Buffer overflow vulnerability static detection method and system supporting incomplete codes
By performing enhanced operations and heuristic analysis of the abstract syntax tree of incomplete code, an extended value flow graph is generated and function summary matching and constraint generation is solved, and the problem of buffer overflow vulnerability detection is improved in the case of incomplete code.
Patent Information
- Application Number
- CN202411717623.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-27
- Publication Date
- 2025-05-06
AI Technical Summary
The prior art is difficult to effectively detect buffer overflow vulnerabilities in the case of incomplete code, resulting in a reduced detection accuracy.
Enhanced operations through the abstract syntax tree of the detection code, including heuristic compiler matching, heuristic header file retrieval, heuristic macro replacement, and heuristic binding construction, generate extended value flow graphs, and heuristic function summary matching and constraint generation to identify possible buffer overflow vulnerabilities.
It realizes effective detection of buffer overflow vulnerabilities in the case of incomplete code, improves detection accuracy, and makes up for the missing compiled information.
Smart Images

Figure CN119939579A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer technology, and in particular to a static detection method and system for buffer overflow vulnerabilities supporting incomplete codes. Background Art
[0002] A buffer is a contiguous storage space reserved in the stack. When a program tries to put more data into a buffer and the data exceeds the reserved range of the buffer or when a program tries to put data into a memory location that exceeds the boundary of the buffer, a buffer overflow occurs. Buffer overflow vulnerabilities can lead to a variety of serious security issues, including code execution, information leakage, program crashes, and privilege escalation.
[0003] Buffer overflow static detection tools are widely used in software development and testing. In order to maintain the accuracy of the analysis, compilation is a prerequisite for most static analysis tools. However, in the actual detection process, the code being tested is often incomplete, making the program unable to compile.
[0004] Therefore, how to detect buffer overflow vulnerabilities when the code is incomplete has become a technical problem that needs to be solved urgently in the industry. Summary of the invention
[0005] The present invention provides a buffer overflow vulnerability static detection method and system supporting incomplete codes, which are used to solve the technical problem of how to detect buffer overflow vulnerabilities when the codes are incomplete.
[0006] The present invention provides a static detection method for buffer overflow vulnerabilities supporting incomplete codes, comprising: Performing an enhancement operation on an abstract syntax tree corresponding to the code to be detected to determine an enhanced abstract syntax tree corresponding to the code to be detected; the code to be detected is an incomplete code; the enhancement operation includes heuristic compiler matching, heuristic header file retrieval, heuristic macro replacement and heuristic binding construction; Based on the enhanced abstract syntax tree, determining the extended value flow graph corresponding to the code to be detected, and performing heuristic function summary matching on the functions in the code to be detected; Traversing each node in the extended value flow graph to determine a vulnerable node corresponding to the code to be detected; the vulnerable node is a node where a buffer overflow vulnerability may occur; Heuristic constraint conditions are generated for the vulnerable nodes, and based on the solution results of the constraint conditions, the buffer overflow vulnerability detection results of the code to be detected are determined; the constraint conditions are used to ensure that the vulnerable nodes do not have buffer overflows.
[0007] In some embodiments, the heuristic compiler matching includes: In the case that there is no configuration file for the code to be detected or the compilation library cannot be determined based on the configuration file of the code to be detected, searching the code to be detected to obtain a header file set in the code to be detected; Matching each header file in the header file set with a proprietary header file in each preset compiled library to determine the matching number of header files in each preset compiled library; Determine the similarity between each preset compiled library and the compiled library of the code to be detected based on the number of header file matches of each preset compiled library and the number of files in the header file set; The preset compilation library corresponding to the highest similarity is determined as the compilation library of the code to be detected, and the compiler corresponding to the code to be detected is determined.
[0008] In some embodiments, the heuristic header file retrieval includes: Determine the current file being analyzed; Determine, in the compiled library of the code to be detected, a plurality of candidate header files corresponding to the currently analyzed file; Determine the distance between the path string of each candidate header file and the path string of the currently analyzed file; The candidate header file corresponding to the minimum distance is determined as the header file included in the currently analyzed file.
[0009] In some embodiments, the heuristic macro replacement includes: Determine the macro definition of the code to be detected based on the configuration file of the code to be detected; Determine a default macro definition list of the compiler corresponding to the code to be detected; Based on the default macro definition list, the macro definition of the code to be detected is replaced.
[0010] In some embodiments, the heuristic binding construction includes: Determine a current statement in the code to be detected; the current statement is a function call statement or a variable declaration statement; Traversing the abstract syntax tree corresponding to the code to be detected to determine candidate expression statements and / or candidate declaration statements corresponding to the current statement; If both the candidate expression statement and the candidate declaration statement exist, the numbers of incorrect bindings of the candidate expression statement and the candidate declaration statement are both zero, and the candidate expression statement is a binary expression, binding the candidate declaration statement with the current statement; When both the candidate expression statement and the candidate declaration statement exist, the number of incorrect bindings of the candidate expression statement and the candidate declaration statement are both zero, and the candidate expression statement is a function call expression, the candidate expression statement is bound to the current statement.
[0011] In some embodiments, the heuristic function digest matching includes: Determine the distance between the function name in the current statement and the function name in the compiled library of the code to be detected; The function summary corresponding to the function name corresponding to the minimum distance is determined as the function summary of the current statement.
[0012] In some embodiments, the heuristic constraint generation includes: Determine a function call statement corresponding to the vulnerable node; Based on the function summary of the function call statement, a constraint condition of the vulnerable node is generated.
[0013] The present invention provides a buffer overflow vulnerability static detection system supporting incomplete code, comprising: A preprocessing unit, configured to perform an enhancement operation on an abstract syntax tree corresponding to a code to be detected, and determine an enhanced abstract syntax tree corresponding to the code to be detected; the code to be detected is an incomplete code; the enhancement operation includes heuristic compiler matching, heuristic header file retrieval, heuristic macro replacement, and heuristic binding construction; A basic analysis unit, configured to determine an extended value flow graph corresponding to the code to be detected based on the enhanced abstract syntax tree, and perform heuristic function summary matching on functions in the code to be detected; A vulnerable node generation unit, used to traverse each node in the extended value flow graph to determine the vulnerable node corresponding to the code to be detected; the vulnerable node is a node where a buffer overflow vulnerability may occur; The constraint condition solving unit is used to generate heuristic constraint conditions for the vulnerable node, and determine the buffer overflow vulnerability detection result of the code to be detected based on the constraint condition solving result; the constraint condition is used to ensure that the vulnerable node does not have a buffer overflow.
[0014] The present invention provides an electronic device, comprising a memory, a processor and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the static detection method for buffer overflow vulnerabilities supporting incomplete codes is implemented.
[0015] The present invention provides a non-transitory computer-readable storage medium on which a computer program is stored. When the computer program is executed by a processor, the static detection method for buffer overflow vulnerabilities supporting incomplete codes is implemented.
