Automated Security Vulnerability Detection Method, System, Electronic Device and Readable Storage Medium for Multiple Types of Scripts in Embedded Systems

By unpacking and analyzing the firmware of the embedded system, the dependencies between script files and template files are identified, and control flow analysis and stain analysis technology is used to solve the security vulnerability detection problem of multiple types of scripts in embedded systems, achieving efficient and accurate vulnerability detection and analysis.

CN119691758BActive Publication Date: 2025-06-13SHANGHAI JIAOTONG UNIV
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510206889.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-02-25
Publication Date
2025-06-13
Estimated Expiration
2045-02-25

AI Technical Summary

Technical Problem

The prior art is difficult to automatically identify security vulnerabilities in multiple types of scripts in embedded systems, especially in complex environments of dynamic execution and multi-script types, and lacks effective vulnerability detection methods.

Method used

By unpacking and analyzing the firmware of the embedded system, the dependencies and interactions between script files and template files are identified, and the context-sensitive control flow analysis algorithm is used to generate control flow diagrams and abstract syntax trees. Combined with data flow analysis and stain analysis, it can identify dangerous execution paths from sensitive input sources to potential vulnerabilities.

Benefits of technology

It realizes automated security vulnerability detection of multiple types of scripts in embedded systems, improves the accuracy and comprehensiveness of vulnerability detection, can span the interaction between different types of scripts, reduces labor costs and improves adaptability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119691758B_ABST
    Figure CN119691758B_ABST
Patent Text Reader

Abstract

The present invention provides an automated security vulnerability detection method, system, electronic device and readable storage medium for multiple types of scripts in an embedded system. The method includes: unpacking and analyzing the firmware of the embedded system to be detected to identify script files and template files; identifying the dependency relationships between the script files and the template files, as well as the interactions and dependency relationships between different types of the script files, marking sensitive input source points and potential vulnerability sink points, and generating a control flow graph and an abstract syntax tree by using a context-sensitive control flow analysis algorithm; constructing a power set lattice according to the assignment statements in the control flow graph and performing data flow analysis by using a fixed-point algorithm to obtain data flow constraint relationships; and performing taint analysis to identify all dangerous execution paths. The present invention can automatically identify script security vulnerabilities, improve the security of the embedded system during script execution, and effectively prevent potential security threats.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of Internet of Things security technology, and particularly to an automated security vulnerability detection method, system, electronic device and readable storage medium for multiple types of scripts in an embedded system. Background Art

[0002] With the rapid development of Internet of Things (IoT) technology, embedded systems have been widely used in various intelligent devices, covering multiple fields such as home automation, intelligent transportation, and industrial control. These embedded systems usually need to process a large amount of external input data, including user instructions, communication information between devices, etc. In order to achieve flexible function expansion and device interaction, embedded systems often use various scripting languages for configuration and control. Although these scripting languages improve the programmability and adaptability of the system, they also bring potential security risks to the system.

[0003] Traditional embedded system security protection methods mostly focus on hardware-level protection or static code analysis. However, when facing dynamically executed scripts, these methods often lack effective vulnerability detection means. Especially in the process of processing multiple types of scripts, how to identify and prevent attacks through script injection, script malicious tampering, etc. has become an important challenge for embedded system security.

[0004] Currently, although there are some security detection technologies for embedded systems, most methods still rely on manual review and static analysis tools, lacking automation and efficiency, and it is difficult to comprehensively cover all potential security hazards in a dynamic environment with multiple script types. Therefore, how to design a method that can automatically identify script security vulnerabilities has become a key problem that urgently needs to be solved in the field of embedded system security.

[0005] It should be noted that the information disclosed in the background art of the present invention is only intended to deepen the understanding of the general background technology of the present invention, and should not be regarded as an admission or any form of suggestion that this information constitutes the prior art known to those skilled in the art. Summary of the Invention

[0006] The purpose of the present invention is to provide an automated security vulnerability detection method, system, electronic device and readable storage medium for multiple types of scripts in an embedded system, which can automatically identify script security vulnerabilities, improve the security of the embedded system during script execution, and effectively prevent potential security threats, especially for complex system environments with multiple script types.

[0007] To achieve the above object, the present invention provides an automated security vulnerability detection method for multiple types of scripts in an embedded system, including: unpacking and analyzing the firmware of the embedded system to be detected to identify script files and template files in the firmware; identifying the dependency relationships between the script files and the template files and the interactions and dependencies between different types of the script files, and based on the dependency relationships between the script files and the template files and the interactions and dependencies between different types of the script files, marking sensitive input source points and potential vulnerability sink points in the script files and the template files, and using a context-sensitive control flow analysis algorithm to generate a control flow graph and an abstract syntax tree; constructing a power set lattice according to the assignment statements in the control flow graph and performing data flow analysis using a fixed-point algorithm to obtain the data flow constraint relationships between the nodes in the control flow graph; performing taint analysis based on the control flow graph, the abstract syntax tree, and the data flow constraint relationships to identify all dangerous execution paths from the sensitive input source points to the potential vulnerability sink points, thereby obtaining the security vulnerability detection result.

