Network equipment firmware vulnerability mining method based on large model

Through a large-model-based method, the network equipment firmware code is automatically analyzed and potential vulnerability patterns are identified, which solves the problems of low firmware vulnerability mining efficiency and limited coverage in the existing technology, and achieves efficient and comprehensive vulnerability mining effects.

CN119918064APending Publication Date: 2025-05-02BEIJING INST OF COMP TECH & APPL
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510162213.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-14
Publication Date
2025-05-02

AI Technical Summary

Technical Problem

The prior art has low efficiency, limited coverage and poor adaptability in network equipment firmware vulnerability mining, making it difficult to efficiently and comprehensively identify vulnerabilities in firmware.

Method used

Using a large-model-based method, we automatically analyze the firmware code to identify potential vulnerability patterns through firmware code preprocessing, large-model training and vulnerability pattern recognition.

Benefits of technology

It improves the efficiency and coverage of firmware vulnerability mining, adapts to firmware of different architectures and manufacturers, reduces manual intervention, and achieves efficient and comprehensive vulnerability mining.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader

Abstract

The invention relates to a network equipment firmware vulnerability mining method based on a large model, and belongs to the technical field of network security. According to the method, firmware codes are automatically analyzed and potential vulnerability modes are identified by utilizing the powerful learning ability of a large model, so that efficient and comprehensive firmware vulnerability mining is realized. The method has the characteristics of high efficiency, comprehensiveness and high universality, is suitable for various network equipment firmware, and has important theoretical significance and application value.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The invention belongs to the technical field of network security, and in particular relates to a network device firmware vulnerability mining method based on a large model. Background Art

[0002] Network device firmware is the core software of network devices, responsible for the startup, operation and management of the device. Since firmware usually runs at the bottom layer of the device and is updated infrequently, vulnerabilities in the firmware are often easily overlooked and become an important target for network attacks. Traditional firmware vulnerability mining methods mainly rely on technologies such as static analysis, dynamic analysis and fuzz testing. Although these methods are effective, they have the following problems:

[0003] Low efficiency: Traditional vulnerability mining methods require a lot of time and computing resources, and are difficult to cope with the analysis needs of large-scale firmware.

[0004] Limited coverage: Traditional methods have difficulty in fully covering all code paths in the firmware, resulting in low coverage of vulnerability mining.

[0005] Poor adaptability: Traditional methods are difficult to adapt to different architectures and firmware from different manufacturers, and lack universality.

[0006] With the successful application of large models (such as GPT, BERT, etc.) in the fields of natural language processing and code analysis, using large models for firmware vulnerability mining has become a new research direction. Large models can automatically identify potential vulnerability patterns by learning a large amount of code and vulnerability data, thereby improving the efficiency and coverage of vulnerability mining. Summary of the invention

[0007] 1. Technical issues to be resolved

[0008] The technical problem to be solved by the present invention is: how to use the powerful learning ability of the large model to automatically analyze the firmware code of network equipment and identify potential vulnerability patterns, thereby achieving efficient and comprehensive firmware vulnerability mining.

[0009] (II) Technical solution

[0010] In order to solve the above technical problems, the present invention provides a network device firmware vulnerability mining method based on a large model, comprising the following steps:

[0011] 1. Firmware code preprocessing

[0012] The firmware code preprocessing module is responsible for preprocessing the network device firmware, extracting the code and data in the firmware, and converting it into a format suitable for large model input. The specific steps are as follows:

[0013] 1.1 Firmware Extraction

[0014] Firmware source: Obtain the firmware binary file through the firmware update package of the network device or directly extract the firmware image. The firmware source can include network devices such as routers, switches, and firewalls.

[0015] Firmware extraction tool: Use a firmware extraction tool such as Binwalk, Firmware Mod Kit, etc. to extract the firmware binary from the device.

[0016] 1.2 Decompilation

[0017] Decompilation tools: Use decompilation tools (such as IDAPro, Ghidra, etc.) to decompile the firmware binary file into assembly code or high-level language code (such as C language).

[0018] Decompilation process:

[0019] 1. Load the firmware binary file into the decompilation tool;

[0020] 2. Identify the code and data segments in the firmware;

[0021] 3. Decompile binary code into assembly code or high-level language code.

[0022] 1.3 Code Cleaning

[0023] Cleaning goal: Remove irrelevant information in the decompiled code, such as comments, debugging information, unused code, etc., and retain key code fragments.