[0016] The present invention provides a static detection method and system for buffer overflow vulnerabilities supporting incomplete codes. When the code to be detected is incomplete, an abstract syntax tree corresponding to the code to be detected is enhanced to determine the enhanced abstract syntax tree corresponding to the code to be detected; based on the enhanced abstract syntax tree, an extended value flow graph corresponding to the code to be detected is determined, and a heuristic function summary matching is performed on the function in the code to be detected; each node in the extended value flow graph is traversed to determine the vulnerable node corresponding to the code to be detected; heuristic constraint conditions are generated for the vulnerable nodes, and a buffer overflow vulnerability detection result of the code to be detected is determined based on the solution result of the constraint conditions; since compilation is not required, the buffer overflow vulnerability is detected in the case of incomplete code; since multiple heuristic strategies such as enhanced operation (including heuristic compiler matching, heuristic header file retrieval, heuristic macro replacement and heuristic binding construction), heuristic function summary matching and heuristic constraint condition generation are adopted in the program parsing, code analysis and defect detection stages to make up for the missing compilation information as much as possible, thereby improving the detection accuracy of the buffer overflow vulnerability. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the invention and, together with the description, serve to explain the principles of the invention.
[0018] In order to more clearly illustrate the technical solutions in the present invention or the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.
[0019] Figure 1 It is a flow chart of a static detection method for buffer overflow vulnerabilities supporting incomplete codes provided by the present invention.
[0020] Figure 2 It is a schematic diagram of the flow chart of the heuristic compiler matching provided by the present invention.
[0021] Figure 3 It is a schematic diagram of the flow of the heuristic header file retrieval provided by the present invention.
[0022] Figure 4 It is a schematic diagram of the process of heuristic binding construction provided by the present invention.
[0023] Figure 5 It is a schematic diagram of the flow of heuristic function summary matching provided by the present invention.
[0024] Figure 6 It is a schematic diagram of the technical architecture of the static detection method for buffer overflow vulnerabilities supporting incomplete codes provided by the present invention.
[0025] Figure 7 It is a structural schematic diagram of a static detection system for buffer overflow vulnerabilities supporting incomplete codes provided by the present invention.
[0026] Figure 8 It is a structural schematic diagram of the electronic device provided by the present invention. DETAILED DESCRIPTION
[0027] In order to enable people in the field of the present invention to better understand the scheme of the present invention, the technical scheme in the embodiment of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiment of the present invention. Obviously, the described embodiment is only a part of the embodiment of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative work should fall within the scope of protection of the present invention.
[0028] It should be noted that the terms "first", "second", etc. in the present invention are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged where appropriate, so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device that includes a series of steps or units or modules is not necessarily limited to those steps or units or modules that are clearly listed, but may include other steps or units or modules that are not clearly listed or inherent to these processes, methods, products or devices.
[0029] A buffer overflow vulnerability is a common computer security vulnerability that usually occurs when a program attempts to write too much data into a fixed-size memory area (buffer).
[0030] The analysis and defense of buffer overflow vulnerabilities have always been a hot and difficult issue in information security research. Buffer overflow vulnerabilities can be detected through static analysis methods. Static analysis refers to the analysis process performed without running the software. The object of static analysis is generally the program source code or the target code. Compared with the defense method during program runtime, the static analysis method has the advantages of discovering vulnerabilities early, providing more detailed vulnerability information, and being able to detect and eliminate vulnerabilities fundamentally.
[0031] In order to maintain the accuracy of the analysis, compilation is a prerequisite for most static analysis tools. By tracking the compilation process, static analysis tools can obtain information about the program build, such as the exact location of each header file included in each source file. However, a considerable portion of the program code is incomplete, such as the lack of necessary dependent packages or dependent files, and cannot be compiled, so it is impossible to detect buffer overflow vulnerabilities.
[0032] In order to solve the shortcomings of related technologies, Figure 1 FIG. 1 is a flow chart of a static detection method for buffer overflow vulnerabilities supporting incomplete codes provided by the present invention. Figure 1 As shown, the method includes step 110 , step 120 , step 130 and step 140 .
[0033] Step 110, performing an enhancement operation on the abstract syntax tree corresponding to the code to be detected to determine an enhanced abstract syntax tree corresponding to the code to be detected; the code to be detected is an incomplete code; the enhancement operation includes heuristic compiler matching, heuristic header file retrieval, heuristic macro replacement and heuristic binding construction.
[0034] Specifically, the execution subject of the static detection method for buffer overflow vulnerabilities supporting incomplete codes provided by the embodiment of the present invention is a static detection system for buffer overflow vulnerabilities. The system can be implemented by software, such as a static detection program for buffer overflow vulnerabilities; or by hardware, such as a computer or server that executes the static detection method for buffer overflow vulnerabilities.
[0035] The application scenario of the static detection method for buffer overflow vulnerability provided by the embodiment of the present invention is to statically detect buffer overflow vulnerability that may exist in the code to be detected. The code to be detected can be a program source code written in C language or C++ language.
[0036] The code to be tested is incomplete, for example, it can be a program source code that lacks a compilation library or header file. The Abstract Syntax Tree (AST) is a tree representation of the source code of a programming language. Each node on the tree represents a structure of the source code. The CDT (C / C++ Development Tooling) framework of the Eclipse development platform can be used to perform lexical analysis and syntax analysis on the code to be tested. This framework can successfully generate an abstract syntax tree even if the C / C++ program fails to compile.
[0037] A series of enhancement operations can be performed on the abstract syntax tree, including heuristic compiler matching, heuristic header file retrieval, heuristic macro replacement and heuristic binding construction, to obtain an enhanced abstract syntax tree, and in the process obtain file missing information of the code to be detected.
[0038] Heuristic compiler matching refers to the operation of determining the compiler library and compiler after matching the header files in the code to be detected with the header files in the preset compiler library. Heuristic header file retrieval refers to the operation of searching and matching the header files in the code to be detected based on the path string. Heuristic macro replacement refers to the operation of replacing the macro definitions in the code to be detected based on the compiler's default macro definition list.
[0039] In the syntax and semantic analysis of programming languages, binding refers to the process of connecting symbols (such as functions, variables, types, etc.) with their actual implementations or values. In the embodiments of the present invention, binding refers to the connection from the use location of a variable / function to the declaration location. Heuristic binding construction refers to the operation of connecting the call statements of a variable / function according to expression statements and / or declaration statements.
[0040] Step 120: Based on the enhanced abstract syntax tree, determine the extended value flow graph corresponding to the code to be detected, and perform heuristic function summary matching on the functions in the code to be detected.
[0041] Specifically, the Value Flow Graph (VFG) is a directed graph that reflects the flow relationship of the values of variables in the program (to distinguish it from the extended value flow graph, it can also be called a traditional value flow graph). Value flow analysis integrates control flow analysis, fixed value usage in data flow analysis, and function call relationship analysis to construct a value flow graph. Each value flow subgraph expresses the life cycle of a variable before its value changes. Each node in the value flow graph is determined according to each statement in the program.