[0008] Optionally, the unpacking and analyzing the firmware of the embedded system to be detected to identify script files and template files in the firmware includes: using a firmware analysis tool to scan and parse the firmware image of the embedded system to be detected to extract the file system in the firmware, and using directory scanning and file suffix matching techniques to identify script files and template files in the file system; using a dynamic behavior simulation algorithm to analyze the files dynamically loaded in the firmware to identify script files.

[0009] Optionally, the identifying the dependency relationships between the script files and the template files and the interactions and dependencies between different types of the script files includes: dynamically reconstructing the dependency relationships between the script files and the template files based on a multi-dimensional collaborative analysis mechanism; constructing a unified syntax and execution semantic model for different types of script files to identify the interactions and dependencies between different types of the script files.

[0010] Optionally, the sensitive input source points include external input data, parameters of API interfaces, and environment variables.

[0011] Optionally, the using a context-sensitive control flow analysis algorithm to generate a control flow graph and an abstract syntax tree includes: performing lexical analysis and syntax analysis on the script files to generate an abstract syntax tree; traversing the abstract syntax tree to extract all function calls, and for each function call, using a context-sensitive control flow analysis algorithm to create an independent function call copy for it, thereby generating a control flow graph.

[0012] Optionally, performing data flow analysis using a fixed-point algorithm to obtain the data flow constraint relationships between the nodes in the control flow graph, including: describing the data transfer relationships between the nodes in the control flow graph using data flow constraint equations; and performing iterative calculations using the fixed-point algorithm according to the data transfer relationships between the nodes in the control flow graph until the data flow constraint relationships converge.

[0013] Optionally, performing taint analysis based on the control flow graph, the abstract syntax tree, and the data flow constraint relationships to identify all dangerous execution paths from the sensitive input source point to the potential vulnerability sink point, including: describing the code structure and execution paths based on the control flow graph and the abstract syntax tree; and tracking the data propagated from the sensitive input source point according to the data flow constraint relationships to identify all dangerous execution paths from the sensitive input source point to the potential vulnerability sink point.

[0014] Optionally, the security vulnerability detection result includes the vulnerability occurrence time, the taint source, the taint convergence point, and the relevant data flow path; the automated security vulnerability detection method for multiple types of scripts in an embedded system provided by the present invention further includes: organizing the vulnerability occurrence time, the taint source, the taint convergence point, and the relevant data flow path in the security vulnerability detection result into an item form and displaying them on the front-end interface.

[0015] To achieve the above object, the present invention further provides an automated security vulnerability detection system for multiple types of scripts in an embedded system, including: a firmware parsing module configured to unpack and analyze the firmware of the embedded system to be detected to identify the script files and template files in the firmware; a dependency and data flow reconstruction module configured to identify the dependency relationships between the script files and the template files and the interactions and dependencies between different types of the script files, and based on the dependency relationships between the script files and the template files and the interactions and dependencies between different types of the script files, mark the sensitive input source points and potential vulnerability sink points in the script files and the template files, and generate a control flow graph and an abstract syntax tree using a context-sensitive control flow analysis algorithm; a data flow constraint relationship analysis module configured to construct a power set lattice according to the assignment statements in the control flow graph and perform data flow analysis using a fixed-point algorithm to obtain the data flow constraint relationships between the nodes in the control flow graph; and a taint analysis module configured to perform taint analysis based on the control flow graph, the abstract syntax tree, and the data flow constraint relationships to identify all dangerous execution paths from the sensitive input source point to the potential vulnerability sink point, thereby obtaining the security vulnerability detection result.

[0016] To achieve the above object, the present invention further provides an electronic device, including a processor and a memory, where a computer program is stored on the memory, and when the computer program is executed by the processor, the automated security vulnerability detection method for multiple types of scripts in an embedded system described above is implemented.

[0017] To achieve the above object, the present invention further provides a readable storage medium, where a computer program is stored in the readable storage medium, and when the computer program is executed by a processor, the automated security vulnerability detection method for multiple types of scripts in an embedded system described above is implemented.

[0018] Compared with the prior art, the automated security vulnerability detection method, system, electronic device, and readable storage medium for multiple types of scripts in an embedded system provided by the present invention have the following beneficial effects:

[0019] The automated security vulnerability detection method for multiple types of scripts in an embedded system provided by the present invention can comprehensively cover multiple types of scripts in the embedded system and identify potential security hazards, avoiding the risk of missing vulnerabilities. In addition, by adopting a context-sensitive control flow analysis algorithm and accurate data flow modeling and tracking, the present invention can effectively capture static and dynamic vulnerabilities, improving the accuracy and comprehensiveness of vulnerability detection. Different from existing static analysis methods, the taint analysis technology in the present invention can automatically identify the dangerous execution paths from sensitive input source points to potential vulnerability sink points, significantly improving the efficiency of vulnerability analysis. At the same time, the present invention can cross the interactions between different types of scripts, mine complex vulnerability hazards, and solve the problem that the vulnerability detection in the prior art has certain limitations. In addition, the present invention has an efficient cross-script type vulnerability detection ability, is easy to deploy and expand, can be quickly integrated into the existing development and testing processes, reduces labor costs, and improves adaptability. In summary, by adopting the automated security vulnerability detection method for multiple types of scripts in an embedded system provided by the present invention, script security vulnerabilities can be automatically identified, significantly improving the effect of embedded system security vulnerability detection, thereby effectively improving the security of the embedded system during script execution, effectively preventing potential security threats, and providing a strong guarantee for the security of the embedded system.