[0024] Cleaning process:

[0025] 1. Use regular expressions or static analysis tools to identify and remove comments and debugging information;

[0026] 2. Identify unused code snippets through code analysis tools and remove them;

[0027] 3. Keep key code snippets related to the vulnerability, such as function calls, memory operations, input and output processing, etc.

[0028] 1.4 Code Vectorization

[0029] Vectorization method: Convert the cleaned code into vector representation to facilitate large model processing. Commonly used vectorization methods include word embedding and code embedding.

[0030] Vectorization process:

[0031] 1. Segment the functions, variables, operators and other elements in the code;

[0032] 2. Use pre-trained word embedding models (such as Word2Vec, FastText) to convert the code elements after word segmentation into vectors;

[0033] 3. Represent code snippets as vector sequences as input to the large model.

[0034] 2. Large model training

[0035] The large model training module is responsible for using the large model to train the firmware code and learn the vulnerability patterns in the firmware code. The specific steps are as follows:

[0036] 2.1 Dataset Construction

[0037] Data source: Build a dataset containing a large amount of firmware code and vulnerability labels. Data sources can include public vulnerability databases (such as CVE), open source firmware projects, self-collected firmware samples, etc.

[0038] Data annotation: Annotate the code snippets in the dataset to mark the known vulnerability locations and types (such as buffer overflow, integer overflow, format string vulnerability, etc.).

[0039] 2.2 Model selection

[0040] Model type: Choose a large model suitable for code analysis, such as GPT, BERT, etc. These models can process the contextual information of the code and identify potential vulnerability patterns.

[0041] Pre-trained model: Use pre-trained large models (such as CodeBERT, GPT-3) as the base model and fine-tune it to adapt to the analysis task of firmware code.

[0042] 2.3 Model Training

[0043] Training process:

[0044] 1. Input the vectorized firmware code into the big model;

[0045] 2. Use the labeled dataset to train a large model to identify vulnerability patterns in firmware code;

[0046] 3. Use transfer learning technology to fine-tune the pre-trained large model to improve training efficiency.

[0047] Training goal: Through training, the large model can automatically identify potential vulnerabilities in firmware code and output the location and type of the vulnerability.

[0048] 3. Vulnerability pattern recognition

[0049] The vulnerability pattern recognition module is responsible for analyzing the firmware code using the trained large model to identify potential vulnerability patterns. The specific steps are as follows:

[0050] 3.1 Code Input

[0051] Input format: Input the preprocessed firmware code (vectorized representation) into the large model;

[0052] Input processing: The large model processes the input code vector and extracts the contextual information and semantic features of the code.

[0053] 3.2 Vulnerability Detection

[0054] Vulnerability pattern recognition: The large model automatically identifies potential vulnerabilities in the firmware code based on the learned vulnerability patterns. For example, it can identify buffer overflows, integer overflows, format string vulnerabilities, etc.

[0055] Vulnerability classification: The large model outputs the type and severity of the vulnerability for further analysis and processing.

[0056] 3.3 Vulnerability Location

[0057] Vulnerability location output: The large model outputs the specific location of the vulnerability in the firmware code (such as function name, code line number, etc.).

[0058] Vulnerability context information: The big model provides context information of the vulnerability, helping analysts understand the cause and scope of the vulnerability.

[0059] 4. Vulnerability verification and repair

[0060] The vulnerability verification and repair module is responsible for verifying the identified vulnerabilities and generating repair suggestions. The specific steps are as follows:

[0061] 4.1 Vulnerability Verification

[0062] Dynamic analysis: Use dynamic analysis techniques (such as symbolic execution and fuzz testing) to verify whether the vulnerabilities identified by the large model actually exist. If so, reproduce the vulnerabilities, otherwise end the process.

[0063] Vulnerability Reproduction: Reproduce the vulnerability in a simulated environment to confirm its exploitability and impact scope.

[0064] 4.2 Repair suggestion generation

[0065] Remediation strategy: Generate remediation suggestions based on the type and location of the vulnerability. For example:

[0066] For buffer overflow vulnerabilities, it is recommended to increase input validation or fix the buffer size.

[0067] For integer overflow vulnerabilities, it is recommended to add bounds checks or use a safe math library.

[0068] Fix suggestion output: The fix suggestion is output as a detailed report, including vulnerability description, fix method and code example.