[0042] There is only one kind of dependency between points in the value flow graph: flow dependency. The value flow graph cannot fully reflect the program semantic information. In order to solve the problem that the value flow graph does not fully express the dependency between variables, the value flow graph is expanded to expand one dependency into four (including entry dependency, flow dependency, pointer dereference dependency and address dependency), thus obtaining an extended value flow graph (also called value dependency graph).
[0043] According to the enhanced abstract syntax tree, the program code is analyzed for control flow, function call relationship, data flow, and value flow, and the corresponding control flow graph, function call graph, definition use chain, and value flow graph are generated. The value flow graph with only one dependency is expanded to generate an extended value flow graph with four dependencies.
[0044] A function summary is a concise description of a function's function, input, output, and behavior. It is usually used in a function's documentation comments to help quickly understand and use the function. If the function call in the code to be detected has not been parsed out of its corresponding definition declaration, and the corresponding summary cannot be searched in the function summary library, a heuristic function summary match can be performed on the function in the code to be detected.
[0045] Heuristic function summary matching refers to the operation of matching the functions in the code to be detected and the functions in the compiled library according to the function names to determine the function summary.
[0046] Step 130, traverse each node in the extended value flow graph to determine the vulnerable node corresponding to the code to be detected; the vulnerable node is a node where a buffer overflow vulnerability may occur.
[0047] Specifically, a vulnerable node refers to a node where a buffer overflow vulnerability may occur, and corresponding to the code to be detected, it may be a statement or structure where a buffer overflow vulnerability may occur.
[0048] By traversing each node in the extended value flow graph, the vulnerability node corresponding to the code to be detected can be screened out.
[0049] Step 140: Generate heuristic constraint conditions for the vulnerable nodes, and determine the buffer overflow vulnerability detection results of the code to be detected based on the solution results of the constraint conditions; the constraint conditions are used to ensure that the vulnerable nodes do not have buffer overflows.
[0050] Specifically, the constraint condition may include a constraint condition related to the value range information of the variable and a constraint condition related to the alias information of the pointer. The constraint condition may generally be expressed as a constraint expression. The constraint expression may be solved. If the constraint condition is satisfied, it may be determined that the vulnerable node is a node where buffer overflow does not occur; if the constraint condition is not satisfied, it may be determined that the vulnerable node is a node where buffer overflow occurs.
[0051] When the vulnerable node is a node where a buffer overflow occurs, the buffer overflow vulnerability detection result of the code to be detected can be determined as the existence of a vulnerability, and information such as the location of the buffer overflow vulnerability can be determined based on the location of the vulnerable node.
[0052] For vulnerable nodes corresponding to function call statements whose function binding cannot be determined, heuristic constraint generation can be used to obtain constraint conditions. Heuristic constraint generation refers to the operation of analyzing the function summary to determine the constraint conditions.
[0053] The embodiment of the present invention provides a static detection method for buffer overflow vulnerabilities supporting incomplete codes. When the code to be detected is incomplete, an abstract syntax tree corresponding to the code to be detected is enhanced to determine the enhanced abstract syntax tree corresponding to the code to be detected; based on the enhanced abstract syntax tree, an extended value flow graph corresponding to the code to be detected is determined, and a heuristic function summary matching is performed on the function in the code to be detected; each node in the extended value flow graph is traversed to determine the vulnerable node corresponding to the code to be detected; heuristic constraint conditions are generated for the vulnerable nodes, and a buffer overflow vulnerability detection result of the code to be detected is determined based on the solution result of the constraint conditions; since compilation is not required, the buffer overflow vulnerability is detected in the case of incomplete code; since multiple heuristic strategies such as enhanced operations (including heuristic compiler matching, heuristic header file retrieval, heuristic macro replacement and heuristic binding construction), heuristic function summary matching and heuristic constraint condition generation are adopted in the program parsing, code analysis and defect detection stages to make up for the missing compilation information as much as possible, thereby improving the detection accuracy of buffer overflow vulnerabilities.
[0054] It should be noted that each implementation of the present invention can be freely combined, the order can be changed, or it can be executed separately, and does not need to rely on or depend on a fixed execution order.
[0055] In some embodiments, traversing each node in the extended value flow graph to determine the vulnerability node corresponding to the code to be detected includes: In order to better describe the C language buffer vulnerability, the embodiment of the present invention abstracts the C language buffer overflow vulnerability, proposes a C language buffer overflow vulnerability model, and uses a quadruple method to represent the vulnerable node, which can be expressed as:<VEN,Type,VONS,Slice> .
[0056] VEN (Vulnerability Emerge Node) is a node where a buffer overflow vulnerability may occur, that is, a vulnerable node. For a buffer overflow caused by an array subscript out of bounds, the VEN node is a node that uses the array name and the array subscript index to access an array element. For a buffer overflow caused by external input, the VEN node is the call node of the external input function.
[0057] For buffer overflows caused by formatted strings, the VEN node is the call node of the sprintf class function and the scanf class function. For buffer overflows caused by memory initialization, the VEN node is the call node of the memset function. For buffer overflows caused by data copying, the VEN node is the call node of the string copy function. For buffer overflows caused by pointer iteration, the VEN node is the dereference node of the pointer and the node for accessing the pointer as an array using a subscript.
[0058] Type is the type of buffer overflow vulnerability in C language, including buffer overflow caused by array index out of bounds (ARRAYINDEX_BOV); buffer overflow caused by external input (INPUT_BOV); buffer overflow caused by format string (FORMAT_BOV); buffer overflow caused by memory initialization (MEMSET_BOV); buffer overflow caused by pointer iteration (ITERATOR_BOV); buffer overflow caused by data copy (DATACOPY _BOV).
[0059] VONS (Vulnerability Origin Node Set) is a set of vulnerability origin nodes, which may contain multiple nodes or only one node. VONS can be understood as the set of declaration and definition nodes of all arrays involved in the VEN node. For buffer overflows caused by formatted strings, VONS is the set of declaration and definition nodes of all character arrays involved in the parameters of the call site of sprintf and scanf functions. For buffer overflows caused by data copying, VONS is the set of declaration and definition nodes of the source and destination character arrays in the string copying function. For buffer overflows caused by memory initialization, VONS is the set of declaration and definition nodes of the array corresponding to the first parameter of the call node of the memset function. For buffer overflows caused by external input, VONS is the set of declaration and definition nodes of the character array corresponding to the string read by the external input function. For buffer overflows caused by pointer iteration, VONS is the set of declaration and definition nodes of the array corresponding to the pointer. For buffer overflows caused by array subscript out of bounds, the VONS node is the set of declaration and definition nodes of the accessed array.
[0060] Slice (extended value flow graph slice) is a slice from each node in the vulnerability root node set (VONS) to the buffer overflow vulnerability node (VEN). The nodes on the slice are all nodes related to the buffer overflow vulnerability involved in the VEN node of the slice. Each VEN node corresponds to a slice, which is a subgraph of the extended value flow graph corresponding to the code to be detected (only contains the extended value flow graph from each node in the vulnerability root node set to the current node). According to the extended value flow graph slice, the corresponding program statement in the code to be detected can be determined.