[0020] Since the automated security vulnerability detection system, electronic device, and readable storage medium for multiple types of scripts in an embedded system provided by the present invention belong to the same inventive concept as the automated security vulnerability detection method for multiple types of scripts in an embedded system provided by the present invention, the automated security vulnerability detection system, electronic device, and readable storage medium for multiple types of scripts in an embedded system provided by the present invention at least have all the beneficial effects of the automated security vulnerability detection method for multiple types of scripts in an embedded system provided by the present invention. For specific details, reference can be made to the relevant descriptions in the above text. Therefore, the beneficial effects of the automated security vulnerability detection system, electronic device, and readable storage medium for multiple types of scripts in an embedded system provided by the present invention will not be elaborated one by one herein. BRIEF DESCRIPTION OF THE DRAWINGS

[0021] Figure 1 It is a flowchart of the automated security vulnerability detection method for multiple types of scripts in an embedded system provided by an embodiment of the present invention.

[0022] Figure 2 It is a structural block diagram of the automated security vulnerability detection system for multiple types of scripts in an embedded system provided by an embodiment of the present invention.

[0023] Figure 3 It is a structural block diagram of the electronic device provided by an embodiment of the present invention.

[0024] Among them, the reference numerals are explained as follows: firmware parsing module - 110; dependency and data flow reconstruction module - 120; data flow constraint relationship analysis module - 130; taint analysis module - 140; processor - 210; communication interface - 220; memory - 230; communication bus - 240. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0025] The following further elaborates in detail the automated security vulnerability detection method, system, electronic device, and readable storage medium for multiple types of scripts in an embedded system proposed by the present invention in conjunction with the drawings and specific embodiments. According to the following description, the advantages and features of the present invention will be clearer. It should be noted that the drawings are in a very simplified form and all use non-precise scales, only for the purpose of facilitating and clearly assisting in explaining the purpose of the present invention. In order to make the purpose, features, and advantages of the present invention more obvious and understandable, please refer to the drawings. It should be known that the structures, scales, sizes, etc. shown in the drawings of this specification are only used to cooperate with the content disclosed in the specification for those skilled in this technology to understand and read, and are not used to limit the limiting conditions for the implementation of the present invention. Any modification of the structure, change of the proportional relationship, or adjustment of the size, under the condition of being the same or approximate to the effect that the present invention can produce and the purpose that can be achieved, should still fall within the scope covered by the technical content disclosed by the present invention.

[0026] For the sake of easy understanding, the research background of the present invention will be described first.

[0027] Static analysis technology is a technology that discovers potential security problems by analyzing source code, bytecode, or other program representations without executing the program. For the security vulnerability detection of embedded systems, static analysis can help identify potential vulnerabilities in the code, such as buffer overflows, resource leaks, unvalidated inputs, etc. By analyzing the structure and control flow of the source code, static analysis can discover security risks without running the program.

[0028] The basic process of static analysis includes steps such as code abstraction, vulnerability pattern matching, data flow analysis, and symbolic execution. First, a static code analysis tool converts the source code or binary file into an abstract representation that is easy to analyze, such as an abstract syntax tree (AST) or a control flow graph (CFG). Then, by looking for known vulnerability patterns (such as unsafe function calls), analyzing the control risks of data flows and external inputs, or by simulating the execution process of the program through symbolic execution to detect potential errors.

[0029] When performing static analysis on Internet of Things (IoT) systems, existing related technologies usually rely on taint analysis to track external inputs, and at the same time combine control flow analysis, symbolic execution, and various heuristic methods for assistance to determine the location of security vulnerabilities and whether external inputs may be triggered, and give an alarm containing specific address and path information for security personnel to confirm. Security personnel disassemble the system firmware or binary program through reverse engineering tools (such as IDA Pro or Ghidra) to locate unsafe external calls or potential vulnerability points.

[0030] Dynamic analysis technology is a method of discovering potential problems by executing a program and monitoring its runtime behavior. Different from static analysis, dynamic analysis requires the program to actually run. During this process, the input and output of the program, resource usage, memory access, system calls, etc. can be observed, so as to capture some vulnerabilities that cannot be detected by static analysis. For the security vulnerability detection of embedded systems, dynamic analysis can identify some vulnerabilities caused by complex environmental factors or external inputs during runtime.

[0031] Since IoT system firmware usually lacks a unified runtime environment, dynamic analysis often uses simulation methods to simulate the firmware operation to get rid of the dependence on the underlying hardware. This simulation environment not only solves the hardware adaptation problem, but also provides key internal information for grey-box testing methods, such as path coverage, etc. Currently, existing related research mostly focuses on specific device types, and through implementing system simulation of the firmware and combining heuristic methods to carry out fuzz testing, potential vulnerabilities in the firmware can be effectively discovered.

[0032] Embedded systems typically use closed-source commercial embedded software, and it is difficult to obtain the source code. Therefore, security detection mainly relies on the analysis of firmware and binary programs. However, existing binary analysis tools cannot fully handle the high security and high specificity characteristics of embedded systems, especially the lack of support for scripting languages and template languages embedded in HTML.

