A Firmware Vulnerability Detection Method Based on Differential Symbolic Execution
Through differentiated symbol execution methods, vulnerabilities in embedded firmware are detected and analyzed, and the problem of difficulty in fully covering the key functional paths of firmware in the prior art is solved, and the rapid and accurate detection of potential vulnerabilities in the firmware of IoT devices is achieved.
Patent Information
- Application Number
- CN202510294202.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-13
- Publication Date
- 2025-05-27
- Estimated Expiration
- 2045-03-13
AI Technical Summary
It is difficult for the prior art to effectively detect and analyze potential vulnerabilities in embedded firmware, especially in IoT devices. Due to the complexity and versatility of firmware, traditional static and dynamic analysis methods are difficult to fully cover key functional paths.
Firmware vulnerability detection method based on differentiated symbol execution is adopted, and the calculation amount and analysis time of symbol execution are reduced by obtaining multi-version firmware images, extracting the difference points in the binary file, and prioritizing and differentiating analysis in the symbol execution engine.
It realizes rapid and accurate detection of potential vulnerabilities in the firmware, reduces unnecessary analysis work, improves detection efficiency and accuracy, and provides strong support for the security protection of IoT devices.
Smart Images

Figure CN119783121B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of vulnerability detection, and particularly relates to a firmware vulnerability detection method based on differential symbolic execution. Background Art
[0002] With the rapid popularization of Internet of Things (IoT) devices, many embedded systems such as routers, smart home appliances, and industrial controllers have become an indispensable part of the network architecture. Such devices generally run dedicated or customized firmware to meet specific functional requirements. However, due to reasons such as tight firmware development cycles, high software update frequencies, and limited hardware resources, there are often potential security risks in firmware, such as buffer overflows, integer overflows, format string vulnerabilities, out-of-bounds memory reads and writes, etc. Once these vulnerabilities are maliciously exploited, they will seriously threaten the security and stability of the device and the network it is in, resulting in user privacy leakage, system paralysis, and even larger-scale network attacks.
[0003] Firmware of devices such as routers and smart gateways often integrates multiple functional modules, such as network management, protocol stacks, Web servers, etc. These modules interact through system calls, shared libraries, or message mechanisms. Traditional single static analysis methods are difficult to fully simulate the behavior of firmware during actual operation; while only using dynamic analysis methods may be limited by problems such as difficult-to-set-up operating environments, hardware differences, or emulator compatibility, making it difficult to cover key functional paths.
[0004] Symbolic Execution can, to a certain extent, achieve automated vulnerability discovery by treating program inputs as symbolic variables, executing along the branch paths of the program, and collecting constraints. However, as the number of branches increases, symbolic execution will face a serious "path explosion" phenomenon: the number of branches grows exponentially, leading to a rapid soar in analysis time and resource requirements, making the overall analysis of large-scale firmware infeasible. Summary of the Invention
[0005] Object of the Invention: To provide a firmware vulnerability detection method based on differential symbolic execution, which solves the above problems existing in the prior art.
[0006] Technical Solution: A firmware vulnerability detection method based on differential symbolic execution includes the following steps:
[0007] Obtain firmware images of different configurations of the same device, and label the firmware images as bin 1 、bin 2 、……、bin x to establish an image set;
[0008] Obtain the firmware images in the image set. After using the firmware extraction tool to extract the executable binary files from the firmware images with different version numbers, locate the code segments that have changed in the binary files, filter out the difference points that are irrelevant to the target vulnerability type, and generate a difference list;
[0009] Mark the difference points in the difference list as difference points 1 , difference point 2 , ……, difference point x After that, map them to the symbolic execution engine, and according to the path priorities preset in the symbolic execution engine, sort the marked difference points to establish a priority sorting set;
[0010] Add a difference awareness module and dynamically adjust the path scheduling to the existing binary analysis framework to build a binary analysis test model. Obtain the difference points in the priority sorting set, conduct differential analysis to obtain the differential analysis results, locate vulnerabilities based on the differential analysis results to generate a vulnerability report, and at the same time archive the branch paths of the vulnerability scenarios or difference points;
[0011] After completing the constraint set archiving, verify the authenticity and triggerability of the vulnerability by whether it can automatically generate the corresponding POC input or traffic. When the corresponding POC input or traffic is automatically generated, determine that the vulnerability is truly triggerable; otherwise, it is not triggerable.