[0061] Traverse the extended value flow graph to find all VEN nodes, and then for each VEN node (current node), determine their type Type; find its corresponding VONS; slice the extended value flow graph according to the VEN node and VONS, and get the slice related to the buffer overflow vulnerability of the VEN node; form a four-tuple<VEN,Type,VONS,Slice> .
[0062] In some embodiments, the constraint conditions corresponding to the current node are solved to determine the variable range information and pointer alias information. The variable range information refers to the value range or constraint conditions associated with the variable. Pointer alias information refers to which pointers in the program may point to the same memory location. In simple terms, pointer alias means that different pointer variables point to the same memory area.
[0063] For example, interval information calculation is performed on the constraint conditions to obtain variable range information, and alias information calculation is performed on the constraint conditions to obtain pointer alias information.
[0064] There are three main methods for solving variable range information: polyhedron analysis, octahedron analysis, and interval analysis. Polyhedron analysis can accurately express the constraint relationship between multiple variables, with high accuracy, high time and space consumption, and poor practicality. Octahedron analysis is a compromise between interval analysis and polyhedron analysis. Compared with polyhedron, it has certain restrictions on the number of variables and coefficients expressed in the constraint expression, resulting in reduced accuracy, but the algorithm efficiency is at the cubic level, and it can be used to analyze larger projects. Interval analysis can only calculate the range of a single variable. The solved range is larger than the actual range. It is a conservative calculation of the variable value and has a high false alarm rate.
[0065] In terms of accuracy, polyhedron analysis is better than octahedron analysis, which is better than interval analysis; in terms of efficiency, interval analysis is better than octahedron analysis, which is better than polyhedron analysis.
[0066] For the calculation of pointer alias information, algorithms such as Choit, Andersen, Burke and Steensgaardi can be used. Among them, Steensgaardi is a flow-insensitive and context-insensitive analysis algorithm. Heap objects are simply represented by allocation addresses, and composite type objects are represented as a whole by an object, without iterative calculation. An alias relationship set is calculated for the entire program, making full use of a fast merge search data structure (union-find set) to represent the alias relationship, with an amortized linear complexity relative to the program size. It assumes that the alias relationship is reflexive and transitive, and no iteration is performed because the merge operation is used.
[0067] The open source operator SMTInterpol can be used to determine whether the constraint condition (constraint expression) is satisfied. If satisfied, there is no buffer overflow vulnerability in the code to be tested. If not satisfied, there is a buffer overflow vulnerability in the code to be tested.<VEN,Type,VONS,Slice> , determine the category information and path information of the buffer overflow vulnerability. Category information refers to the type of buffer overflow vulnerability, which is obtained through Type in the quadruple. Path information refers to the statement code location in the program, which can be obtained through VEN, VONS, and Slice in the quadruple.
[0068] In some embodiments, heuristic compiler matching includes: When there is no configuration file for the code to be detected or the compilation library cannot be determined based on the configuration file of the code to be detected, the code to be detected is searched to obtain a header file set in the code to be detected; Matching each header file in the header file set with the proprietary header files in each preset compilation library to determine the matching number of header files in each preset compilation library; Determine the similarity between each preset compiled library and the compiled library of the code to be detected based on the number of header file matches of each preset compiled library and the number of files in the header file set; The preset compilation library corresponding to the highest similarity is determined as the compilation library of the code to be detected, and the compiler corresponding to the code to be detected is determined.
[0069] Specifically, the configuration file can define settings such as compilation, linking, and debugging of the software engineering project, and specify information such as source code files and dependencies.
[0070] Figure 2 is a flow chart of the heuristic compiler matching provided by the present invention, such as Figure 2As shown in the figure, if there is a configuration file for the code to be detected, the information in the configuration file can be read to determine the compiler. For example, the software project created in Visual Studio has a configuration file with the suffix "vcxproj" or "vcproj". Then, based on these configuration files with specific file formats, the contents of these configuration files are identified, and then the specific type and version information of the compiler are determined based on the information described in the Extensible Markup Language (XML).
[0071] If there is no configuration file for the code to be detected or the compilation library (such as a third-party library) cannot be determined based on the configuration file of the code to be detected, you can perform an in-depth search on the code to be detected to obtain the header file set in the code to be detected. The searched header files are matched with special header file names and different compilers to calculate the similarity.
[0072] A compiler is a tool that converts source code written in a high-level programming language (such as C, C++, etc.) into low-level code (usually machine code or intermediate code) that a computer can understand and execute. A compiler library (sometimes also called a compiler runtime library or standard library) is usually a set of tools and libraries used with a compiler, which provides the functions required during the compilation process and at runtime.
[0073] You can define multiple preset compilation libraries, which can be embedded in the static detection tool. These preset compilation libraries can support compilers including VC6.0, VS08, VS10, VS12, MinGW, GCC, Tornado, QT4 and QT5.
[0074] A proprietary header file refers to a header file that belongs to any preset compilation library but not to other preset compilation libraries. When calculating the similarity between different preset compilation libraries and the set of header files required by the code to be detected, the same header files of each preset compilation library are not considered, only the proprietary header files are considered.
[0075] Each header file in the header file set is matched with the proprietary header files in each preset compilation library to determine the matching number of header files of each preset compilation library, which is expressed as: .
[0076] in, It is Preset Compilation Library The number of matches between the proprietary header files in the header file collection; For header files; Indicates the number of preset compilation libraries; Indicates A preset compilation library.
[0077] Ignoring the file path and considering only the header file name, the similarity between each preset compiled library and the compiled library of the code to be detected can be determined based on the number of header file matches of each preset compiled library and the number of files in the header file set, which can be expressed as: .
[0078] For the The similarity between a preset compiled library and the compiled library of the code to be detected.
[0079] The preset compilation library corresponding to the highest similarity is determined as the compilation library of the code to be detected, and the compiler corresponding to the code to be detected is determined. When there are multiple preset compilation libraries corresponding to the highest similarity, one of the preset compilation libraries can be randomly selected as the compilation library of the code to be detected. The library files in the preset compilation library can be automatically downloaded, and accordingly, the compiler corresponding to the code to be detected is determined.
[0080] The static detection method for buffer overflow vulnerabilities supporting incomplete codes provided by the embodiment of the present invention adopts heuristic compiler matching, which can make up for the missing compilation information as much as possible and improve the detection accuracy of buffer overflow vulnerabilities.
[0081] In some embodiments, the heuristic header file search includes: Determine the current file being analyzed; Determine multiple candidate header files corresponding to the currently analyzed file in the compiled library of the code to be detected; Determine the distance between the path string of each candidate header file and the path string of the current file being analyzed; The candidate header file corresponding to the minimum distance is determined as the header file included in the current analyzed file.
[0082] Specifically, when the language type of the code to be detected is C / C++ language, the types of header files may include user header files and library header files. Angle brackets represent library header files, and semicolons represent user header files. In a C / C++ project, multiple header files of different modules of a third-party library may have the same name, and incorrect matching may affect the correctness of static analysis. The embodiment of the present invention performs matching in a fine-grained manner, supporting not only library matching but also header file matching.
