Buffer overflow vulnerability decision-making judgment method and system based on extended value flow graph
Through the method based on the extended value flow graph, the detection program is analyzed and vulnerability node identification is generated and resolved to determine buffer overflow vulnerabilities, which solves the problems of low detection accuracy and efficiency in the prior art, and achieves more efficient vulnerability detection.
Patent Information
- Application Number
- CN202411717621.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-27
- Publication Date
- 2025-05-06
AI Technical Summary
The prior art is difficult to effectively improve the detection accuracy and detection efficiency of buffer overflow vulnerabilities.
Using the method based on the extended value flow graph, the abstract syntax tree of the detection program is analyzed, the extended value flow graph is determined, the nodes are traversed to identify the vulnerability node, and constraints are generated based on the vulnerability nodes, and buffer overflow vulnerabilities are determined by solving the constraint conditions.
Through the static detection method, buffer overflow vulnerabilities can be discovered earlier and more detailed vulnerability information can be provided, which improves detection accuracy; at the same time, analysis of vulnerable nodes is only performed, avoiding the analysis of irrelevant nodes and improving detection efficiency.
Smart Images

Figure CN119939589A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer technology, and in particular to a buffer overflow vulnerability decision-making method and system based on an extended value flow graph. Background Art
[0002] During computer operation, various variables are declared in a program. Static global variables are located in the data segment and are loaded when the program starts running. Dynamic local variables are allocated in the stack, and the buffer is a continuous storage space reserved in the stack. When a program tries to put more data into a buffer, the data exceeds the reserved range of the buffer or when a program tries to put data into a memory location that exceeds the boundary of the buffer, a buffer overflow occurs.
[0003] Buffer overflow vulnerabilities can lead to a variety of serious security issues, including code execution, information leakage, program crash, and privilege escalation.
[0004] Therefore, how to improve the detection accuracy and efficiency of buffer overflow vulnerabilities has become a technical problem that needs to be urgently solved in the industry. Summary of the invention
[0005] The present invention provides a buffer overflow vulnerability decision-making determination method and system based on an extended value flow graph, which are used to solve the technical problem of how to improve the detection accuracy and detection efficiency of buffer overflow vulnerabilities.
[0006] The present invention provides a buffer overflow vulnerability decision-making method based on an extended value flow graph, comprising: Analyze the abstract syntax tree corresponding to the program to be detected, and determine the extended value flow graph corresponding to the program to be detected; Traversing each node in the extended value flow graph to determine a vulnerable node corresponding to the program to be detected; the vulnerable node is a node where a buffer overflow vulnerability may occur; Determining a constraint condition corresponding to the vulnerable node; the constraint condition is used to ensure that the vulnerable node does not have a buffer overflow; Based on the solution result of the constraint condition, a buffer overflow vulnerability detection result of the program to be detected is determined.
[0007] In some embodiments, analyzing the abstract syntax tree corresponding to the program to be detected to determine the extended value flow graph corresponding to the program to be detected includes: Determine an abstract syntax tree corresponding to the program to be detected; Performing value flow analysis on the abstract syntax tree to determine entry dependency, flow dependency, pointer dereference dependency and address fetch dependency corresponding to the program to be detected; Determine an extended value flow graph corresponding to the program to be detected based on the entry dependency, the flow dependency, the pointer dereference dependency and the address fetch dependency; Among them, the entry dependency refers to the dependency from the program entry node to the variable declaration node; the flow dependency refers to the dependency from the variable definition node to the variable direct use node; the pointer dereference dependency refers to the dependency from the variable definition node to the node that dereferences the variable; the address dependency refers to the dependency from the variable definition node to the node that performs address operations on the variable.
[0008] In some embodiments, traversing each node in the extended value flow graph to determine the vulnerability node corresponding to the program to be detected includes: Determining that a current node in the extended value flow graph is a vulnerable node; Generate a vulnerable node quadruple corresponding to the current node based on the current node, the buffer overflow vulnerability type corresponding to the current node, the vulnerability root node set and the extended value flow graph slice; The extended value flow graph slice is an extended value flow graph from each node in the vulnerability root node set to the current node.
[0009] In some embodiments, the determining of the constraint conditions corresponding to the vulnerable nodes includes: Based on the vulnerable node quadruple corresponding to the current node, determine the buffer overflow vulnerability type corresponding to the current node; Based on the buffer overflow vulnerability type corresponding to the current node, determine the security policy corresponding to the current node; the security policy is a rule to be followed to ensure that there is no buffer overflow vulnerability in the program; Based on the security policy and the current node, a constraint condition corresponding to the current node is generated.