[0012] Preferably, the process of filtering out the difference points that are irrelevant to the target vulnerability type is as follows:
[0013] First, obtain the binary files within at least two different version numbers, and label the binary programs in the binary files as P 1 , P 2 ……, P x , where the binary program P 1 contains a set of basic blocks B 1i , the binary program P 2 contains a set of basic blocks B 2i . Calculate the hash values of the basic block B 1i and the basic block B 2i through formula (1), where formula (1) is as follows:
[0014]
[0015] In the formula: h represents the hash value; P x represents the binary version number; i represents the index of the basic block;
[0016] Identify the differential basic block ΔB based on the calculated hash values. When then the basic block B in version P 2 and 2iThe hash value of 1 does not exist in version P, indicating that this basic block is newly added or modified;
[0017] Using the filtering function F of the target vulnerability type, filter the identified differential basic blocks ΔB to obtain differential points ΔB c , and its calculation formula is as formula (2):
[0018] ΔB c ={B∈ΔB|F(B)=True} (2).
[0019] Preferably, after completing the screening of differential points, classify the differential points according to the type of basic blocks to generate a differential list, and the differential list includes at least the location, type, and influence range of the differential points.
[0020] Preferably, the process of sorting the priorities of differential points is as follows:
[0021] Assign a high-level priority mark to the basic block corresponding to the differential point, and adjust the weight of the high-level priority mark as the priority weight according to the importance of the differential point, that is, the basic block corresponding to the differential point is assigned priority marks from high to low corresponding to importance, secondary importance, and universality;
[0022] Assign a delay mark to the basic block corresponding to the non-differential point.
[0023] Preferably, the process of assigning priorities to differential points is as follows:
[0024] Pre-assign a priority value Priority(π) to the corresponding path π of the basic block. Based on whether the path π contains a differential point and the importance w(B Pxi ), and calculate the pre-assigned priority value Priority(π) through formula (3):
[0025]
[0026] In the formula: I(B Pxi ∈ΔBc) represents an indicator function, which is 1 when B Pxi is a differential basic block, and 0 otherwise; w(B Pxi ) represents the importance weight of the differential basic block B Pxi .
[0027] Preferably, the process of mapping differential points to the symbolic execution engine is as follows:
[0028] Map the position of the differential point in the binary to the corresponding node or basic block in the symbolic execution engine, and perform differential-guided symbolic execution on the differential point using the binary analysis test model. The process is as follows:
[0029] Obtain the differential basic block BPxi , given the mapping relationship M, the corresponding node of each differential basic block in the symbolic execution engine is N i , that is, M(B Pxi ) = N i ; merge or process the corresponding intermediate representation nodes to obtain the final intermediate representation node N, that is, M(ΔB) = N, which means that the differential basic block ΔB is mapped to the intermediate representation node N of the symbolic execution engine.
[0030] Preferably, the differential-guided symbolic execution process is as follows:
[0031] Based on the binary analysis test model, in the initial stage, generate new path branches according to the conventional symbolic execution, and judge whether the new path branches contain differential markers. If the new path branches contain differential markers, insert the new path branches into the priority queue and preferentially solve their constraints; otherwise, put them into the ordinary queue to complete the path priority scheduling;
[0032] After completing the path priority scheduling, obtain the number of branch nodes in the new path branches, merge the path states with similar or identical constraints, and based on the threshold, merge or prune the low-priority paths to obtain new paths and establish an optimized branch set Q. Add vulnerability detection assertions at the call points of each branch path in the optimized branch set. When the vulnerability detection assertion satisfies the trigger condition, record the vulnerability and terminate the execution of the branch path.