[0069] 4.3 Repair implementation

[0070] Repair code generation: Generate repaired code snippets based on repair suggestions;

[0071] Fix verification: Verify whether the fixed code eliminates the vulnerability through dynamic analysis or fuzz testing;

[0072] Firmware update: Apply the repaired code to the firmware, generate a repaired firmware version, and publish and deploy it.

[0073] The present invention also provides a system for implementing the method.

[0074] The invention also provides a network security method implemented based on the method.

[0075] (III) Beneficial effects

[0076] The present invention has the following advantages:

[0077] 1. Large model application: Utilize the powerful learning ability of large models to automatically analyze firmware code, identify potential vulnerability patterns, and improve the efficiency and coverage of vulnerability mining.

[0078] 2. Automated process: Through automated firmware code preprocessing, large model training and vulnerability identification processes, manual intervention is reduced and the efficiency of vulnerability mining is improved.

[0079] 3. Strong versatility: The large model can adapt to different architectures and firmware from different manufacturers, and has strong versatility. DETAILED DESCRIPTION

[0080] In order to make the purpose, content and advantages of the present invention more clear, the specific implementation methods of the present invention are further described in detail below in conjunction with embodiments.

[0081] The present invention provides a network device firmware vulnerability mining system and method based on a large model (such as GPT, BERT, etc.), which automatically analyzes firmware code and identifies potential vulnerability patterns by utilizing the powerful learning ability of the large model, thereby achieving efficient and comprehensive firmware vulnerability mining. The present invention is efficient, comprehensive, and highly versatile, and is applicable to various network device firmwares, and has important theoretical significance and application value.

[0082] Assuming that there is a buffer overflow vulnerability in the firmware of the target network device, this embodiment can exploit the vulnerability through the following steps:

[0083] 1. Firmware extraction: Extract the firmware binary from the target network device.

[0084] 2. Decompile: Use a decompilation tool to decompile the firmware binary file into C language code.

[0085] 3. Code cleaning: Clean the decompiled C language code and remove irrelevant code and comments.

[0086] 4. Code vectorization: Convert the cleaned C language code into vector representation.

[0087] 5. Large model training: Use a large model to train the firmware code and learn the patterns of buffer overflow vulnerabilities.

[0088] 6. Vulnerability identification: Use the trained large model to analyze the firmware code and identify potential buffer overflow vulnerabilities.

[0089] 7. Vulnerability verification and repair: Verify the authenticity of the buffer overflow vulnerability through dynamic analysis and generate repair suggestions (such as adding input verification).

[0090] 1. System architecture

[0091] The system architecture of this embodiment includes the following seven main modules:

[0092] 1. Firmware extraction module:

[0093] o Responsible for extracting firmware binaries from network devices.

[0094] o Use a firmware extraction tool such as Binwalk to extract the firmware image from the device.

[0095] 2. Decompile module:

[0096] o Responsible for decompiling firmware binary files into assembly code or high-level language code (such as C language).

[0097] o Use decompilation tools (such as IDAPro, Ghidra) for decompilation.

[0098] 3. Code cleaning module:

[0099] o Responsible for cleaning the decompiled code and removing irrelevant code and comments.

[0100] o Use regular expressions and static analysis tools to remove comments, debug information, and unused code.

[0101] 4. Code vectorization module:

[0102] o Responsible for converting the cleaned code into vector representation for easy processing of large models.

[0103] o Use word embedding techniques such as Word2Vec to convert functions, variables, and operators in your code into vectors.

[0104] 5. Large model training module:

[0105] o Responsible for using large models to train firmware code and learn vulnerability patterns.

[0106] o Use a pre-trained large model such as CodeBERT for fine-tuning.

[0107] 6. Vulnerability identification module:

[0108] o Responsible for using the trained large model to analyze the firmware code and identify potential vulnerabilities.

[0109] o Outputs the location, type, and context information of the vulnerability.

[0110] 7. Vulnerability verification and repair module:

[0111] o Responsible for validating identified vulnerabilities and generating remediation recommendations.

[0112] o Use dynamic analysis techniques such as fuzz testing to verify vulnerabilities and generate fixed code.

[0113] 2. Method flow

[0114] The method flow of this embodiment is as follows:

[0115] 1. Firmware extraction:

[0116] o Extract firmware binaries from target network devices.

[0117] o For example, use Binwalk to extract the firmware image from your router.

[0118] 2. Decompile:

[0119] oUse a decompilation tool to decompile the firmware binary file into C language code.

[0120] o For example, use IDA Pro to decompile the firmware binary into C code.