[0010] In some embodiments, the determining of the buffer overflow vulnerability detection result of the program to be detected based on the solution result of the constraint condition includes: Solve the constraint conditions corresponding to the current node, and determine the variable value range information and pointer alias information corresponding to the constraint conditions; When the constraint condition is not satisfied, determining that a buffer overflow vulnerability exists in the program to be detected; Determine the category information and path information of the buffer overflow vulnerability based on the vulnerable node quadruple corresponding to the current node; Based on the category information and path information of the buffer overflow vulnerability, a buffer overflow vulnerability detection result of the program to be detected is generated.
[0011] In some embodiments, solving the constraint conditions corresponding to the current node and determining the variable value range information and pointer alias information corresponding to the constraint conditions includes: Determine a first interval set and a second interval set corresponding to the current node; the first interval set is an interval set where the variable may exist; the second interval set is an interval set where the variable must exist; Determine interval information of variables flowing into the current node and interval information of variables flowing out of the current node based on the first interval set and the second interval set; Based on the interval information of the variables flowing into the current node and the interval information of the variables flowing out of the current node, the variable range information corresponding to the constraint condition is determined.
[0012] In some embodiments, buffer overflow vulnerability types include buffer overflow caused by format string, buffer overflow caused by data copy, buffer overflow caused by memory initialization, buffer overflow caused by external input, buffer overflow caused by pointer iteration, and buffer overflow caused by array subscript out of bounds.
[0013] The present invention provides a buffer overflow vulnerability decision-making and determination system based on an extended value flow graph, comprising: An extended value flow graph determination unit, used to analyze an abstract syntax tree corresponding to a program to be detected, and determine an extended value flow graph corresponding to the program to be detected; A vulnerable node extraction unit, used to traverse each node in the extended value flow graph to determine the vulnerable node corresponding to the program to be detected; the vulnerable node is a node where a buffer overflow vulnerability may occur; A constraint condition generating unit, used for determining the constraint condition corresponding to the vulnerable node; the constraint condition is used for ensuring that the vulnerable node does not have a buffer overflow; The vulnerability information detection unit is used to determine the buffer overflow vulnerability detection result of the program to be detected based on the solution result of the constraint condition.
[0014] The present invention provides an electronic device, comprising a memory, a processor and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the method for determining a buffer overflow vulnerability based on an extended value flow graph is implemented.
[0015] The present invention provides a non-transitory computer-readable storage medium on which a computer program is stored. When the computer program is executed by a processor, the buffer overflow vulnerability decision-making and determination method based on an extended value flow graph is implemented.
[0016] The buffer overflow vulnerability decision-making and determination method and system based on the extended value flow graph provided by the present invention analyze the abstract syntax tree corresponding to the program to be detected to determine the extended value flow graph corresponding to the program to be detected; traverse each node in the extended value flow graph to determine the vulnerable node corresponding to the program to be detected; the vulnerable node is a node where a buffer overflow vulnerability may occur; determine the constraint condition corresponding to the vulnerable node; the constraint condition is used to ensure that the vulnerable node does not have a buffer overflow; based on the solution result of the constraint condition, determine the buffer overflow vulnerability detection result of the program to be detected; due to the use of a static detection method, the extended value flow graph that can fully reflect the dependency relationship between variables, especially pointers, is analyzed to determine the vulnerable node, and the buffer overflow vulnerability detection result is determined according to the solution of the constraint condition corresponding to the vulnerable node, so that the vulnerability can be discovered earlier and more detailed vulnerability information can be given, thereby improving the detection accuracy of the buffer overflow vulnerability; since only the vulnerable node is analyzed, the analysis of the node irrelevant to the vulnerability is avoided, thereby improving the detection efficiency of the buffer overflow vulnerability. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the invention and, together with the description, serve to explain the principles of the invention.
[0018] In order to more clearly illustrate the technical solutions in the present invention or the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.
[0019] Figure 1 It is a flow chart of a buffer overflow vulnerability decision-making method based on an extended value flow graph provided by the present invention.
[0020] Figure 2 It is a schematic diagram of the value flow graph and the extended value flow graph provided by the present invention.
[0021] Figure 3 It is one of the schematic diagrams of the extended value flow graph provided by the present invention.
[0022] Figure 4 It is a schematic diagram of the extended value stream graph slice provided by the present invention.
[0023] Figure 5 This is the second schematic diagram of the extended value flow graph provided by the present invention.
[0024] Figure 6 It is a schematic diagram of the inter-node interval information dependency relationship provided by the present invention.
[0025] Figure 7 It is a schematic diagram of the node interval information calculation process provided by the present invention.
[0026] Figure 8 It is one of the structural schematic diagrams of the buffer overflow vulnerability decision-making and determination system based on the extended value flow graph provided by the present invention.