[0033] Preferably, during the path priority scheduling, a preset priority function quantifies the importance of the new path, and during the symbolic execution, select the new path to execute in descending order of priority, where the priority function formula is as follows:
[0034]
[0035] In the formula: Q j represents the new path in the symbolic execution; δ(Q j ) represents the differential awareness; κ(Q j ) represents the risk degree / vulnerability metric; c(Q j ) represents the cost or complexity of the path; ω1, ω2, ω3 are adjustable weights used to balance the impacts among differential awareness, risk degree, and execution cost;
[0036] Use differential symbolic execution to judge path merging and pruning, and define a similarity function to evaluate the overlapping degree of two paths in terms of constraints or states. The similarity function formula is as follows:
[0037]
[0038] In the formula: C(P xi ) represents the path P xiconstraint set; S(P xi , P (x+1)i ) has a value range of [0, 1]; the closer the value is to 1, it indicates that P xi and P (x+1)i have more similar constraint conditions;
[0039] Preferably, when using incremental execution for differential incremental analysis after version iteration, the savings effect is quantified using the repeated analysis rate metric, and the formula for the repeated analysis rate is as follows:
[0040]
[0041] In the formula: bin x represents the set of paths explored during the analysis of the previous version; P x represents the set of all potential paths to be explored during the analysis of the new version; |bin x ∩P x | represents the number of overlapping paths between the new and old versions.
[0042] Preferably, when using multiple objectives to cover the differential regions and vulnerabilities after version iteration, during execution, the target framework includes at least the total number of paths, analysis time, differential coverage rate, and vulnerability discovery rate. The formula (4) is used to calculate the maximization of the coverage of differential regions, vulnerabilities, and execution time, and formula (4) is as follows:
[0043]
[0044] In the formula: A represents the scheduling algorithm or "execution strategy" of symbolic execution; D(Α) represents the differential coverage rate under this strategy; VulnFound(Α) represents the number of vulnerabilities found or the vulnerability coverage rate in the test set; Time(Α) represents the total analysis time or resource consumption under this strategy; α, β, γ are adjustable parameters that comprehensively measure the balance between differential coverage, vulnerability discovery effect, and analysis cost.
[0045] Beneficial effects: The present invention relates to a firmware vulnerability detection method based on differential symbolic execution. By obtaining multiple versions of firmware images in the firmware, extracting the differential points in the binary files in the firmware images, and through differential path scheduling and pruning, reducing paths that are irrelevant or repetitive to the vulnerabilities, the computational amount of symbolic execution can be reduced, and the analysis time can be shortened;
[0046] Secondly, based on the existing symbolic execution framework, a binary analysis test model is built by adding difference awareness to obtain difference points. In cooperation with symbolic execution, the difference increments after version iteration are analyzed, and the target framework is used to calculate the target maximization to calculate the coverage and execution time of the difference area and vulnerabilities, verify the authenticity and triggerability of the vulnerabilities and generate reports. When dealing with multi-version firmware images, potential vulnerabilities and security issues can be discovered more quickly and accurately, while reducing unnecessary analysis work, providing strong support for the security protection of devices. BRIEF DESCRIPTION OF THE DRAWINGS
[0047] Figure 1 It is a system block diagram of the present invention;
[0048] Figure 2 It is a block diagram for extracting difference points of the present invention;
[0049] Figure 3 It is a block diagram for sorting the priorities of difference points of the present invention. DETAILED DESCRIPTION OF THE INVENTION
[0050] As Figures 1 to 3 shown, the present invention provides a technical solution: a firmware vulnerability detection method based on differential symbolic execution, including the following steps:
[0051] Obtain firmware images of the same device with different configurations, and label the firmware images as bin 1 、bin 2 、……、bin x Establish an image set, obtain the firmware images in the image set, and after using a firmware extraction tool to extract the executable binary files from the firmware images with different version numbers, locate the code fragments that have changed in the binary files. In this embodiment, binary diff analysis or abstract syntax tree level matching is used to locate the code fragments that have changed at the function, basic block, or instruction level in the binary files, and the difference points irrelevant to the target vulnerability type are filtered through optional static analysis to obtain the final key difference points and generate a difference point list. Among them, the process of filtering the difference points irrelevant to the target vulnerability type is as follows:
[0052] First, obtain binary files within at least two different version numbers, and label the binary programs in the binary files as P 1 、P 2 ……、P x , where the binary program P 1 contains a set of basic blocks B 1i , and the binary program P 2 contains a set of basic blocks B 2i . Calculate the basic block B 1i and the basic block B through formula (1)2i The hash value, where formula (1) is as follows:
[0053]
[0054] In the formula: h represents the hash value; P x represents the binary version number; i represents the index of the basic block;
[0055] Identify the differential basic block ΔB based on the calculated hash value. When then version P 2 the basic block B 2i in has no corresponding hash value in version P 1 it means that this basic block is newly added or modified. After generating the differential list, mark the differential points in the differential list as differential point 1 , differential point 2 , ……, differential point x and then map them to the symbolic execution engine. According to the path priority preset in the symbolic execution engine, perform priority sorting on the marked differential points to establish a priority sorting set;
[0056] Then add a differential perception module and dynamically adjust the path scheduling to the existing binary analysis framework to build a binary analysis test model. Obtain the differential points in the priority sorting set, perform differential analysis to obtain the differential analysis result, locate the vulnerability based on the differential analysis result to generate a vulnerability report, and at the same time archive the branch paths of the vulnerability scenario or differential points; By obtaining the firmware images of multiple versions in the firmware, extracting the differential points in the binary files in the firmware images, and through differential path scheduling and pruning, reduce the paths irrelevant to or repetitive with the vulnerability, which can reduce the computational amount of symbolic execution and shorten the analysis time. Secondly, adding differential perception on the basis of the existing symbolic execution framework to build a binary analysis test model can obtain the differential points, cooperate with symbolic execution to analyze the differential increment after version iteration, and use the target framework to calculate the target maximum to calculate the coverage and execution time of the differential region and vulnerability, and verify the authenticity and triggerability of the vulnerability and generate a report.
