business logic vulnerabilities in IoT terminal firmware; By constructing a business object knowledge graph based on basic data such as the function description, high-level function summary, loop summary, data dependency relationship, and program call graph of the firmware business program to be detected, the accuracy of the subsequent logic vulnerability detection result of the firmware business program to be detected can be further ensured; Based on the business logic vulnerability knowledge base, by using the retrieval-enhanced generation algorithm to obtain the sensitive control flow and business logic vulnerability paradigm corresponding to the firmware business program to be detected, a high-dimensional mapping between the control flow semantic representation and potential vulnerability types can be established, so as to dynamically and adaptively provide guiding examples for the large language model chain of thought technology; By using the large language model chain of thought technology, decomposing the reasoning process of logic vulnerabilities and related taint analysis processes, and generating multi-level prompts (Prompts) corresponding to the call chain data flow tracking analysis and security vulnerability existence judgment vulnerability analysis atomic operations, the context learning and fine-tuning of the large language model can be iteratively advanced; Based on the multi-level prompt words and the business object knowledge graph, by using the second large language model for taint analysis, the large language model can be driven to gradually infer whether each node function of the sensitive control flow of the firmware business program to be detected violates the security policy according to the taint analysis steps, so as to effectively ensure the accuracy of the logic vulnerability detection result of the firmware business program to be detected.

[0088] It should be noted that computer program code for performing the operations of the present invention can be written in one or more programming languages or combinations thereof. The programming languages include object-oriented programming languages such as Java, Smalltalk, C++, and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, executed as an independent software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computer (for example, by using an Internet service provider to connect through the Internet).

[0089] It should be noted that the devices and methods disclosed in the embodiments of this article can also be implemented in other ways. The device embodiments described above are merely illustrative. For example, the flowcharts and block diagrams in the accompanying drawings show the possible architectures, functions, and operations of devices, methods, and computer program products according to multiple embodiments of this article. In this regard, each block in the flowchart or block diagram may represent a module, program, or part of code, and the module, program segment, or part of code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than that marked in the accompanying drawings. For example, two consecutive blocks can actually be executed substantially in parallel, and they can sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, as well as the combination of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system for performing the specified functions or actions, or can be implemented by a combination of dedicated hardware and computer instructions. Additionally, the functional modules in each embodiment of this article can be integrated together to form an independent part, or each module can exist separately, or two or more modules can be integrated to form an independent part.

[0090] It should also be noted that the above description is only a description of the preferred embodiments of the present invention and does not limit the scope of the present invention in any way. Any changes and modifications made by those of ordinary skill in the field of the present invention based on the above disclosure fall within the protection scope of the present invention. Obviously, those skilled in the art can make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if these modifications and variations fall within the scope of the present invention and its equivalent technologies, the present invention also intends to include these modifications and variations.

Claims

1. A firmware logic vulnerability detection method based on a large language model thinking chain, characterized in that: include: The first language model is used to process the collected firmware business program vulnerability data source to construct a business logic vulnerability knowledge base, wherein the business logic vulnerability knowledge base includes vulnerability information summaries, vulnerability context information, vulnerability constraints, logic vulnerability paradigms, and business functions corresponding to different types of business logic vulnerabilities, wherein the logic vulnerability paradigm includes vulnerability code semantic information, and the vulnerability code semantic information includes code functions related to logic vulnerabilities, and attributes or operations of vulnerability codes; Obtain basic data of the firmware business program to be detected, and construct a business object knowledge graph based on the basic data of the firmware business program to be detected, wherein the basic data includes function description, high-level function summary, loop summary, data dependency and program call graph; Based on the business logic vulnerability knowledge base, a retrieval enhancement generation algorithm is used to obtain the sensitive control flow and business logic vulnerability paradigm corresponding to the firmware business program to be detected; Based on the business logic vulnerability paradigm and sensitive control flow corresponding to the firmware business program to be detected, the large language model thinking chain technology is used to decompose the reasoning process of the logic vulnerability and the related taint analysis process to iteratively generate multi-level prompt words corresponding to the logic vulnerability analysis steps; Based on the multi-level prompt words and the business object knowledge graph, a second language model is used to perform taint analysis to obtain a logic vulnerability detection result corresponding to the firmware business program to be detected; The method of obtaining the sensitive control flow and business logic vulnerability paradigm corresponding to the firmware business program to be detected by using a retrieval enhancement generation algorithm based on the business logic vulnerability knowledge base includes: Based on the source code or decompiled code of the firmware business program to be detected, a search is performed in a pre-created vector database through a search enhancement generation algorithm to obtain a target vulnerability report associated with a target logical vulnerability in the firmware business program to be detected and a corresponding target vulnerability code; Performing code semantic description on the target vulnerability code to construct a business logic vulnerability paradigm corresponding to the target logic vulnerability; The business logic vulnerability paradigm is similarly matched in the business logic vulnerability knowledge base to obtain the vulnerability function summary and sensitive control flow corresponding to the target logic vulnerability.

2. The firmware logic vulnerability detection method based on large language model thinking chain according to claim 1 is characterized in that: The step of obtaining basic data of the firmware service program to be detected includes: Using a static analysis tool to analyze the source code or decompiled code of the firmware service program to be detected to obtain a static analysis result corresponding to the firmware service program to be detected, wherein the static analysis result includes a data flow and a control flow; Using a third language model to analyze the source code or decompiled code of the firmware business program to be detected, so as to obtain a large model analysis result corresponding to the firmware business program to be detected, wherein the large model analysis result includes a vulnerability associated function summary, business function, business scenario and description information; The static analysis result corresponding to the firmware business program to be detected is combined with the large model analysis result to obtain basic data of the firmware business program to be detected.