[0027] Fig. 9 This is the second structural schematic diagram of the buffer overflow vulnerability decision-making and determination system based on the extended value flow graph provided by the present invention.
[0028] Fig.10 It is a structural schematic diagram of the electronic device provided by the present invention. DETAILED DESCRIPTION
[0029] In order to enable those skilled in the art to better understand the scheme of the present invention, the technical scheme in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work should fall within the scope of protection of the present invention.
[0030] It should be noted that the terms "first", "second", etc. in the present invention are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged where appropriate, so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device that includes a series of steps or units or modules is not necessarily limited to those steps or units or modules that are clearly listed, but may include other steps or units or modules that are not clearly listed or inherent to these processes, methods, products or devices.
[0031] A buffer overflow vulnerability is a common computer security vulnerability that usually occurs when a program attempts to write too much data into a fixed-size memory area (buffer).
[0032] Buffer overflow vulnerabilities can be divided into two categories according to where they occur: stack buffer overflow and heap buffer overflow. When a program writes content to the memory on the call stack, it exceeds the size of the expected data structure (this expected data structure is often a buffer of fixed length), and a stack buffer overflow will occur. Heap buffer overflow is a buffer overflow that occurs in the heap data area. Heap memory is often dynamically allocated when the application is running, and usually contains program data. Due to the dynamic nature of the heap when allocating and releasing, the exploitation of heap buffer overflow vulnerabilities is relatively rare in reality. Buffer overflow vulnerabilities can be divided into three categories according to the actions when they occur: buffer overflow caused by unsafe memory allocation, buffer overflow caused by unsafe memory reading, and buffer overflow caused by unsafe memory writing.
[0033] The analysis and defense of buffer overflow vulnerabilities have always been a hot and difficult issue in information security research. Buffer overflow vulnerabilities can be detected through static analysis methods. Static analysis refers to the analysis process performed without running the software. The object of static analysis is generally the program source code or the target code. Compared with the defense method during program runtime, the static analysis method has the advantages of discovering vulnerabilities early, providing more detailed vulnerability information, and being able to detect and eliminate vulnerabilities fundamentally.
[0034] Figure 1 is a flow chart of a buffer overflow vulnerability decision determination method based on an extended value flow graph provided by the present invention, such as Figure 1 As shown, the method includes step 110 , step 120 , step 130 and step 140 .
[0035] Step 110: Analyze the abstract syntax tree corresponding to the program to be detected, and determine the extended value flow graph corresponding to the program to be detected.
[0036] Specifically, the execution subject of the buffer overflow vulnerability decision determination method based on the extended value flow graph provided in the embodiment of the present invention is a buffer overflow vulnerability decision determination system. The system can be implemented by software, such as a buffer overflow vulnerability decision determination program; or by hardware, such as a computer or server that executes the buffer overflow vulnerability decision determination method.
[0037] The application scenario of the buffer overflow vulnerability decision-making method provided by the embodiment of the present invention is to detect buffer overflow vulnerabilities that may exist in a program to be detected. The program to be detected can be a program written in C language or C++ language.
[0038] Static detection of buffer overflows in programs to be tested can be performed using three models, namely, Abstract Syntax Tree (AST), Control Flow Graph (CFG), and Value Flow Graph (VFG). An abstract syntax tree is a tree representation of the source code of a programming language. Each node on the tree represents a structure of the source code. A control flow graph is a directed graph that reflects the logic control flow of a program. The nodes of a control flow graph are the following basic blocks: the instruction sequence is always executed continuously from the first to the last, and no instruction will be skipped during the process. The boundaries of the control flow graph represent the control flow path between basic blocks. A value flow graph is a directed graph that reflects the flow relationship of the values of variables in a program (to distinguish it from an extended value flow graph, it can also be called a traditional value flow graph). Value flow analysis constructs a value flow graph by integrating control flow analysis, fixed value usage in data flow analysis, and function call relationship analysis. Each value flow subgraph expresses the life cycle of a variable before its value changes. Each node in the value flow graph is determined according to each statement in the program.
[0039] There is only one kind of dependency between points in the value flow graph: flow dependency. The value flow graph cannot fully reflect the program semantic information. In order to solve the problem that the value flow graph does not fully express the dependency between variables, the value flow graph is expanded to expand one dependency into four (including entry dependency, flow dependency, pointer dereference dependency and address dependency), thus obtaining an extended value flow graph (also called value dependency graph).
[0040] The abstract syntax tree corresponding to the program to be detected can be determined according to the source code of the program to be detected, and the abstract syntax tree is analyzed to obtain the extended value flow graph corresponding to the program to be detected.
[0041] Step 120, traverse each node in the extended value flow graph to determine the vulnerable node corresponding to the program to be detected; the vulnerable node is a node where a buffer overflow vulnerability may occur.