[0033] Based on this, the core idea of the present invention is to provide an automated security vulnerability detection method, system, electronic device, and readable storage medium for multiple types of scripts in embedded systems, which can automatically identify script security vulnerabilities, improve the security of embedded systems during script execution, and effectively prevent potential security threats, especially for complex system environments with multiple script types.

[0034] It should be noted that the automated security vulnerability detection method for multiple types of scripts in embedded systems provided by the present invention can be applied to the automated security vulnerability detection system for multiple types of scripts in embedded systems provided by the present invention. The automated security vulnerability detection system for multiple types of scripts in embedded systems can be configured on an electronic device. Among them, the electronic device can be a personal computer, a mobile terminal, etc. The mobile terminal can be a hardware device such as a mobile phone or a tablet computer with various operating systems. It should also be noted that the development platform of the present invention can be the Ubuntu 22.04 operating system and is developed using Python 3.8. Static code analysis is based on the Ghidra framework, and the taint analysis engine is based on the Angr framework.

[0035] To achieve the above idea, the present invention provides an automated security vulnerability detection method for multiple types of scripts in embedded systems. Please refer to Figure 1 , which is a flowchart of the automated security vulnerability detection method for multiple types of scripts in embedded systems provided by an embodiment of the present invention. As Figure 1As shown in the figure, the automated security vulnerability detection method for multiple types of scripts in an embedded system provided by the present invention includes: Step S100, unpacking and analyzing the firmware of the embedded system to be detected to identify the script files and template files in the firmware; Step S200, identifying the dependency relationships between the script files and the template files and the interactions and dependency relationships between different types of the script files, and based on the dependency relationships between the script files and the template files and the interactions and dependency relationships between different types of the script files, marking the sensitive input source points and potential vulnerability sink points in the script files and the template files, and using a context-sensitive control flow analysis algorithm to generate a control flow graph and an abstract syntax tree; Step S300, constructing a power set lattice according to the assignment statements in the control flow graph and performing data flow analysis using a fixed point algorithm to obtain the data flow constraint relationships between the nodes in the control flow graph; Step S400, performing taint analysis based on the control flow graph, the abstract syntax tree, and the data flow constraint relationships to identify all dangerous execution paths from the sensitive input source points to the potential vulnerability sink points, thereby obtaining the security vulnerability detection result.

[0036] The present invention can comprehensively cover multiple types of scripts in an embedded system and identify potential security hazards, avoiding the risk of missing vulnerabilities. In addition, by adopting a context-sensitive control flow analysis algorithm and precise data flow modeling and tracking, the present invention can effectively capture static and dynamic vulnerabilities, improving the accuracy and comprehensiveness of vulnerability detection. Different from existing static analysis methods, the taint analysis technology in the present invention can automatically identify the dangerous execution paths from sensitive input source points to potential vulnerability sink points, significantly improving the efficiency of vulnerability analysis. At the same time, the present invention can cross the interactions between different types of scripts, excavate complex vulnerability hazards, and solve the problem that there are certain limitations in vulnerability detection in the prior art. In addition, the present invention has an efficient cross-script type vulnerability detection ability, is easy to deploy and expand, can be quickly integrated into the existing development and test processes, reduces labor costs and improves adaptability. In summary, by adopting the automated security vulnerability detection method for multiple types of scripts in an embedded system provided by the present invention, script security vulnerabilities can be automatically identified, significantly improving the effect of security vulnerability detection in the embedded system, thereby effectively improving the security of the embedded system during the script execution process, effectively preventing potential security threats, and providing a strong guarantee for the security of the embedded system.

[0037] Furthermore, by identifying the interactions and dependencies between different types of the script files, the present invention can effectively capture the data flow and control flow paths between different types of script files, and thus can effectively analyze potential vulnerability hazards between multiple scripting languages, such as command injection, data leakage, etc. between script files. By tracing the interactions and data flow paths between different script files, security vulnerabilities that may occur in a multi-language environment can be accurately identified to ensure that vulnerability detection covers all possible security hazards. Especially in the context of cross-script analysis, interactive vulnerabilities between script files can be identified. For example, a Shell script affects the execution result of a Python script through a command injection vulnerability, which in turn affects the behavior of a Lua script, ensuring that vulnerability hazards between each script file are comprehensively covered, including vulnerabilities within a single scripting language and cross-language interactions.

[0038] Furthermore, through the generated abstract syntax tree, the present invention can effectively capture the structure of the code, making subsequent analysis more targeted; through the generated control flow graph, it is convenient to trace potential taint paths, judge whether data flows as expected, and identify possible security vulnerabilities. Since the assignment statement is an important operation affecting data flow and plays a key role in data flow analysis, the present invention can more accurately express the impact of the assignment statement on data flow by converting the assignment statement in the control flow graph into a power set lattice form. By using the fixed-point algorithm for data flow analysis to obtain the data flow constraint relationships between the nodes in the control flow graph, it can help accurately trace the data flow path in the program and provide reliable data support for taint analysis; by adopting the taint analysis method, all potential dangerous execution paths from the source point to the sink point can be discovered, and thus potential security hazards can be accurately discovered to help developers repair vulnerabilities in a timely manner.