[0083] Figure 3 It is a schematic diagram of the flow of the heuristic header file retrieval provided by the present invention, such as Figure 3As shown, the currently analyzed file may be a header file included in the code to be detected (source file src), and matching is performed from the compiled library of the code to be detected using the included header file name or path suffix ("windows.h" or "sys / confg.h").
[0084] If multiple candidate header files are found, a heuristic rule is executed to calculate the path distance between each candidate header file and the current file being analyzed.
[0085] Assume The path string of the candidate header file in the compilation library is .in, Indicates the directory hierarchy, Indicates the file directory in the compiled library. The path string of the currently analyzed file in the source file is , Indicates the directory level, Represents the file directory in the source file.
[0086] Determine the distance between the path string of each candidate header file and the path string of the current file being analyzed, expressed as: In the formula, For the The distance between the path string of the candidate header file and the path string of the current file being analyzed; Indicates the directory level of the current calculation; is the Levenshtein function. This formula is used to indicate that the candidate header file with the most similar path prefix rather than suffix should be considered as having the minimum distance. The candidate header file corresponding to the minimum distance is determined as the header file included in the current analyzed file.
[0087] You can also choose the distance Sort the candidate header files according to the following principles: In the formula, For the Candidate header files, For the Candidate header files.
[0088] If the candidate header file set is not empty, the one with the closest path is selected as the header file included in the current analyzed file; if the candidate header file set is empty, that is, there is no candidate header file, the missing file information can be reported to the user.
[0089] The static detection method for buffer overflow vulnerabilities supporting incomplete codes provided by the embodiment of the present invention adopts heuristic header file retrieval, which can make up for the missing compilation information as much as possible and improve the detection accuracy of buffer overflow vulnerabilities.
[0090] In some embodiments, the heuristic macro replacement includes: Based on the configuration file of the code to be detected, determine the macro definition of the code to be detected; Determine the default macro definition list of the compiler corresponding to the code to be detected; Based on the default macro definition list, replace the macro definition of the code to be detected.
[0091] Specifically, in C / C++ programming languages, macros are widely used to generate different versions of software. By tracking the compilation process, compiler-defined macros and macros defined in the software development project corresponding to the code to be tested can be automatically obtained. However, when analyzing a project without tracking compilation information, these values are likely to be missing.
[0092] The configuration file of the code to be detected can be read to obtain the macro definition of the code to be detected. After determining the compiler corresponding to the code to be detected, the default macro definition list of the compiler can be obtained. According to each macro definition in the default macro definition list, the macro definition of the code to be detected is replaced.
[0093] For example, for the assert keyword, it is a macro replacement. For the VS08 and VC6 compilers, assert is replaced by a macro into a logical expression, and in the GCC compiler it is parsed into a ternary expression. It involves the actual _assert and _wassert functions. Therefore, choosing a different compiler means using a different default macro definition list, and also means using a different function summary (_assert and _wassert), which improves the compilation accuracy of incomplete code to a certain extent.
[0094] The static detection method for buffer overflow vulnerabilities supporting incomplete codes provided by the embodiment of the present invention adopts heuristic macro replacement, which can improve the accuracy of macro definitions, make up for missing compilation information as much as possible, and improve the detection accuracy of buffer overflow vulnerabilities.
[0095] In some embodiments, the heuristic binding construction includes: Determine the current statement in the code to be detected; the current statement is a function call statement or a variable declaration statement; Traverse the abstract syntax tree corresponding to the code to be checked to determine candidate expression statements and / or candidate declaration statements corresponding to the current statement; If both the candidate expression statement and the candidate declaration statement exist, the number of incorrect bindings of the candidate expression statement and the candidate declaration statement are both zero, and the candidate expression statement is a binary expression, the candidate declaration statement is bound to the current statement; When both the candidate expression statement and the candidate declaration statement exist, the number of incorrect bindings of the candidate expression statement and the candidate declaration statement are both zero, and the candidate expression statement is a function call expression, the candidate expression statement is bound to the current statement.
[0096] Specifically, function binding connects function calls and definitions, so it is particularly important for inter-function analysis. Variable binding connects variable declarations and uses. In order to establish missing binding information without a compilation process, you can find variable / function definitions with the same name and then compare the path similarity of the declaration, definition, and use files. The number of problem bindings refers to the number of times a wrong binding occurred.
[0097] Figure 4 is a schematic diagram of the process of heuristic binding construction provided by the present invention, such as Figure 4 As shown in the figure, in the abstract syntax tree (AST), for ambiguous nodes, CDT first parses them into unclear nodes (AmbiguousNode), and then resolves the ambiguity (resolve Ambiguty) on them.
[0098] For the statement A *b;, an AST Ambiguous Node will be generated. This AST AmbiguousNode has an alternative set (alternatives). The process of resolveAmbiguty is the process of selecting the bestalternative. In CDT, this process includes three steps: 1) Traverse all alternatives to find a particularly perfect one: find the first alternative with a problemBinding number of 0, stop traversal, and use it as the bestalternative. 2) If a particularly perfect one cannot be found, then find a relatively perfect one. Use the alternative with the smallest problemBinding number as the bestalternative. Then, use that bestalternative as the result of resolveAmbiguty and as the AST unit corresponding to the statement.
[0099] Take the following program code as an example.
[0100] typedef struct{int a;}Monkey; int fun(){int *p;if(1) Monkey *p;return 0;} Monkey*p is parsed into an expression statement, which does not match the original intention of the program. The reason for this is: for Monkey*p, this node has two alternatives: 1) alternative 1 is an expression statement (the expression is a binary expression); 2) alternative 2 is a declaration statement - in fact, it should be selected as the result after Monkey*p is parsed. However, because of the resolveAmbiguty process of CDT mentioned in the previous paragraph 1) traverse all alternatives to find a particularly perfect one: find the first alternative with a problemBinding number of 0, stop traversal, and use it as the bestalternative.
[0101] The improvement of the embodiment of the present invention is that even if the first alternative with a problemBinding number of 0 is found, the traversal is not terminated at this time, and there may be another alternative with a problemBinding number of 0. The details are as follows: A current statement in the code to be detected is determined, which may be a function call statement or a variable declaration statement.
[0102] The abstract syntax tree corresponding to the code to be checked is traversed to determine candidate expression statements and / or candidate declaration statements corresponding to the current statement.
[0103] When both candidate expression statements and candidate declaration statements exist, the problem binding numbers of candidate expression statements and candidate declaration statements are both zero, and the candidate expression statement is a binary expression, the candidate declaration statement is bound to the current statement. For example, if multiple alternative problem binding numbers are found to be 0, then if both expression statements and declaration statements exist and both problem binding numbers are 0, and the candidate expression statement is a binary expression, the declaration statement is selected as its bestalternative. This allows the above program to be parsed correctly.
[0104] When both candidate expression statements and candidate declaration statements exist, the number of problem bindings for both candidate expression statements and candidate declaration statements is zero, and the candidate expression statement is a function call expression, the candidate expression statement is bound to the current statement. For example, if both the expression statement and the declaration statement exist and the number of problemBindings is 0, and the candidate expression statement is a function call expression, the expression statement is selected as its bestalternative. This ensures that the program can be parsed correctly even when the code parsing is incomplete.