[0042] Specifically, a vulnerable node refers to a node where a buffer overflow vulnerability may occur, and corresponding to the program to be detected, it may be a statement or structure where a buffer overflow vulnerability may occur.
[0043] By traversing each node in the extended value flow graph, the vulnerable nodes corresponding to the program to be tested can be screened out.
[0044] Step 130: determine the constraint conditions corresponding to the vulnerable node; the constraint conditions are used to ensure that the vulnerable node does not have a buffer overflow.
[0045] Specifically, constraints usually refer to specific requirements or restrictions that must be met during program execution. Constraints are used to ensure that vulnerable nodes do not overflow buffers.
[0046] By analyzing the vulnerable nodes corresponding to the program to be detected, the constraints corresponding to each vulnerable node can be determined. In the embodiment of the present invention, the constraints mainly include constraints related to the value range information of the variable and constraints related to the alias information of the pointer.
[0047] Step 140: Based on the solution results of the constraint conditions, determine the buffer overflow vulnerability detection result of the program to be detected.
[0048] Specifically, the constraint condition can usually be expressed as a constraint expression. The constraint expression can be solved. If the constraint condition is satisfied, it can be determined that the vulnerable node is a node where buffer overflow will not occur; if the constraint condition is not satisfied, it can be determined that the vulnerable node is a node where buffer overflow occurs.
[0049] When the vulnerable node is a node where a buffer overflow occurs, the buffer overflow vulnerability detection result of the program to be detected can be determined as the existence of a vulnerability, and information such as the location of the buffer overflow vulnerability can be determined based on the location of the vulnerable node.
[0050] The buffer overflow vulnerability decision-making and determination method based on the extended value flow graph provided by the embodiment of the present invention analyzes the abstract syntax tree corresponding to the program to be detected to determine the extended value flow graph corresponding to the program to be detected; traverses each node in the extended value flow graph to determine the vulnerable node corresponding to the program to be detected; the vulnerable node is a node where a buffer overflow vulnerability may occur; determines the constraint condition corresponding to the vulnerable node; the constraint condition is used to ensure that the vulnerable node does not have a buffer overflow; based on the solution result of the constraint condition, determines the buffer overflow vulnerability detection result of the program to be detected; due to the use of a static detection method, the extended value flow graph that can fully reflect the dependency relationship between variables, especially pointers, is analyzed to determine the vulnerable node, and the buffer overflow vulnerability detection result is determined according to the solution of the constraint condition corresponding to the vulnerable node, so that the vulnerability can be discovered earlier and more detailed vulnerability information can be given, thereby improving the detection accuracy of the buffer overflow vulnerability; since only the vulnerable node is analyzed, the analysis of the node unrelated to the vulnerability is avoided, thereby improving the detection efficiency of the buffer overflow vulnerability.
[0051] It should be noted that each implementation of the present invention can be freely combined, the order can be changed, or it can be executed separately, and does not need to rely on or depend on a fixed execution order.
[0052] In some embodiments, analyzing the abstract syntax tree corresponding to the program to be detected to determine the extended value flow graph corresponding to the program to be detected includes: Determine the abstract syntax tree corresponding to the program to be tested; Perform value flow analysis on the abstract syntax tree to determine the entry dependency, flow dependency, pointer dereference dependency, and address dependency corresponding to the program to be tested; Determine the extended value flow graph corresponding to the program to be detected based on the entry dependency, flow dependency, pointer dereference dependency and address fetch dependency; Among them, the entry dependency refers to the dependency from the program entry node to the variable declaration node; the flow dependency refers to the dependency from the variable definition node to the node that directly uses the variable; the pointer dereference dependency refers to the dependency from the variable definition node to the node that dereferences the variable; the address dependency refers to the dependency from the variable definition node to the node that performs the address operation on the variable.
[0053] Specifically, the value flow analysis can be performed on the abstract syntax tree to determine the entry dependency, flow dependency, pointer dereference dependency and address fetch dependency corresponding to the program to be detected.
[0054] The following program code is used as an example for explanation.
[0055] void fun(){int array
[10] ;int *p;int *q;int *r;int t;p=array;q=p;r=&array;t=*p;} Figure 2 is a schematic diagram of the value flow diagram and the extended value flow diagram provided by the present invention, such as Figure 2 As shown in the figure, the value flow graph includes 6 nodes, namely n1, n2, n3, n4, n5, and n6. There is only one kind of dependency between the nodes in the value flow graph: flow dependency, which cannot fully reflect the program semantic information. The flow of n3 node (p=array) depends on n2 node (int array
[10] ); the flow of n5 node (q=p) depends on n3 node (p=array); but in fact, n4 node (r=&array) depends on n2 node (intarray
[10] ) to a certain extent, and n6 node (t=*p) depends on n3 node p=array to a certain extent. The dependency between these variables is not reflected in the value flow graph.