[0121] 3. Code cleaning:

[0122] o Clean the decompiled C language code and remove irrelevant code and comments.

[0123] o For example, use regular expressions to strip comments and debug information.

[0124] 4. Code vectorization:

[0125] o Convert the cleaned C code into vector representation.

[0126] o For example, use Word2Vec to convert functions, variables, and operators in your code into vectors.

[0127] 5. Large model training:

[0128] o Use large models to train firmware code and learn vulnerability patterns.

[0129] o For example, CodeBERT is used to fine-tune firmware code to learn patterns for buffer overflow vulnerabilities.

[0130] 6. Vulnerability identification:

[0131] o Use the trained large model to analyze the firmware code and identify potential vulnerabilities.

[0132] o For example, a buffer overflow vulnerability in firmware code is identified and the location and type of vulnerability are output.

[0133] 7. Vulnerability verification and repair:

[0134] o Verify the authenticity of the vulnerability through dynamic analysis and generate repair suggestions.

[0135] o For example, fuzz testing can be used to detect buffer overflow vulnerabilities and generate fixes (such as adding input validation).

[0136] 3. Specific Examples

[0137] Assuming that there is a buffer overflow vulnerability in the firmware of the target network device, this embodiment can exploit the vulnerability through the following steps:

[0138] 1. Firmware extraction:

[0139] o Extract the firmware binary from the target router.

[0140] o For example, use Binwalk to extract the firmware image firmware.bin.

[0141] 2. Decompile:

[0142] o Use IDAPro to decompile the firmware binary file into C language code.

[0143] o For example, after decompilation, the C language code file firmware.c is obtained.

[0144] 3. Code cleaning:

[0145] o Clean the decompiled C language code and remove irrelevant code and comments.

[0146] o For example, remove comments and debugging information and keep key code snippets.

[0147] 4. Code vectorization:

[0148] o Convert the cleaned C code into vector representation.

[0149] o For example, use Word2Vec to convert functions, variables, and operators in your code into vectors.

[0150] 5. Large model training:

[0151] o The firmware code is trained using CodeBERT to learn patterns of buffer overflow vulnerabilities.

[0152] o For example, fine-tuning a code snippet containing a buffer overflow vulnerability.

[0153] 6. Vulnerability identification:

[0154] o Use the trained large model to analyze the firmware code and identify potential buffer overflow vulnerabilities.

[0155] oFor example, it identifies a buffer overflow vulnerability in the strcpy function call in the firmware code and outputs the location and type of the vulnerability.

[0156] 7. Vulnerability verification and repair:

[0157] o Verify the authenticity of the buffer overflow vulnerability through fuzz testing.

[0158] o For example, use AFL (American Fuzzy Lop) to perform fuzz testing to confirm the exploitability of the vulnerability.

[0159] o Generates fix suggestions, such as replacing strcpy with strncpy and adding input validation.

[0160] 4. Results Analysis

[0161] Through the above examples, the present invention demonstrates how to use the powerful learning ability of large models to automatically analyze firmware codes and identify potential vulnerability patterns, thereby achieving efficient and comprehensive firmware vulnerability mining. The specific results are as follows:

[0162] 1. Efficiency: Through the automated analysis of large models, the efficiency of firmware vulnerability mining is greatly improved.

[0163] 2. Comprehensiveness: Large models can fully cover the code paths in the firmware and improve the coverage of vulnerability mining.

[0164] 3. Versatility: The large model can adapt to different architectures and firmware from different manufacturers and has strong versatility.

[0165] It can be seen that the present invention has the following advantages:

[0166] 1. Efficiency: Through the automated analysis of large models, the efficiency of firmware vulnerability mining is greatly improved;

[0167] 2. Comprehensiveness: The large model can fully cover the code paths in the firmware, improving the coverage of vulnerability mining;

[0168] 3. Versatility: The large model can adapt to different architectures and firmware from different manufacturers and has strong versatility.

[0169] The above is only a preferred embodiment of the present invention. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the technical principles of the present invention. These improvements and modifications should also be regarded as the scope of protection of the present invention.