[0057] After completing the constraint set archiving, verify the authenticity and triggerability of the vulnerability by whether it can automatically generate the corresponding POC input or traffic. When the corresponding POC input or traffic is automatically generated, it is determined that the vulnerability is truly triggerable; otherwise, it is not triggerable. In the case of multi-version firmware images, potential vulnerabilities and security issues can be discovered more quickly and accurately, while reducing unnecessary analysis work, providing strong support for the security protection of the device.
[0058] In a further embodiment, the process of filtering differential points irrelevant to the target vulnerability type is as follows:
[0059] First, obtain binary files within at least two different version numbers, and label the binary programs within the binary files as P 1 , P 2 ……, P x , where the binary program P 1 contains a set of basic blocks B 1i , the binary program P 2 contains a set of basic blocks B 2i . Calculate the hash values of basic block B 1i and basic block B 2i through formula (1), identify and compare the basic blocks, and identify the different basic blocks. Among them, formula (1) is as follows:
[0060]
[0061] In the formula: h represents the hash value; P x represents the binary version number; i represents the index of the basic block;
[0062] Identify the different basic block ΔB based on the calculated hash value. When then the hash value of the basic block B 2 in version P 2i does not exist in version P 1 , it means that this basic block is newly added or modified. For fine-grained difference monitoring, compare each instruction to locate the change of the specific instruction;
[0063] Use the filtering function F of the target vulnerability type to filter the difference points ΔB c of the identified different basic block ΔB. Its calculation formula is as formula (2):
[0064] ΔB c = {B ∈ ΔB|F(B) = True} (2); After completing the filtering of the difference points, classify the difference points according to the type of the basic block to generate a difference list. The difference list includes at least the location, type, and influence range of the difference points for subsequent symbolic execution guidance.
[0065] In a further embodiment, the process of sorting the difference point priorities is as follows:
[0066] Assign a high-priority label to the basic block corresponding to the difference point. Among them, the process of assigning the difference point priority is as follows:
[0067] Pre-assign a priority value Priority(π) to the corresponding path π of the basic block. Based on whether the path π contains a difference point and the importance w(B Pxi ), and calculate the pre-assigned priority value Priority(π) through formula (3):
[0068]
[0069] where: I(B Pxi ∈ΔBc) represents an indicator function, which is 1 when B Pxi is a differential basic block and 0 otherwise; w(B Pxi ) represents the importance weight of the differential basic block B Pxi . The importance weight refers to the relative importance of the differential basic block in the entire vulnerability detection, which is determined by the nature of the differential basic block, its impact on the vulnerability or potential risks. The importance weight is used to reflect the influence of the differential basic block on the detection result. According to the importance degree of the differential point, the weight of the high-level priority mark is adjusted as the priority weight. Therefore, the priority weight is assigned based on the sorting from high to low corresponding to the importance, secondary importance, and universality of the basic block corresponding to the differential point. That is, according to the importance of the differential point, the priority weight is adjusted, which can affect how to select and process the corresponding differential basic block during symbolic execution. Therefore, the priority is adjusted through the influence of the differential basic block and the risk degree of the vulnerability, and the basic block corresponding to the non-differential point is given a delay mark or a delayed processing mark. By performing delay, merging, or pruning operations on the paths that do not contain differential points or are significantly irrelevant, the aim is to reduce ineffective exploration and unnecessary analysis work.