[0056] To solve the problem that the value stream diagram does not fully express the dependency relationship between variables, the value stream diagram is expanded by expanding one dependency relationship into four to obtain an extended value stream diagram.
[0057] In the extended value flow graph, the entry dependency (EntryDepend) refers to the dependency from the program entry node to the variable declaration node. For example, the dependency from the n1 node (Entry) to the n2 node (int array
[10] ) is the entry dependency.
[0058] A flow dependency (FlowDepend) refers to the dependency from the definition node of a variable to the node that directly uses the variable. For example, the relationship from the n2 node (int array
[10] ) to the n3 node (p=array) is a flow dependency; the relationship from the n3 node (p=array) to the n5 node (q=p) is also a flow dependency.
[0059] Pointer dereference dependency (DerefDepend) refers to the dependency from the variable definition node to the node used to dereference the variable. For example, the relationship from n3 node (p=array) to n6 node (t=*p) is a pointer dereference dependency.
[0060] Address dependency refers to the dependency from the variable definition node to the node that performs the address operation on the variable. For example, the relationship from node n2 (p=array) to node n4 (r=&array) is an address dependency.
[0061] The buffer overflow vulnerability decision-making and determination method based on the extended value flow graph provided in the embodiment of the present invention analyzes the abstract syntax tree corresponding to the program to be detected and determines the extended value flow graph corresponding to the program to be detected, which can make the semantic information of the program more completely reflected and improve the detection accuracy of the buffer overflow vulnerability.
[0062] In some embodiments, buffer overflow vulnerability types include buffer overflow caused by format string, buffer overflow caused by data copy, buffer overflow caused by memory initialization, buffer overflow caused by external input, buffer overflow caused by pointer iteration, and buffer overflow caused by array subscript out of bounds.
[0063] Specifically, buffer overflow vulnerability types can be roughly divided into six categories.
[0064] The first type is buffer overflow caused by format string (FORMAT_BOV).
[0065] Buffer overflow caused by formatted string refers to buffer overflow caused by not limiting the length of the array when formatting the string. It is a buffer overflow caused by writing data out of bounds. There are two main types of formatted string functions in C language that may cause buffer overflow, one is scanf-type functions, and the other is sprintf-type functions.
[0066] The second type is buffer overflow caused by data copy (DATACOPY_BOV).
[0067] Buffer overflow caused by data copying refers to a buffer overflow caused by not limiting the size of the copied content when calling the string copy function. It is a buffer overflow caused by out-of-bounds reading and writing of data. According to the action when the overflow occurs, the buffer overflow caused by data copying can be divided into two types: overflow caused by out-of-bounds reading of data and overflow caused by out-of-bounds writing of data. Overflow caused by out-of-bounds reading of data refers to a buffer overflow caused by the content read beyond the range of the source character array when reading the content to be copied to the destination character array when calling the string copy function. Overflow caused by out-of-bounds writing of data refers to a buffer overflow caused by out-of-bounds writing of data when copying the content from the source character array to the destination character array when calling the string copy function.
[0068] The third type is buffer overflow caused by memory initialization (MEMSET_BOV).
[0069] Buffer overflow caused by memory initialization refers to the situation where the declared size of the array is not taken into consideration when initializing the memory of the array, and the adjacent memory is overwritten, which causes a buffer overflow. It is a buffer overflow caused by out-of-bounds writing of data.
[0070] The fourth category is buffer overflow caused by external input (INPUT_BOV).
[0071] A buffer overflow caused by external input refers to a buffer overflow caused by overwriting the storage content of adjacent memory due to the length of the string from external input exceeding the declared size of the character array. It is a buffer overflow caused by out-of-bounds writing of data.
[0072] The fifth category is buffer overflow caused by pointer iteration (ITERATOR_BOV).
[0073] In C language, pointers and arrays can be flexibly converted to each other, which brings great flexibility to the program but also brings serious security problems. Buffer overflow caused by pointer iteration refers to the use of pointers to replace array element addresses and access specific array elements through pointer offsets. The buffer overflow is caused by the pointer address exceeding the array element range. Buffer overflow caused by pointer iteration is a buffer overflow caused by out-of-bounds writing or reading of data.
[0074] The sixth type is buffer overflow caused by array index out of bounds (ARRAYINDEX_BOV).
[0075] Buffer overflow caused by array subscript out of bounds refers to buffer overflow caused by the possible value range of the array subscript exceeding the array size.
[0076] The buffer overflow vulnerability decision-making and determination method based on the extended value flow graph provided by the embodiment of the present invention can detect six types of buffer overflow vulnerabilities, thereby improving the detection accuracy of buffer overflow vulnerabilities.