Claims

1. A network device firmware vulnerability mining method based on a large model, characterized in that: The following steps are involved: Step 1. Firmware code preprocessing Preprocess the network device firmware, extract the code in the firmware, and convert it into a format suitable for large model input; The specific steps of step 1 are as follows: 1.1 Firmware Extraction Extract firmware binaries from network devices using firmware extraction tools; 1.2 Decompilation Decompile the firmware binary file into assembly code or high-level language code using a decompilation tool; the specific decompilation process includes: loading the firmware binary file into the decompilation tool; identifying the code segment and data segment in the firmware; decompiling the binary code into assembly code or high-level language code; 1.3 Code Cleaning Remove irrelevant information from the decompiled code and retain key code snippets. The specific cleaning process includes: using regular expressions or static analysis tools to identify and remove comments and debugging information; using code analysis tools to identify unused code snippets and remove them; retaining key code snippets related to vulnerabilities; 1.4 Code Vectorization The cleaned code is converted into vector representation. The vectorization methods include word embedding and code embedding. The vectorization process includes: word segmentation of functions, variables, and operators in the code; using a pre-trained word embedding model to convert the word segmented code elements into vectors; representing the code snippets as vector sequences as input to the large model; Step 2. Large model training Use the big model to train the firmware code and learn the vulnerability patterns in the firmware code. The specific steps are as follows: 2.1 Dataset Construction Build a dataset containing a large amount of firmware code and vulnerability labels; annotate the code snippets in the dataset and mark the known vulnerability locations and types; 2.2 Model selection Choose a large model suitable for code analysis. The selected large model can process the contextual information of the code and identify potential vulnerability patterns. 2.3 Model Training Input the vectorized firmware code into the big model; use the labeled data set to train the big model so that it can identify vulnerability patterns in the firmware code; use transfer learning technology to fine-tune the pre-trained big model; through training, the big model can automatically identify potential vulnerabilities in the firmware code and output the location and type of the vulnerability; Step 3. Vulnerability pattern identification Use the trained large model to analyze the firmware code and identify potential vulnerability patterns. The specific steps are as follows: 3.1 Code Input The preprocessed firmware code is input into the large model; the large model processes the input code vector and extracts the context information and semantic features of the code; 3.2 Vulnerability Detection Vulnerability pattern recognition: The large model automatically identifies potential vulnerabilities in the firmware code based on the learned vulnerability patterns; Vulnerability classification: The type and severity of the vulnerability output by the large model; 3.3 Vulnerability Location Vulnerability location output: The large model outputs the specific location of the vulnerability in the firmware code; Vulnerability context information: The big model provides context information about the vulnerability to help analysts understand the cause and scope of the vulnerability. Step 4. Vulnerability verification and repair Verify the identified vulnerabilities and generate repair suggestions. The specific steps are as follows: 4.1 Vulnerability Verification Dynamic analysis: Use dynamic analysis technology to verify whether the vulnerability identified by the large model really exists. If so, reproduce the vulnerability, otherwise end; Vulnerability Reproduction: Reproduce the vulnerability in a simulated environment to confirm its exploitability and impact scope; 4.2 Repair suggestion generation Repair strategy: Generate repair suggestions based on the type and location of the vulnerability. For buffer overflow vulnerabilities, it is recommended to increase input validation or repair the buffer size; for integer overflow vulnerabilities, it is recommended to increase boundary checks or use a safe math library. Fix suggestion output: The fix suggestion is output as a detailed report. The information in the report includes vulnerability description, fix method and code example. 4.3 Repair implementation Repair code generation: Generate repaired code snippets based on repair suggestions; Fix verification: Verify whether the fixed code eliminates the vulnerability through dynamic analysis or fuzz testing; Firmware update: Apply the repaired code to the firmware, generate a repaired firmware version, and publish and deploy it.

2. The method according to claim 1, characterized in that In step 1.1, obtain the firmware binary file through the network device's firmware update package or directly extract the firmware image.

3. The method according to claim 1, characterized in that Firmware sources include network devices such as routers, switches, and firewalls.

4. The method according to claim 1, characterized in that Firmware extraction tools include Binwalk and Firmware ModKit.

5. The method according to claim 1, characterized in that Decompilation tools include IDA Pro and Ghidra.

6. The method according to claim 1, characterized in that Pre-trained word embedding models include Word2Vec and FastText.

7. The method according to claim 1, characterized in that Data sources include public vulnerability databases, open source firmware projects, and self-collected firmware samples.

8. The method according to claim 1, characterized in that Dynamic analysis techniques include symbolic execution and fuzz testing.

9. A system for implementing the method according to any one of claims 1 to 8.

10. A network security method implemented based on the method according to any one of claims 1 to 8.

Citation Information

Cited By

  • Vulnerability mining method based on large model

    CN120408649A