[0039] In some exemplary embodiments, the step S100 of unpacking and analyzing the firmware of the embedded system to be detected to identify the script files and template files in the firmware includes: using a firmware analysis tool to scan and parse the firmware image of the embedded system to be detected to extract the file system in the firmware, and adopting directory scanning and file suffix matching techniques to identify the script files and template files in the file system; adopting a dynamic behavior simulation algorithm to analyze the files dynamically loaded in the firmware to identify the script files.

[0040] Specifically, the firmware analysis tool can be Binwalk, that is, firmware unpacking can be achieved by using the Binwalk framework. Binwalk is a widely used firmware analysis tool that can scan firmware images and identify common embedded file formats and file systems, thereby extracting individual files from the firmware and providing data support for subsequent analysis. In an embedded system, the firmware is usually based on the OpenWRT operating system, so it is necessary to perform targeted parsing according to the specific format of the firmware. If the firmware uses a vendor-customized format or a special version format, Binwalk may not be able to directly recognize it. In this case, by expanding the functions of Binwalk, the parsing ability for custom firmware formats is enhanced, ensuring that binary files can be accurately extracted even in firmware with special formats, laying a foundation for subsequent static analysis.

[0041] Since static directory scanning and file suffix matching can only locate some of the script files, and some scripts are directly written in the program and cannot be extracted by static extraction alone. Therefore, the present invention uses a dynamic behavior simulation algorithm to analyze the files dynamically loaded in the firmware, which can ensure that all potential script files are covered.

[0042] It should be noted that in an embedded system, script files (such as Lua, Shell, Perl) usually store the core business logic of the device, while template files are used for rendering and configuration management. By matching specific suffixes in the file system (such as ".lua", ".htm", ".sh"), script files with sensitive operations can be identified, providing analysis targets for subsequent steps. By analyzing the dependency relationship between script files and template files, it can be ensured that all relevant code files are fully covered in subsequent vulnerability analysis, thereby improving the accuracy of vulnerability detection.

[0043] In some exemplary embodiments, the sensitive input source points include external input data, parameters of API interfaces, and environment variables.

[0044] Specifically, the sensitive input source points in an embedded system include form data submitted by users (external input data), parameters of API interfaces, environment variables, etc. Through regular expressions and syntax parsing, these sensitive input source points can be identified and marked (such as luci.http.formvalue, luci.http.getcookie, etc.). Further, these sensitive input source points can be automatically identified and classified through a machine learning model.

[0045] In some exemplary embodiments, identifying the dependency relationships between the script file and the template file and the interactions and dependency relationships between different types of the script files in step S200 includes: dynamically reconstructing the dependency relationships between the script file and the template file based on a multi-dimensional collaborative analysis mechanism; for different types of script files, constructing a unified syntax and execution semantic model to identify the interactions and dependency relationships between different types of the script files. Thus, by dynamically reconstructing the dependency relationships between the script file and the template file based on the multi-dimensional collaborative analysis mechanism (combining various analysis methods, such as syntax analysis, control flow analysis, data flow analysis, etc.), the accuracy of the obtained dependency relationships between the script file and the template file can be effectively ensured; by constructing a unified syntax and execution semantic model for different types of script files, the calls and dependencies between scripts can be processed through the unified syntax model, so that the interactions and dependency relationships between different types of the script files can be accurately identified, ensuring that all vulnerability detection requirements can be comprehensively covered in a multi-script environment.

[0046] In some exemplary embodiments, adopting a context-sensitive control flow analysis algorithm in step S200 to generate a control flow graph and an abstract syntax tree includes: performing lexical analysis and syntax analysis on the script file to generate an abstract syntax tree; traversing the abstract syntax tree to extract all function calls, and for each function call, using a context-sensitive control flow analysis algorithm to create an independent function call copy for it, thereby generating a control flow graph.

[0047] Thus, by performing lexical analysis and syntax analysis on the script file to generate an abstract syntax tree, it is convenient to accurately identify each line of code in the script, thereby effectively capturing the code structure and making subsequent analysis more targeted. By traversing the abstract syntax tree to generate a control flow graph, the execution flow of the code can be understood based on the control flow graph. Especially in complex conditional judgments and loop statements, it can be understood how data flow is transmitted and control flow is transferred; through the analysis of the control flow graph, potential taint paths can be traced to determine whether data flows as expected to identify possible security vulnerabilities. By using a context-sensitive control flow analysis algorithm to process each function call: whenever a function is called, an independent function call copy is created for the function, and its control flow is spliced into the control flow graph, which can ensure that the analysis of the same function at different positions does not interfere with each other, thus accurately reflecting the execution path of the program and helping to identify potential security vulnerabilities.

[0048] In some exemplary embodiments, the use of the fixed-point algorithm in step S300 for data flow analysis to obtain the data flow constraint relationships between the nodes in the control flow graph includes: using data flow constraint equations to describe the data transfer relationships between the nodes in the control flow graph; and performing iterative calculations using the fixed-point algorithm according to the data transfer relationships between the nodes in the control flow graph until the data flow constraint relationships converge. Thus, by using data flow constraint equations to describe the constraint relationships between the nodes in the control flow graph, the value of each node can be associated with adjacent nodes. By performing iterative calculations using the fixed-point algorithm until the results of two adjacent iterations no longer change, that is, reaching a fixed point, it indicates that the data flow constraint relationships have converged, so that the flow path of data in the program can be accurately traced, providing reliable data support for taint analysis.