[0077] In some embodiments, traversing each node in the extended value flow graph to determine the vulnerability node corresponding to the program to be detected includes: Determine that the current node in the extended value flow graph is a vulnerable node; Generate a vulnerable node quadruple corresponding to the current node based on the current node, the buffer overflow vulnerability type corresponding to the current node, the vulnerability root node set and the extended value flow graph slice; Among them, the extended value flow graph slice is an extended value flow graph from each node in the vulnerability root node set to the current node.
[0078] Specifically, in order to better describe the C language buffer vulnerability, the embodiment of the present invention abstracts the C language buffer overflow vulnerability, proposes a C language buffer overflow vulnerability model, and uses a quadruple method to represent the vulnerable node, which can be expressed as<VEN,Type,VONS,Slice> .
[0079] VEN (Vulnerability Emerge Node) is a node where a buffer overflow vulnerability may occur, that is, a vulnerable node. For a buffer overflow caused by an array subscript out of bounds, the VEN node is a node that uses the array name and the array subscript index to access an array element. For a buffer overflow caused by external input, the VEN node is the call node of the external input function.
[0080] For buffer overflows caused by formatted strings, the VEN node is the call node of the sprintf class function and the scanf class function. For buffer overflows caused by memory initialization, the VEN node is the call node of the memset function. For buffer overflows caused by data copying, the VEN node is the call node of the string copy function. For buffer overflows caused by pointer iteration, the VEN node is the dereference node of the pointer and the node for accessing the pointer as an array using a subscript.
[0081] Type is the type of buffer overflow vulnerability in C language, including buffer overflow caused by array index out of bounds (ARRAYINDEX_BOV); buffer overflow caused by external input (INPUT_BOV); buffer overflow caused by format string (FORMAT_BOV); buffer overflow caused by memory initialization (MEMSET_BOV); buffer overflow caused by pointer iteration (ITERATOR_BOV); buffer overflow caused by data copy (DATACOPY _BOV).
[0082] VONS (Vulnerability Origin Node Set) is a set of vulnerability origin nodes, which may contain multiple nodes or only one node. VONS can be understood as the set of declaration and definition nodes of all arrays involved in the VEN node. For buffer overflows caused by formatted strings, VONS is the set of declaration and definition nodes of all character arrays involved in the parameters of the call site of sprintf and scanf functions. For buffer overflows caused by data copying, VONS is the set of declaration and definition nodes of the source and destination character arrays in the string copying function. For buffer overflows caused by memory initialization, VONS is the set of declaration and definition nodes of the array corresponding to the first parameter of the call node of the memset function. For buffer overflows caused by external input, VONS is the set of declaration and definition nodes of the character array corresponding to the string read by the external input function. For buffer overflows caused by pointer iteration, VONS is the set of declaration and definition nodes of the array corresponding to the pointer. For buffer overflows caused by array subscript out of bounds, the VONS node is the set of declaration and definition nodes of the accessed array.
[0083] Slice (extended value flow graph slice) is a slice from each node in the vulnerability root node set (VONS) to the buffer overflow vulnerability node (VEN). The nodes on the slice are all nodes related to the buffer overflow vulnerability involved in the VEN node of the slice. Each VEN node corresponds to a slice, which is a subgraph of the extended value flow graph corresponding to the program to be tested (only contains the extended value flow graph from each node in the vulnerability root node set to the current node). According to the extended value flow graph slice, the corresponding program statement in the program to be tested can be determined.
[0084] Traverse the extended value flow graph to find all VEN nodes, and then for each VEN node (current node), determine their type Type; find its corresponding VONS; slice the extended value flow graph according to the VEN node and VONS, and get the slice related to the buffer overflow vulnerability of the VEN node; form a four-tuple<VEN,Type,VONS,Slice> . Take the following program code as an example: void wrapped_read(char* buf, int count){fgets(buf, count, stdin)} void TaintedAcess(){char buf1
[12] ; char buf2
[12] ; char dst
[16] ; wrapped_read (buf1, sizeof(buf1)); wrapped_read (buf2, sizeof(buf2)); springf(dst, "%s-%s\n", buf1,buf2);} Figure 3 is one of the schematic diagrams of the extended value flow graph provided by the present invention, such as Figure 3 As shown in the figure, each extended value flow graph has an EntryNode, which represents the entry node of the program. There are 19 nodes in the figure, reflecting the value flow relationship of the corresponding program. First, according to the VEN node type information corresponding to different buffer overflow vulnerabilities, it can be found that the call node n17 of the sprintf function in the second to last line of the program is a VEN node. The type (Type) of this VEN node is FORMAT_BOV, and the VONS corresponding to this VEN node is a node set consisting of n3 (the declaration node of buf1), n4 (the declaration node of buf2) and n12 (the declaration node of dst). The slicing process is to start from VEN node n17 and traverse in reverse until the node n3, n4, n12 or n1 (EntryNode) in VONS is accessed, and the traversal is terminated. The nodes accessed during the traversal process will be recorded, and the nodes accessed and the edges between them constitute the slice corresponding to the VEN node. For VEN node n17, a slice (Slice) can be obtained.