[0070] In a further embodiment, the process of mapping the differential point to the symbolic execution engine is as follows:
[0071] Map the position of the differential point in the binary to the corresponding node or basic block in the symbolic execution engine, and perform differential-guided symbolic execution on the differential point using the binary analysis test model. The process is as follows:
[0072] Obtain the differential basic block B Pxi . Given the mapping relationship M, the corresponding node of each differential basic block in the symbolic execution engine is N i , that is, M(B Pxi ) = N i ; Merge or process the corresponding intermediate representation nodes to obtain the final intermediate representation node N, that is, M(ΔB) = N, which means that the differential basic block ΔB is mapped to the intermediate representation node N of the symbolic execution engine, and handle the mapping problems caused by different compiler optimization levels and binary relocations to ensure accuracy.
[0073] In a further embodiment, the process of differential-guided symbolic execution is as follows:
[0074] Based on the binary analysis test model, in the initial stage, new path branches are generated according to the conventional symbolic execution, and it is judged whether the new path branches contain difference markers. If the new path branches contain difference markers, the new path branches are inserted into the priority queue, and their constraints are preferentially solved; otherwise, they are put into the ordinary queue to complete the path priority scheduling;
[0075] After the path priority scheduling is completed, the number of branch nodes in the new path branches is obtained, the path states with similar or identical constraints are merged, and for the low-priority paths, merging or pruning is performed based on the threshold to obtain new paths and establish an optimized branch set Q. Vulnerability detection assertions are added at the call points of each branch path in the optimized branch set. When the vulnerability detection assertions meet the triggering conditions, the vulnerabilities are recorded and the execution of the branch path is terminated.
[0076] When performing path priority scheduling, a preset priority function quantifies the importance of the new path, and during symbolic execution, the new paths are selected for execution in descending order of priority. The formula of the priority function is as follows:
[0077]
[0078] In the formula: Q j represents the new path in symbolic execution; δ(Q j ) represents the difference awareness; κ(Q j ) represents the risk degree / vulnerability metric; c(Q j ) represents the cost or complexity of the path; ω1, ω2, ω3 are adjustable weights used to balance the influences among difference awareness, risk degree, and execution cost. In the scheduling queue, the priority function is calculated for the new paths, and the path with the largest Π value is preferentially selected for the next symbolic execution or constraint solving, and thus the scheduling can be completed through scheduling strategies from multiple perspectives such as difference priority and risk priority.
[0079] Differentiated symbolic execution is used to judge path merging and pruning, and a similarity function is defined to evaluate the overlapping degree of two paths in terms of constraints or states. The formula of the similarity function is as follows:
[0080]
[0081] In the formula: C(P xi ) represents the constraint set of path P xi ; the value range of S(P xi , P (x+1)i ) is in [0,1]; the closer the value is to 1, the more similar the constraint conditions of P xi and P (x+1)i are, and thus paths with high similarity are merged, which can significantly reduce the repeated solving of symbolic execution on similar paths.
[0082] When incremental execution is selected for differential incremental analysis after version iteration, the savings effect is quantified using the repeated analysis rate metric, and the formula for the repeated analysis rate is as follows:
[0083]
[0084] In the formula: bin x represents the set of paths explored during the analysis of the previous version; P x represents the set of all potential paths to be explored during the analysis of the new version; |bin x ∩P x | represents the number of overlapping paths between the new and old versions. That is, the closer the repeated analysis rate is to 1, the higher the similarity between the paths in the new version and the paths in the old version. By means of incremental execution, a large amount of full-scale repeated analysis can be significantly reduced.