3. The firmware logic vulnerability detection method based on large language model thinking chain according to claim 1 is characterized in that: The method further comprises: Based on the target vulnerability report, a search is performed in the business logic vulnerability knowledge base to obtain vulnerability information summaries, business functions, vulnerability constraints, and vulnerability context information that match the target logic vulnerability.

4. The firmware logic vulnerability detection method based on large language model thinking chain according to claim 3 is characterized in that: Based on the business logic vulnerability paradigm and sensitive control flow corresponding to the firmware business program to be detected, the large language model thinking chain technology is used to decompose the reasoning process of the logic vulnerability and the related taint analysis process to iteratively generate multi-level prompt words corresponding to the logic vulnerability analysis steps, including: According to the business logic vulnerability paradigm and sensitive control flow corresponding to the firmware business program to be detected, as well as the vulnerability information summary, business function, vulnerability constraint conditions and vulnerability context information matching the target logic vulnerability, the large language model thinking chain technology is used to decompose the reasoning process of the logic vulnerability and the related taint analysis process; Iteratively generate multi-level prompt words corresponding to function call chain taint tracking analysis, security vulnerability judgment and constraint solving.

5. The firmware logic vulnerability detection method based on large language model thinking chain according to claim 3 is characterized in that: The method further comprises: The target vulnerability report is analyzed using the first language model to obtain a functional description of a target vulnerability code associated with the target logic vulnerability and a root cause of the target logic vulnerability.

6. The firmware logic vulnerability detection method based on large language model thinking chain according to claim 5 is characterized in that: The method of performing taint analysis based on the multi-level prompt words and the business object knowledge graph using the second largest language model to obtain a logic vulnerability detection result corresponding to the firmware business program to be detected includes: Inputting the functional description of the target vulnerability code and the root cause of the target logic vulnerability into the second largest language model; Inputting the multi-level prompt words, the business object knowledge graph, the sensitive control flow, and the data flow corresponding to the firmware business program to be detected into the second language model in sequence; A taint analysis algorithm is used to gradually infer whether each node function in the sensitive control flow violates the security policy, so as to obtain the logic vulnerability detection result corresponding to the firmware business program to be detected.

7. A firmware logic vulnerability detection system based on a large language model thinking chain, characterized in that: include: a knowledge base construction module configured to process the collected firmware business program vulnerability data source using the first language model to construct a business logic vulnerability knowledge base, wherein the business logic vulnerability knowledge base includes vulnerability information summaries, vulnerability context information, vulnerability constraints, logic vulnerability paradigms, and business functions corresponding to different types of business logic vulnerabilities, wherein the logic vulnerability paradigm includes vulnerability code semantic information, and the vulnerability code semantic information includes code functions related to logic vulnerabilities, and attributes or operations of vulnerability codes; A knowledge graph construction module is configured to construct a business object knowledge graph based on basic data of the firmware business program to be detected, wherein the basic data includes function description, high-level function summary, loop summary, data dependency and program call graph; A retrieval enhancement module is configured to obtain the sensitive control flow and business logic vulnerability paradigm corresponding to the firmware business program to be detected by using a retrieval enhancement generation algorithm based on the business logic vulnerability knowledge base; A multi-level prompt word generation module is configured to use a large language model thinking chain technology to decompose the reasoning process of the logic vulnerability and the related taint analysis process based on the business logic vulnerability paradigm and sensitive control flow corresponding to the firmware business program to be detected, so as to iteratively generate multi-level prompt words corresponding to the logic vulnerability analysis steps; as well as A business logic vulnerability analysis module is configured to perform taint analysis using a second language model based on the multi-level prompt words and the business object knowledge graph to obtain a logic vulnerability detection result corresponding to the firmware business program to be detected; The method of obtaining the sensitive control flow and business logic vulnerability paradigm corresponding to the firmware business program to be detected by using a retrieval enhancement generation algorithm based on the business logic vulnerability knowledge base includes: Based on the source code or decompiled code of the firmware business program to be detected, a search is performed in a pre-created vector database through a search enhancement generation algorithm to obtain a target vulnerability report associated with a target logical vulnerability in the firmware business program to be detected and a corresponding target vulnerability code; Performing code semantic description on the target vulnerability code to construct a business logic vulnerability paradigm corresponding to the target logic vulnerability; The business logic vulnerability paradigm is similarly matched in the business logic vulnerability knowledge base to obtain the vulnerability function summary and sensitive control flow corresponding to the target logic vulnerability.

8. An electronic device, characterized in that: It includes a processor and a memory, wherein a computer program is stored in the memory, and when the computer program is executed by the processor, the firmware logic vulnerability detection method based on the large language model thinking chain as described in any one of claims 1 to 6 is implemented.

9. A computer-readable storage medium, characterized in that: A computer program is stored thereon, and when the computer program is executed by a processor, the firmware logic vulnerability detection method based on a large language model thinking chain as described in any one of claims 1 to 6 is implemented.

Citation Information

Patent Citations

  • Vulnerability relationship mining method and device based on large model, equipment and medium

    CN117390634A

  • Code risk detection method and device, electronic equipment and computer storage medium

    CN118673497A