[0085] Figure 4 is a schematic diagram of the extended value stream graph slice provided by the present invention, such as Figure 4 As shown, this program has only one VEN node n17, and the generated quadruple is<n17,FORMAT_BOV,{ n3,n4,n12},SliceOfn17> .
[0086] The buffer overflow vulnerability decision-making and determination method based on the extended value flow graph provided by the embodiment of the present invention traverses each node in the extended value flow graph, determines the vulnerable node corresponding to the program to be detected, realizes the screening of each node, and improves the detection efficiency of the buffer overflow vulnerability.
[0087] In some embodiments, determining the constraint conditions corresponding to the vulnerable nodes includes: Based on the vulnerable node quadruple corresponding to the current node, determine the buffer overflow vulnerability type corresponding to the current node; Based on the buffer overflow vulnerability type corresponding to the current node, determine the security policy corresponding to the current node; the security policy is the rules to be followed to ensure that there is no buffer overflow vulnerability in the program; Based on the security policy and the current node, generate the constraints corresponding to the current node.
[0088] Specifically, according to the vulnerable node quadruple corresponding to the current node, the buffer overflow vulnerability type (Type) corresponding to the current node is determined. According to the buffer overflow vulnerability type corresponding to the current node, the security policy (Security Policy, SP) corresponding to the current node is determined. The security policy is the rules to be followed to ensure that there is no buffer overflow vulnerability in the program.
[0089] There is a one-to-one mapping relationship between buffer overflow vulnerability types and security policies. Each input of a vulnerable node quadruple<VEN,Type,VONS,Slice> , we can get the corresponding SP according to the category information of Type. For example, the vulnerable node quadruple<n17,FORMAT_BOV,{ n3,n4,n12},SliceOfn17> The Type is FORMAT_BOV, so the corresponding security policy SP is that the size of the character array to be formatted should be greater than or equal to the length of the string used for formatting.
[0090] Generate specific constraint expressions (Constraint, C) according to the corresponding security policy SP and VEN nodes.<VEN,SP> A constraint expression will be generated. For example, the four-tuple<n17,FORMAT_BOV,{ n3,n4,n12},SliceOfn17> SP is the source string length for formatting, which should be smaller than the size of the character array to be formatted. VEN is node n17: sprintf(dst,"%s-%s\n",buf1,buf2); then the generated constraint is size(dst)≥len(buf1)+1+len(buf2).
[0091] The buffer overflow vulnerability decision-making method based on the extended value flow graph provided by the embodiment of the present invention determines the constraint conditions corresponding to the vulnerable node according to the vulnerable node quadruple corresponding to the current node, thereby improving the detection accuracy of the buffer overflow vulnerability.
[0092] In some embodiments, based on the solution result of the constraint condition, determining the buffer overflow vulnerability detection result of the program to be detected includes: Solve the constraints corresponding to the current node and determine the variable range information and pointer alias information corresponding to the constraints; When the constraint condition is not satisfied, it is determined that there is a buffer overflow vulnerability in the program to be detected; Based on the vulnerable node quadruple corresponding to the current node, determine the category information and path information of the buffer overflow vulnerability; Based on the category information and path information of the buffer overflow vulnerability, a buffer overflow vulnerability detection result of the program to be detected is generated.
[0093] Specifically, the constraints corresponding to the current node are solved to determine the variable range information and pointer alias information. Variable range information refers to the value range or constraints associated with the variable. Pointer alias information refers to which pointers in the program may point to the same memory location. In simple terms, pointer alias means that different pointer variables point to the same memory area.
[0094] For example, interval information calculation is performed on the constraint conditions to obtain variable range information, and alias information calculation is performed on the constraint conditions to obtain pointer alias information.
[0095] There are three main methods for solving variable range information: polyhedron analysis, octahedron analysis, and interval analysis. Polyhedron analysis can accurately express the constraint relationship between multiple variables, with high accuracy, high time and space consumption, and poor practicality. Octahedron analysis is a compromise between interval analysis and polyhedron analysis. Compared with polyhedron, it has certain restrictions on the number of variables and coefficients expressed in the constraint expression, resulting in reduced accuracy, but the algorithm efficiency is at the cubic level, and it can be used to analyze larger projects. Interval analysis can only calculate the range of a single variable. The solved range is larger than the actual range. It is a conservative calculation of the variable value and has a high false alarm rate.