[0085] When multiple objectives are selected for coverage of the differential area and vulnerabilities after version iteration, during execution, the target framework includes at least the total number of paths, analysis time, differential coverage rate, and vulnerability discovery rate. The formula (4) is used to calculate the maximization of the coverage of the differential area, vulnerabilities, and execution time. The formula (4) is as follows:
[0086]
[0087] In the formula: A represents the scheduling algorithm or "execution strategy" of symbolic execution; D(A) represents the differential coverage rate under this strategy; VulnFound(A) represents the number of vulnerabilities found or the vulnerability coverage rate in the test set; Time(A) represents the total analysis time or resource consumption under this strategy; α, β, and γ are adjustable parameters that comprehensively measure the balance between differential coverage, vulnerability discovery effect, and analysis cost, so as to maximize the coverage of the differential area and vulnerabilities while shortening the execution time.
[0088] The preferred embodiments of the present invention have been described in detail above. However, the present invention is not limited to the specific details in the above embodiments. Within the scope of the technical concept of the present invention, various equivalent transformations can be made to the technical solutions of the present invention, and these equivalent transformations all belong to the protection scope of the present invention.
Claims
1. A firmware vulnerability detection method based on differentiated symbolic execution, characterized in that: The following steps are involved: Get the firmware images of different configurations of the same device, and mark the firmware images as bin1, bin2, ..., bin according to the version number of the firmware image x Create an image set; Get the firmware images in the image set, use the firmware extraction tool to extract the executable binary files of the firmware images with different version numbers, locate the changed code fragments in the binary files, filter the differences that are not related to the target vulnerability type and generate a difference list. The process is as follows: First, obtain at least two binary files with different version numbers, and mark the binary programs in the binary files as P1, P2, ..., P x , where the binary program P1 contains a set of basic blocks B 1i , the binary program P2 contains a set of basic blocks B 2i , by calculating the basic block B 1i and basic block B 2i The hash value is used to identify the difference basic block ΔB, and the filter function F of the target vulnerability type is used to filter the difference basic block ΔB to the difference point ΔB. c ; Mark the difference points in the difference list as difference point 1, difference point 2, ..., difference point x After that, it is mapped to the symbolic execution engine, and the marked difference points are prioritized to establish a priority set according to the path priority preset in the symbolic execution engine; Add a difference perception module and dynamically adjust the path scheduling to the existing binary analysis framework to build a binary analysis test model, obtain the difference points in the priority sorting set, perform differential analysis to obtain differential analysis results, locate vulnerabilities based on the differential analysis results, generate vulnerability reports, and archive the branch paths of vulnerability scenarios or difference points; After completing the constraint set archiving, the authenticity and triggerability of the vulnerability are verified by whether the corresponding POC input or traffic can be automatically generated. When the corresponding POC input or traffic is automatically generated, the vulnerability is determined to be real and triggerable, otherwise it is not triggerable.
2. The firmware vulnerability detection method based on differentiated symbolic execution according to claim 1, characterized in that: In the process of filtering out differences that are irrelevant to the target vulnerability type, the basic block B is calculated by formula (1) 1i and basic block B 2i The hash value of , where formula (1) is as follows: Where: h represents the hash value; P x Represents the binary version number; i represents the index of the basic block; The difference basic block ΔB is identified based on the calculated hash value. Then the basic block B in version P2 2i The hash value of does not exist in version P1, indicating that the basic block is newly added or modified; Using the filter function F of the target vulnerability type, the identified difference basic blocks ΔB are filtered to the difference points ΔB c , and its calculation formula is as follows: ΔB c ={B∈ΔB|F(B)=True} (2)。 3. The firmware vulnerability detection method based on differentiated symbolic execution according to claim 2, characterized in that: After completing the screening of the difference points, the difference points are classified according to the type of the basic block, and a difference list is generated. The difference list at least includes the location, type and impact range of the difference points.
4. The firmware vulnerability detection method based on differentiated symbolic execution according to claim 2, characterized in that: The process of prioritizing differences is as follows: The basic blocks corresponding to the difference points are assigned high-level priority tags, and the weight of the high-level priority tags is adjusted as the priority weight according to the importance of the difference points, that is, the basic blocks corresponding to the difference points are assigned priority tags from high to low according to importance, secondary importance and universality; The basic blocks corresponding to the indifference points are assigned delay tags.
5. The firmware vulnerability detection method based on differentiated symbolic execution according to claim 4, characterized in that: The process of assigning priority to difference points is as follows: The corresponding path π of the basic block is pre-assigned a priority value Priority(π), based on whether the path π contains a difference point and the importance of the difference point And the pre-allocated priority value Priority(π) is calculated by formula (3): Where: represents the indicator function, when If it is a difference basic block, it is 1, otherwise it is 0; Representing difference basic blocks The importance weight of .