[0049] In some exemplary embodiments, the taint analysis in step S400 based on the control flow graph, the abstract syntax tree, and the data flow constraint relationships to identify all dangerous execution paths from the sensitive input source point to the potential vulnerability sink point includes: describing the code structure and execution paths based on the control flow graph and the abstract syntax tree; and tracking the data propagated from the sensitive input source point according to the data flow constraint relationships to identify all dangerous execution paths from the sensitive input source point to the potential vulnerability sink point.

[0050] Thus, by parsing the abstract syntax tree and the control flow graph, the variable relationships and execution paths in the program can be comprehensively understood. The abstract syntax tree is used to extract key nodes such as function calls and assignment operations, while the control flow graph describes the execution order and jump paths between the nodes. By marking the source points (such as external input data or sensitive interface calls) and tracking the data propagated from these source points, combined with the fixed-point algorithm and the data flow constraint relationships, how the data propagates in the control flow graph can be analyzed, thus ensuring the accuracy of taint propagation. If it is found that the taint in some data flow paths is not correctly processed, then mark these paths as potential dangerous paths and continue in-depth analysis to ensure that the vulnerabilities are thoroughly discovered.

[0051] In some exemplary embodiments, the security vulnerability detection results include the time of vulnerability occurrence, the taint source, the taint sink, and the relevant data flow paths. The automated security vulnerability detection method for multiple types of scripts in an embedded system provided by the present invention further includes: organizing the time of vulnerability occurrence, the taint source, the taint sink, and the relevant data flow paths in the security vulnerability detection results into an item form and displaying them on the front-end interface. Thus, by organizing these information such as the time of vulnerability occurrence, the taint source, the taint sink, and the relevant data flow paths into items and displaying them on the front-end interface, the security assessment of the embedded system can be made more intuitive, and developers can view the detailed information of the vulnerabilities on the interface, analyze potential security risks, and take corresponding repair measures, thereby improving the security and stability of the embedded system.

[0052] Specifically, the template mechanism in the Django framework can be used to generate the web page of the vulnerability detection report, and the view part is responsible for processing requests and passing the results to the front-end for display. In this flexible and efficient way, developers can quickly view the detailed information of each vulnerability and can locate and repair according to the specific data flow paths provided in the report.

[0053] Based on the same inventive concept, the present invention also provides an automated security vulnerability detection system for multiple types of scripts in an embedded system. Please refer to Figure 2 , which is the structural block diagram of the automated security vulnerability detection system for multiple types of scripts in an embedded system provided by an embodiment of the present invention. As Figure 2As shown in the figure, the automated security vulnerability detection system for multiple types of scripts in an embedded system provided by the present invention includes a firmware parsing module 110 configured to unpack and analyze the firmware of the embedded system to be detected to identify script files and template files in the firmware; a dependency and data flow reconstruction module 120 configured to identify the dependency relationships between the script files and the template files and the interactions and dependencies between different types of the script files, and based on the dependency relationships between the script files and the template files and the interactions and dependencies between different types of the script files, mark sensitive input source points and potential vulnerability sink points in the script files and the template files, and generate a control flow graph and an abstract syntax tree using a context-sensitive control flow analysis algorithm; a data flow constraint relationship analysis module 130 configured to construct a power set lattice according to the assignment statements in the control flow graph and perform data flow analysis using a fixed-point algorithm to obtain the data flow constraint relationships between the nodes in the control flow graph; and a taint analysis module 140 configured to perform taint analysis based on the control flow graph, the abstract syntax tree, and the data flow constraint relationships to identify all dangerous execution paths from the sensitive input source points to the potential vulnerability sink points, thereby obtaining the security vulnerability detection result.

[0054] It should be noted that the automated security vulnerability detection system for multiple types of scripts in an embedded system provided by the present invention can be used to execute the automated security vulnerability detection method for multiple types of scripts in an embedded system described above. The technical principles, the technical problems solved, and the technical effects produced by the two are similar. Those skilled in the art of this technology can clearly understand that for the convenience and conciseness of description, for more content about the automated security vulnerability detection system for multiple types of scripts in an embedded system provided by the present invention, reference can be made to the content described in the above text about the automated security vulnerability detection method for multiple types of scripts in an embedded system provided by the present invention, and details will not be repeated here.

[0055] Based on the same inventive concept, the present invention also provides an electronic device. Please refer to Figure 3 which is the structural block diagram of the electronic device provided by an embodiment of the present invention. As Figure 3As shown, the electronic device includes a processor 210 and a memory 230. A computer program is stored on the memory 230. When the computer program is executed by the processor 210, it implements the automated security vulnerability detection method for multiple types of scripts in the embedded system described above. Since the electronic device provided by the present invention and the automated security vulnerability detection method for multiple types of scripts in the embedded system provided by the present invention belong to the same inventive concept, the electronic device provided by the present invention has at least all the beneficial effects of the automated security vulnerability detection method for multiple types of scripts in the embedded system provided by the present invention. Therefore, for the beneficial effects of the electronic device provided by the present invention, reference can be made to the relevant descriptions of the beneficial effects of the automated security vulnerability detection method for multiple types of scripts in the embedded system provided by the present invention above, and details will not be repeated here.