[0105] That is to say, when there are multiple alternatives with the same problemBinding number for an AmbiguousNode, the embodiment of the present invention does not use the first alternative found as the result of resolveAmbiguty as in the traditional method, but selects according to the following relationship with a certain priority: expression statement (function call expression) > declaration statement > expression statement (binary operation expression). This is in line with the design principle of C / C++ programming language and can ensure the accuracy of parsing is improved when the code is incomplete.
[0106] The static detection method for buffer overflow vulnerabilities supporting incomplete codes provided by the embodiment of the present invention adopts heuristic binding construction, which can make up for the missing compilation information as much as possible and improve the detection accuracy of buffer overflow vulnerabilities.
[0107] In some embodiments, heuristic function digest matching includes: Determine the distance between the function name in the current statement and the function name in the compiled library of the code to be detected; The function summary corresponding to the function name corresponding to the minimum distance is determined as the function summary of the current statement.
[0108] Specifically, function summaries are constructed during within-function analysis and used during between-function analysis.
[0109] For the current statement, if the function call has not been parsed to find its corresponding definition, it will search in the function summary library. If the search is successful, the summary will be used.
[0110] Figure 5 : is a flow chart of the heuristic function summary matching provided by the present invention, such as Figure 5 As shown, in the case of search failure, the distance between the function name in the current statement and the function name in the compiled library of the code to be detected can be calculated, and the distance can be the edit distance (Levenshtein). The function summary corresponding to the function name corresponding to the minimum distance is determined as the function summary of the current statement.
[0111] For example, if the function called in the program is x_malloc, then the function digest of malloc will be matched. If the heuristic algorithm still cannot match any digest to that function, then it will be considered a user-defined function.
[0112] The static detection method for buffer overflow vulnerabilities supporting incomplete codes provided by the embodiment of the present invention adopts heuristic function summary matching, which can make up for the missing compilation information as much as possible and improve the detection accuracy of buffer overflow vulnerabilities.
[0113] In some embodiments, heuristic constraint generation includes: Determine the function call statement corresponding to the vulnerable node; Based on the function summary of the function call statement, the constraint conditions of the vulnerable node are generated.
[0114] Specifically, heuristic constraint generation is mainly used for constraint generation of vulnerable nodes.
[0115] For user function call points where no corresponding binding can be found, in this case, the function summary cannot be determined, and constraints cannot be generated. A heuristic algorithm is used to construct the function summary, and then constraints are generated based on the generated function summary.
[0116] Take the following code as an example.
[0117] #include<stdio.h> #include "fun.h" void TaintedAccess(){char buf1
[12] ; char buf2
[12] ; char dst
[16] ; wrapped_read(buf1,sizeof(buf1)); wrapped_read(buf2,sizeof(buf2)); sprintf(dst,“%s-%s”,buf1,buf2)} The function wrapped_read may not be able to find the header file, and thus the function definition and declaration, because the uploaded project lacks compilation information.
[0118] keyi heuristically analyzes the function type and finds that the function has two parameters: one is a character array parameter (buf1, buf2), and the other is a character length parameter (sizeof(buf1), sizeof(buf2)). At the same time, the function name contains the word "read", which means it is likely to read a string.
[0119] Then, the function wrapped_read summary is constructed heuristically, and it is considered that after being processed by this function, the value of length(buf1) is between 0 and 12 (sizeof(buf1)), and the value of length(buf2) is between 0 and 12 (sizeof(buf2)). The statement sprintf(dst, "%s-%s", buf1, buf2); on line 10 is judged, and it is considered that the value of length(buf1)+1+length(buf2) is between 0 and 25, which may exceed the size of dst, 16, so this point is a buffer overflow vulnerability. The added heuristic strategy can reduce false negatives.
[0120] Take the following code as an example.
[0121] Line 1 #include<stdio.h> Line 2 #include "fun.h" Line 3 void TaintedAccess() Line 4 { Line 5 char buf1
[12] ; Line 6 char buf2
[12] ; Line 7 char dst
[16] ; Line 8 wrapped_read(buf1,6); Line 9 wrapped_read(buf2,6); Line 10: sprintf(dst,"%s-%s",buf1,buf2); Line 11} Using the same heuristic summary construction, it is believed that after being processed by this function, the value of length(buf1) is between 0 and 6, and the value of length(buf2) is between 0 and 6. The sprintf(dst, "%s-%s", buf1,buf2); statement in line 10 is judged and it is believed that the value of length(buf1)+1+length(buf2) is between 0 and 13, which will not exceed the size of dst, 16. Therefore, this point is not a buffer overflow vulnerability. The added heuristic strategy can reduce false positives.
[0122] For functions such as scanf, fscanf, etc., set certain function summaries and combine them with regular expression matching to generate corresponding constraints.
[0123] Take the following code as an example.
[0124] Line 1 #include<stdio.h> Line 2 int main() Line 3 { Line 4 long int rv=0; Line 5 char s
[1024] ; Line 6 FILE *f=fopen("D:\\11.txt", "r"); Line 7 int n=0; Line 8 s[0]='\0'; Line 9 rv=fscanf(f,"%1023s%n",s,&n); Line 10 s[n]='\0'; Line 11} If the instruction "%1023s%n" is not considered, the value n read in may be any value, i.e. (-∞, +∞), and a buffer overflow vulnerability will be reported in line 10. This is obviously a false positive. The essential reason is that the function summary in line 9 is not constructed sufficiently and the constraints are not constructed intelligently.
[0125] The function summary is constructed and intelligent constraints are generated. First, n is restricted by %n. The length of n should be the length of string s. Then, the information 1023 is extracted through regular expressions. It is inferred that the length of string s should not be greater than 1023, and then the constraints related to n are constructed, 0≤n≤1023. In this way, when the buffer is accessed in line 10, the buffer range is not exceeded.
[0126] Take the following code as an example.
[0127] Line 1 void fun(int i) Line 2 {int a
[10] ; Line 3 int b; Line 4 if((uint)i<10) Line 5 {b=a[i];}} Line 6 int main() Line 7 {fun(-1); Line 8 fun(2);} In line 7, the function parameter i=-1 is passed in. In line 4, the function parameter i is judged. If (uint)i<10, the array a[i] is accessed in line 5. uint is actually typedefed to unsigned int type, but it may not be correctly parsed due to the lack of compilation information and the lack of linking with the corresponding header file. In this case, if heuristic constraint generation is not performed, it will be considered that -1<10 is true, so the array a[-1] is accessed and a buffer overflow vulnerability occurs, which is obviously a false positive. Because -1 is forced to be converted to unsigned int type, it no longer meets the condition of <10 and will not enter line 5 of the program. When encountering a forced conversion statement that cannot be parsed, it is defaulted to convert the signed type to the unsigned type for heuristic constraint generation, which effectively reduces false positives.