6. The firmware vulnerability detection method based on differentiated symbolic execution according to claim 4, characterized in that: The process of mapping the difference points to the symbolic execution engine is as follows: The position of the difference point in the binary is mapped to the corresponding node or basic block in the symbolic execution engine, and the binary analysis test model is used to perform difference-guided symbolic execution on the difference point. The process is as follows: Get the difference basic block Given a mapping relationship M, the corresponding node of each difference basic block in the symbolic execution engine is N i ,Right now The corresponding intermediate representation nodes are merged or processed to obtain the final intermediate representation node N, that is, M(ΔB)=N, that is, the difference basic block ΔB is mapped to the intermediate representation node N of the symbolic execution engine.
7. The firmware vulnerability detection method based on differentiated symbolic execution according to claim 6, characterized in that: The difference-guided symbolic execution process is as follows: Based on the binary analysis test model, in the initial stage, a new path branch is generated according to conventional symbolic execution, and a judgment is made as to whether the new path branch contains a difference mark. If the new path branch contains a difference mark, the new path branch is inserted into the priority queue and its constraints are solved first; Otherwise, it is placed in the normal queue to complete the path priority scheduling; After completing the path priority scheduling, obtain the number of branch nodes in the new path branch, merge the path states with similar or identical constraints, merge or prune the low-priority paths based on the threshold, obtain the new path and establish the optimized branch set Q, add a vulnerability detection assertion at the call of each branch path in the optimized branch set, and when the vulnerability detection assertion meets the trigger condition, record the vulnerability and terminate the execution of the branch path.
8. The firmware vulnerability detection method based on differentiated symbolic execution according to claim 7, characterized in that: In path priority scheduling, the preset priority function quantifies the importance of the new path, and in symbolic execution, the new path is selected for execution from the highest priority to the lowest priority. The priority function formula is as follows: P(Q j )=ω1·δ(Q j )+ω2·κ(Q j )-ω3·c(Q j ) Where: Q j represents a new path in symbolic execution; δ(Q j ) represents the difference perception; κ(Q j ) represents the risk / vulnerability measure; c(Q j ) represents the cost or complexity of the path; ω1, ω2, ω3 are adjustable weights used to balance the impact of difference perception, risk and execution cost; Differentiated symbolic execution is used to determine path merging and pruning, and a similarity function is defined to evaluate the degree of overlap between two paths in terms of constraints or states. The similarity function formula is as follows: Where: C(P x i) represents the path P x The constraint set of i; S(P x i,P (x+1) The value range of i) is [0,1]; the closer the value is to 1, the higher the P x i and P (x+1) The more similar the constraints of i are.
9. The firmware vulnerability detection method based on differentiated symbolic execution according to claim 7, characterized in that: When incremental analysis is performed on the differences after version iteration, the savings effect is quantified using the repeated analysis rate indicator, where the repeated analysis rate calculation formula is as follows: Where: bin x represents the set of paths explored during the analysis of the previous version; P x Represents the set of all potential paths to be explored when analyzing a new version; |bin x ∩P x |Indicates the number of overlaps between the new and old version paths.
10. The firmware vulnerability detection method based on differentiated symbolic execution according to claim 7, characterized in that: The coverage of the difference area and vulnerabilities after version iteration is carried out by using multiple objectives. During execution, the target framework includes at least the total number of paths, analysis time, difference coverage, and vulnerability discovery rate. The difference area, vulnerability coverage, and execution time of the maximized objective are calculated by formula (4). Formula (4) is as follows: Where A represents the scheduling algorithm or "execution strategy" of symbolic execution; D(Α) represents the difference coverage under this strategy; VulnFound(Α) represents the number of vulnerabilities found in the test set or the vulnerability coverage; Time(Α) represents the total analysis time or resource consumption of this strategy; α, β, γ are adjustable parameters that comprehensively measure the balance between difference coverage, vulnerability discovery effect, and analysis cost.
Citation Information
Patent Citations
Router firmware two-stage vulnerability automatic mining method based on GNN and angr
CN118797658A
Open-source vulnerability detection and impact assessments
US20240330484A1