[0056] Please continue to refer to Figure 3 , such as Figure 3 As shown, the electronic device further includes a communication interface 220 and a communication bus 240. Among them, the processor 210, the communication interface 220, and the memory 230 complete mutual communication through the communication bus 240. The communication bus 240 can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. This communication bus 240 can be divided into an address bus, a data bus, a control bus, etc. For the sake of convenience of representation, only a thick line is shown in the figure, but it does not mean that there is only one bus or one type of bus. The communication interface 220 is used for communication between the above-mentioned electronic device and other devices.

[0057] It should be noted that the processor 210 referred to in the present invention may be a Central Processing Unit (CPU), or other general-purpose processors, Digital Signal Processors (DSPs), Application Specific Integrated Circuits (ASICs), Field-Programmable Gate Arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc. The processor 210 is the control center of the electronic device, connecting various parts of the entire electronic device through various interfaces and lines.

[0058] It should also be noted that the processor 210 realizes various functions of the electronic device by running or executing the computer programs stored in the memory 230 and by invoking the data stored in the memory 230. The memory 230 may include non-volatile and / or volatile memories. The non-volatile memory may include read-only memory (ROM), programmable memory (PROM), electrically programmable memory (EPROM), electrically erasable programmable memory (EEPROM), or flash memory. The volatile memory may include random access memory (RAM) or external cache memory. By way of illustration and not limitation, random access memory is available in various forms, such as static random access memory (SRAM), dynamic random access memory (DRAM), synchronous random access memory (SDRAM), double data rate synchronous random access memory (DDR SDRAM), enhanced synchronous random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM), Rambus direct random access memory (RDRAM), direct memory bus dynamic random access memory (DRDRAM), and Rambus dynamic random access memory (RDRAM), etc.

[0059] The present invention also provides a readable storage medium having a computer program stored therein, and when the computer program is executed by a processor, it can implement the above-described automated security vulnerability detection method for multiple types of scripts in an embedded system. Since the readable storage medium provided by the present invention and the automated security vulnerability detection method for multiple types of scripts in an embedded system provided by the present invention belong to the same inventive concept, the readable storage medium provided by the present invention has at least all the beneficial effects of the automated security vulnerability detection method for multiple types of scripts in an embedded system provided by the present invention. Therefore, for the beneficial effects of the readable storage medium provided by the present invention, reference may be made to the relevant descriptions in the above regarding the beneficial effects of the automated security vulnerability detection method for multiple types of scripts in an embedded system provided by the present invention, and details will not be repeated herein.

[0060] In summary, compared with the prior art, the automated security vulnerability detection method, system, electronic device, and readable storage medium for multiple types of scripts in an embedded system provided by the present invention have the following beneficial effects: The present invention can comprehensively cover multiple types of scripts in an embedded system and identify potential security hazards, avoiding the risk of missing vulnerabilities. In addition, by adopting a context-sensitive control flow analysis algorithm and precise data flow modeling and tracking, the present invention can effectively capture static and dynamic vulnerabilities, improving the accuracy and comprehensiveness of vulnerability detection. Different from existing static analysis methods, the taint analysis technology in the present invention can automatically identify the dangerous execution paths from sensitive input source points to potential vulnerability sink points, significantly improving the efficiency of vulnerability analysis. At the same time, the present invention can cross the interactions between different types of scripts, mine complex vulnerability hazards, and solve the problem of certain limitations in vulnerability detection in the prior art. In addition, the present invention has an efficient cross-script type vulnerability detection ability, is easy to deploy and expand, can be quickly integrated into existing development and testing processes, reduces labor costs, and improves adaptability. In summary, it can be seen that the present invention can automatically identify script security vulnerabilities, significantly improve the effect of embedded system security vulnerability detection, thereby effectively improving the security of the embedded system during script execution, effectively preventing potential security threats, and providing a strong guarantee for the security of the embedded system.

[0061] It should be noted that the above description is only a description of the preferred embodiments of the present invention and does not limit the scope of the present invention in any way. Any changes and modifications made by those of ordinary skill in the art of the present invention based on the above disclosure belong to the protection scope of the present invention. Obviously, those skilled in the art can make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if these modifications and variations are within the scope of the present invention and its equivalent technologies, the present invention is also intended to include these modifications and variations.

Claims

1. An automated security vulnerability detection method for multiple types of scripts in embedded systems, characterized in that: include: Unpacking and analyzing the firmware of the embedded system to be detected to identify the script files and template files in the firmware; Identify the dependency relationship between the script file and the template file, as well as the interaction and dependency relationship between different types of script files, and based on the dependency relationship between the script file and the template file, as well as the interaction and dependency relationship between different types of script files, mark sensitive input source points and potential vulnerability sink points in the script file and the template file, and use a context-sensitive control flow analysis algorithm to generate a control flow graph and an abstract syntax tree; Constructing a power set lattice according to the assignment statements in the control flow graph, and performing data flow analysis using a fixed point algorithm to obtain a data flow constraint relationship between nodes in the control flow graph; Performing taint analysis based on the control flow graph, the abstract syntax tree, and the data flow constraint relationship to identify all dangerous execution paths from the sensitive input source point to the potential vulnerability sink point, thereby obtaining a security vulnerability detection result; The unpacking and analyzing of the firmware of the embedded system to be detected to identify the script files and template files in the firmware includes: Scan and parse the firmware image of the embedded system to be detected using a firmware analysis tool to extract the file system in the firmware, and use directory scanning and file suffix matching technology to identify the script files and template files in the file system; Use dynamic behavior simulation algorithm to analyze files dynamically loaded in firmware to identify script files; The identifying the dependency relationship between the script file and the template file and the interaction and dependency relationship between different types of script files includes: Dynamically reconstructing the dependency relationship between the script file and the template file based on a multi-dimensional collaborative analysis mechanism, wherein the multi-dimensional collaborative analysis mechanism includes syntax analysis, control flow analysis, and data flow analysis; For different types of script files, a unified syntax and execution semantics model is constructed to process calls and dependencies between scripts to identify interactions and dependencies between different types of script files.