[0128] The static detection method for buffer overflow vulnerabilities supporting incomplete codes provided by the embodiment of the present invention adopts heuristic constraint condition generation, which can make up for the missing compilation information as much as possible and improve the detection accuracy of buffer overflow vulnerabilities.
[0129] Figure 6 Schematic diagram of the technical architecture of the static detection method for buffer overflow vulnerabilities supporting incomplete codes provided by the present invention. Figure 6 As shown, the method includes: 1. Preprocessing stage Generate an enhanced abstract syntax tree based on C / C++ source code; in addition, a file missing report is also generated to inform the user about missing header file information included in the source file; use the EclipseCDT plug-in to perform lexical analysis and syntax analysis, and the CDT framework of the Eclipse development platform is used in the analysis process. The biggest advantage of this framework is that it can successfully generate an abstract syntax tree even if the C / C++ program fails to compile; however, in projects that do not track compilation information, the generated ASTs often lack necessary information, reducing detection accuracy.
[0130] 2. Basic Analysis Stage The enhanced abstract syntax tree is converted into a program dependency model; called an extended value flow graph (VDG), in preparation for the detection phase; first, the present invention converts ASTs into intermediate expressions (IR), and then creates summaries for library functions. Then the present invention performs a series of analyses, including control flow graph (CFG) construction, function call graph (CG) construction, global analysis, virtual function analysis, SSA analysis, pointer analysis, mod-effect analysis, and data flow analysis.
[0131] 3. Vulnerable Node Generation Phase Program slicing is performed according to the TYPE of the VEN node; mainly by analyzing the extended value flow graph output by the basic analyzer, the nodes where buffer overflow vulnerabilities may occur are found, and a four-tuple set representing the vulnerable node information is generated to generate constraint conditions.
[0132] 4. Constraint Generation and Solution Phase Vulnerability constraints are generated for each slice and the constraints are solved by SMTInterpol to determine whether the slice contains a buffer overflow vulnerability.
[0133] Constraint generation phase: based on the input vulnerable node quadruple<VEN,Type,VONS,Slice> Generate the corresponding constraint. First, the security policy generator combines the Type in the vulnerable node quadruple to generate the corresponding security policy SP, and then the constraint generator combines the VEN node and SP to generate the corresponding constraint C (Constraint).
[0134] Constraint solving stage: Input constraints and vulnerable node quadruple<VEN,Type,VONS,Slice> Generate the corresponding constraint solution results. Use the interval information calculator to obtain the value range information of the variables involved in the constraint conditions, use the alias information calculator to obtain the alias information of the pointers involved in the constraint conditions, and then use the open source operator SMTInterpol to determine whether the constraint expression is satisfied. If there is a feasible solution that makes it unsatisfactory, then select the quadruple.<VEN,Type,VONS,Slice> The vulnerability information is extracted from the corresponding SP and Constraint and reported to the user.
[0135] In the above methods, heuristic compiler matching, heuristic header file retrieval, heuristic macro replacement, heuristic binding construction, heuristic function summary matching and heuristic constraint condition generation are adopted.
[0136] In the preprocessing stage: heuristic compiler matching, selecting the compiler based on the code configuration file and the included header files; heuristic header file retrieval, finding the appropriate header file to prevent some statements from not being recognized by the syntax analysis; heuristic macro replacement technology handles some missing macros; heuristic binding construction, constructing bindings for function call points or variable usage points to find their definitions.
[0137] In the basic analysis phase: heuristic function summary matching, using its own function summary library to match function calls that cannot be found.
[0138] In the constraint generation stage: heuristic constraint generation, different heuristic strategies are used to reduce false positives.
[0139] The following describes a system provided by an embodiment of the present invention. The system described below and the method described above can be referenced to each other.
[0140] Figure 7 Schematic diagram of the structure of the static detection system for buffer overflow vulnerabilities supporting incomplete codes provided by the present invention. Figure 7 As shown, the system includes: A preprocessing unit 710 is used to perform an enhancement operation on an abstract syntax tree corresponding to the code to be detected, and determine an enhanced abstract syntax tree corresponding to the code to be detected; the code to be detected is an incomplete code; the enhancement operation includes heuristic compiler matching, heuristic header file retrieval, heuristic macro replacement and heuristic binding construction; A basic analysis unit 720 is used to determine the extended value flow graph corresponding to the code to be detected based on the enhanced abstract syntax tree, and perform heuristic function summary matching on the functions in the code to be detected; The vulnerable node generation unit 730 is used to traverse each node in the extended value flow graph to determine the vulnerable node corresponding to the code to be detected; the vulnerable node is a node where a buffer overflow vulnerability may occur; The constraint condition solving unit 740 is used to generate heuristic constraint conditions for vulnerable nodes, and determine the buffer overflow vulnerability detection result of the code to be detected based on the constraint condition solution result; the constraint condition is used to ensure that the vulnerable node does not have a buffer overflow.
[0141] The embodiment of the present invention provides a static detection device for buffer overflow vulnerabilities supporting incomplete codes. When the code to be detected is incomplete, an abstract syntax tree corresponding to the code to be detected is enhanced to determine the enhanced abstract syntax tree corresponding to the code to be detected; based on the enhanced abstract syntax tree, an extended value flow graph corresponding to the code to be detected is determined, and a heuristic function summary matching is performed on the function in the code to be detected; each node in the extended value flow graph is traversed to determine the vulnerable node corresponding to the code to be detected; heuristic constraint conditions are generated for the vulnerable nodes, and a buffer overflow vulnerability detection result of the code to be detected is determined based on the solution result of the constraint conditions; since compilation is not required, the buffer overflow vulnerability is detected in the case of incomplete code; since multiple heuristic strategies such as enhanced operations (including heuristic compiler matching, heuristic header file retrieval, heuristic macro replacement and heuristic binding construction), heuristic function summary matching and heuristic constraint condition generation are adopted in the program parsing, code analysis and defect detection stages to make up for the missing compilation information as much as possible, thereby improving the detection accuracy of buffer overflow vulnerabilities.
[0142] Figure 8 is a schematic diagram of the structure of the electronic device provided by the present invention, such as Figure 8 As shown, the electronic device may include: a processor (Processor) 810, a communication interface (Communications Interface) 820, a memory (Memory) 830 and a communication bus (Communications Bus) 840, wherein the processor 810, the communication interface 820, and the memory 830 communicate with each other through the communication bus 840. The processor 810 may call the logic command in the memory 830 to execute the method described in the above embodiment, for example: Perform enhancement operations on the abstract syntax tree corresponding to the code to be detected, and determine the enhanced abstract syntax tree corresponding to the code to be detected; the code to be detected is incomplete code; the enhancement operations include heuristic compiler matching, heuristic header file retrieval, heuristic macro replacement and heuristic binding construction; based on the enhanced abstract syntax tree, determine the extended value flow graph corresponding to the code to be detected, and perform heuristic function summary matching on the functions in the code to be detected; traverse each node in the extended value flow graph to determine the vulnerable node corresponding to the code to be detected; the vulnerable node is a node where a buffer overflow vulnerability may occur; heuristic constraint conditions are generated for the vulnerable nodes, and based on the solution results of the constraint conditions, the buffer overflow vulnerability detection results of the code to be detected are determined; the constraint conditions are used to ensure that the vulnerable nodes do not have buffer overflows.
[0143] In addition, the logic commands in the above-mentioned memory can be implemented in the form of software functional units and can be stored in a computer-readable storage medium when sold or used as an independent product. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product, which is stored in a storage medium and includes several commands to enable a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present invention. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), disk or optical disk, etc., which can store program code.
[0144] The processor in the electronic device provided in the embodiment of the present invention can call the logic instructions in the memory to implement the above method. Its specific implementation method is consistent with the implementation method of the aforementioned method and can achieve the same beneficial effects, which will not be repeated here.
[0145] An embodiment of the present invention further provides a computer-readable storage medium on which a computer program is stored. When the computer program is executed by a processor, the method provided in the above embodiments is implemented.
[0146] Its specific implementation is consistent with the aforementioned method implementation and can achieve the same beneficial effects, so it will not be repeated here.
[0147] An embodiment of the present invention provides a computer program product, including a computer program. When the computer program is executed by a processor, the method described above is implemented.
[0148] The device embodiments described above are merely illustrative, wherein the units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place, or they may be distributed on multiple network units. Some or all of the modules may be selected according to actual needs to achieve the purpose of the scheme of this embodiment. Ordinary technicians in this field can understand and implement it without paying creative labor.
[0149] Through the description of the above implementation methods, those skilled in the art can clearly understand that each implementation method can be implemented by means of software plus a necessary general hardware platform, and of course, can also be implemented by hardware. Based on this understanding, the above technical solution is essentially or the part that contributes to the prior art can be embodied in the form of a software product, and the computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, a disk, an optical disk, etc., including a number of instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.
[0150] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A static detection method for buffer overflow vulnerabilities supporting incomplete code, characterized in that: include: Performing an enhancement operation on an abstract syntax tree corresponding to the code to be detected, and determining an enhanced abstract syntax tree corresponding to the code to be detected; The code to be detected is an incomplete code; The enhanced operations include heuristic compiler matching, heuristic header file retrieval, heuristic macro replacement and heuristic binding construction; Based on the enhanced abstract syntax tree, determining the extended value flow graph corresponding to the code to be detected, and performing heuristic function summary matching on the functions in the code to be detected; Traversing each node in the extended value flow graph to determine a vulnerable node corresponding to the code to be detected; the vulnerable node is a node where a buffer overflow vulnerability may occur; Heuristic constraint conditions are generated for the vulnerable nodes, and based on the solution results of the constraint conditions, the buffer overflow vulnerability detection results of the code to be detected are determined; the constraint conditions are used to ensure that the vulnerable nodes do not have buffer overflows.
2. The static detection method for buffer overflow vulnerabilities supporting incomplete code according to claim 1, characterized in that: The heuristic compiler matching includes: In the case that there is no configuration file for the code to be detected or the compilation library cannot be determined based on the configuration file of the code to be detected, searching the code to be detected to obtain a header file set in the code to be detected; Matching each header file in the header file set with a proprietary header file in each preset compiled library to determine the matching number of header files in each preset compiled library; Determine the similarity between each preset compiled library and the compiled library of the code to be detected based on the number of header file matches of each preset compiled library and the number of files in the header file set; The preset compilation library corresponding to the highest similarity is determined as the compilation library of the code to be detected, and the compiler corresponding to the code to be detected is determined.
3. The static detection method for buffer overflow vulnerabilities supporting incomplete code according to claim 2, characterized in that: The heuristic header file retrieval includes: Determine the current file being analyzed; Determine, in the compiled library of the code to be detected, a plurality of candidate header files corresponding to the currently analyzed file; Determine the distance between the path string of each candidate header file and the path string of the currently analyzed file; The candidate header file corresponding to the minimum distance is determined as the header file included in the currently analyzed file.
4. The static detection method for buffer overflow vulnerabilities supporting incomplete code according to claim 2, characterized in that: The heuristic macro replacement includes: Determine the macro definition of the code to be detected based on the configuration file of the code to be detected; Determine a default macro definition list of the compiler corresponding to the code to be detected; Based on the default macro definition list, the macro definition of the code to be detected is replaced.
5. The static detection method for buffer overflow vulnerabilities supporting incomplete code according to claim 4, characterized in that: The heuristic binding construction includes: Determine a current statement in the code to be detected; the current statement is a function call statement or a variable declaration statement; Traversing the abstract syntax tree corresponding to the code to be detected to determine candidate expression statements and / or candidate declaration statements corresponding to the current statement; If both the candidate expression statement and the candidate declaration statement exist, the numbers of incorrect bindings of the candidate expression statement and the candidate declaration statement are both zero, and the candidate expression statement is a binary expression, binding the candidate declaration statement with the current statement; When both the candidate expression statement and the candidate declaration statement exist, the number of incorrect bindings of the candidate expression statement and the candidate declaration statement are both zero, and the candidate expression statement is a function call expression, the candidate expression statement is bound to the current statement.
6. The static detection method for buffer overflow vulnerabilities supporting incomplete code according to claim 5, characterized in that: The heuristic function summary matching includes: Determine the distance between the function name in the current statement and the function name in the compiled library of the code to be detected; The function summary corresponding to the function name corresponding to the minimum distance is determined as the function summary of the current statement.
7. The static detection method for buffer overflow vulnerabilities supporting incomplete code according to claim 6, characterized in that: The heuristic constraint generation includes: Determine a function call statement corresponding to the vulnerable node; Based on the function summary of the function call statement, a constraint condition of the vulnerable node is generated.
8. A static detection system for buffer overflow vulnerabilities supporting incomplete code, characterized in that: include: A preprocessing unit, configured to perform an enhancement operation on an abstract syntax tree corresponding to the code to be detected, and determine an enhanced abstract syntax tree corresponding to the code to be detected; The code to be detected is an incomplete code; The enhanced operations include heuristic compiler matching, heuristic header file retrieval, heuristic macro replacement and heuristic binding construction; A basic analysis unit, configured to determine an extended value flow graph corresponding to the code to be detected based on the enhanced abstract syntax tree, and perform heuristic function summary matching on functions in the code to be detected; A vulnerable node generation unit, used to traverse each node in the extended value flow graph to determine the vulnerable node corresponding to the code to be detected; the vulnerable node is a node where a buffer overflow vulnerability may occur; The constraint condition solving unit is used to generate heuristic constraint conditions for the vulnerable node, and determine the buffer overflow vulnerability detection result of the code to be detected based on the constraint condition solving result; the constraint condition is used to ensure that the vulnerable node does not have a buffer overflow.
9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the computer program, the static detection method for buffer overflow vulnerabilities supporting incomplete codes as described in any one of claims 1 to 7 is implemented.
10. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the static detection method for buffer overflow vulnerabilities supporting incomplete codes as described in any one of claims 1 to 7 is implemented.