2. The method for automatic security vulnerability detection of multiple types of scripts in embedded systems according to claim 1, characterized in that: The sensitive input sources include external input data, API interface parameters and environment variables.

3. The method for automatic security vulnerability detection of multiple types of scripts in embedded systems according to claim 1, characterized in that: The context-sensitive control flow analysis algorithm is used to generate a control flow graph and an abstract syntax tree, including: Performing lexical analysis and grammatical analysis on the script file to generate an abstract syntax tree; The abstract syntax tree is traversed to extract all function calls, and for each function call, a context-sensitive control flow analysis algorithm is used to create an independent function call copy for it, thereby generating a control flow graph.

4. The method for automatic security vulnerability detection of multiple types of scripts in embedded systems according to claim 1, characterized in that: The method of using a fixed point algorithm to perform data flow analysis to obtain a data flow constraint relationship between nodes in the control flow graph includes: Using data flow constraint equations to describe the data transfer relationship between nodes in the control flow graph; According to the data transfer relationship between the nodes in the control flow graph, a fixed point algorithm is used to perform iterative calculations until the data flow constraint relationship converges.

5. The method for automatic security vulnerability detection of multiple types of scripts in embedded systems according to claim 1, characterized in that: The taint analysis is performed based on the control flow graph, the abstract syntax tree and the data flow constraint relationship to identify all dangerous execution paths from the sensitive input source point to the potential vulnerability sink point, including: Based on the control flow graph and the abstract syntax tree, describe the code structure and execution path; The data propagated by the sensitive input source point is tracked according to the data flow constraint relationship to identify all dangerous execution paths from the sensitive input source point to the potential vulnerability sink point.

6. The method for automatic security vulnerability detection of multiple types of scripts in embedded systems according to claim 1, characterized in that: The security vulnerability detection result includes the vulnerability occurrence time, taint source, taint convergence point and related data flow path; The method further comprises: The vulnerability occurrence time, taint source, taint convergence point and related data flow paths in the security vulnerability detection results are organized into entry forms and displayed on the front-end interface.

7. An automated security vulnerability detection system for multiple types of scripts in embedded systems, characterized in that: include: A firmware parsing module, configured to unpack and analyze the firmware of the embedded system to be detected, so as to identify script files and template files in the firmware; A dependency and data flow reconstruction module, configured to identify the dependency between the script file and the template file and the interaction and dependency between different types of the script files, and based on the dependency between the script file and the template file and the interaction and dependency between different types of the script files, mark sensitive input source points and potential vulnerability sink points in the script file and the template file, and generate a control flow graph and an abstract syntax tree using a context-sensitive control flow analysis algorithm; A data flow constraint relationship analysis module is configured to construct a power set lattice according to the assignment statements in the control flow graph, and perform data flow analysis using a fixed point algorithm to obtain a data flow constraint relationship between nodes in the control flow graph; as well as a taint analysis module configured to perform taint analysis based on the control flow graph, the abstract syntax tree and the data flow constraint relationship to identify all dangerous execution paths from the sensitive input source point to the potential vulnerability sink point, thereby obtaining a security vulnerability detection result; The unpacking and analyzing of the firmware of the embedded system to be detected to identify the script files and template files in the firmware includes: Scan and parse the firmware image of the embedded system to be detected using a firmware analysis tool to extract the file system in the firmware, and use directory scanning and file suffix matching technology to identify the script files and template files in the file system; Use dynamic behavior simulation algorithm to analyze files dynamically loaded in firmware to identify script files; The identifying the dependency relationship between the script file and the template file and the interaction and dependency relationship between different types of script files includes: Dynamically reconstructing the dependency relationship between the script file and the template file based on a multi-dimensional collaborative analysis mechanism, wherein the multi-dimensional collaborative analysis mechanism includes syntax analysis, control flow analysis, and data flow analysis; For different types of script files, a unified syntax and execution semantics model is constructed to process calls and dependencies between scripts to identify interactions and dependencies between different types of script files.

8. An electronic device, characterized in that: The invention comprises a processor and a memory, wherein a computer program is stored in the memory, and when the computer program is executed by the processor, the method for detecting automatic security vulnerabilities of multiple types of scripts in an embedded system according to any one of claims 1 to 6 is implemented.

9. A readable storage medium, characterized in that: The readable storage medium stores a computer program, and when the computer program is executed by a processor, the method for automatically detecting security vulnerabilities of multiple types of scripts in an embedded system according to any one of claims 1 to 6 is implemented.

Citation Information

Patent Citations

  • Intelligent device remote code execution vulnerability detection method based on static analysis

    CN117744087A