[0096] In terms of accuracy, polyhedron analysis is better than octahedron analysis, which is better than interval analysis; in terms of efficiency, interval analysis is better than octahedron analysis, which is better than polyhedron analysis.
[0097] For the calculation of pointer alias information, algorithms such as Choit, Andersen, Burke and Steensgaardi can be used. Among them, Steensgaardi is a flow-insensitive and context-insensitive analysis algorithm. Heap objects are simply represented by allocation addresses, and composite type objects are represented as a whole by an object, without iterative calculation. An alias relationship set is calculated for the entire program, making full use of a fast merge search data structure (union-find set) to represent the alias relationship, with an amortized linear complexity relative to the program size. It assumes that the alias relationship is reflexive and transitive, and no iteration is performed because the merge operation is used.
[0098] The open source operator SMTInterpol can be used to determine whether the constraint condition (constraint expression) is satisfied. If satisfied, there is no buffer overflow vulnerability in the program to be tested. If not satisfied, there is a buffer overflow vulnerability in the program to be tested.<VEN,Type,VONS,Slice> , determine the category information and path information of the buffer overflow vulnerability. Category information refers to the type of buffer overflow vulnerability, which is obtained through Type in the quadruple. Path information refers to the statement code location in the program, which can be obtained through VEN, VONS, and Slice in the quadruple.
[0099] The category information and path information can be displayed to the user as the buffer overflow vulnerability detection result of the program to be detected. When the user views a line number on the path information, the system can correctly jump to the program statement corresponding to the line number, making it easier for the user to understand the vulnerability information.
[0100] The buffer overflow vulnerability decision-making method based on the extended value flow graph provided in the embodiment of the present invention determines the buffer overflow vulnerability detection result of the program to be detected according to the solution result of the constraint condition, thereby improving the detection efficiency of the buffer overflow vulnerability and facilitating user viewing and understanding.
[0101] In some embodiments, solving the constraint conditions corresponding to the current node and determining the variable range information and pointer alias information corresponding to the constraint conditions include: Determine the first interval set and the second interval set corresponding to the current node; the first interval set is the interval set where the variable may exist; the second interval set is the interval set where the variable must exist; Determine interval information of variables flowing into the current node and interval information of variables flowing out of the current node based on the first interval set and the second interval set; Based on the interval information of the variables flowing into the current node and the interval information of the variables flowing out of the current node, the variable range information corresponding to the constraint condition is determined.
[0102] Specifically, the embodiment of the present invention provides a new interval information calculation for obtaining variable range information. Take the following program code as an example: / / a:[2,9]; b:[4,6] if(a<=b)c=a+1;else c=b*2; Using only one interval set cannot describe the range information of variables in the actual program in more detail. For the above program, assuming that before the if statement in line 2 of the program, the range of a is [2,9] and the range of b is [4,6], it is impossible to determine whether the condition of the if statement in line 2 of the program is true or false. Therefore, the range information of the variables involved in lines 3 and 5 of the program cannot be described.
[0103] The embodiment of the present invention uses MayMustIS (May Must Interval Set) to describe the value range information of the variable. MayMustIS is a data structure used to describe the value range information of the variable. The structure consists of two members: the first interval set (May Interval Set, MayIS) is the interval set where the variable may exist; the second interval set (Must IntervalSet, MustIS) is the interval set where the variable must exist.
[0104] Assume that the constraint expression C There are n variables involved, namely Then for the variable : .
[0105] .
[0106] Represents the variables before calculation of , Represents the variables before calculation of , Represents the constraint expression C satisfy.
[0107] Reanalyzing the above program, the condition to reach line 3 of the program is a<=b, and line 3 of the program only requires the range information of a, not the range information of b. Solving the MustIS of a in the third row is equivalent to solving the problem of a<=b when a is a certain value, no matter what value b takes. It can be found that when a∈[2,4], the inequality holds for any b∈[4,6], so the MustIS of a in the third row is [2,4]; Solving the MayIS of a in the third row is equivalent to solving the problem of a<=b when b takes a certain value in [4,6], and it can be found that when a∈(6,9], the inequality a<=b cannot hold for any b∈[4,6], so the MayIS of a in the third row is [2,6]; then the MayIS of c in the third row is: [3,7]; MustIS: [3,5]; similarly, the MayIS of b in the fifth row is: [4,6]; MustIS: ; MayIS of c in row 5: [8,12]; MustIS: , which describes the value range information of the variable in more detail.
[0108] The embodiment of the present invention constructs two structures for nodes in the extended value flow graph to reflect the interval information of each extended value flow graph node: inVISMap<Var, MayMustIS> , outVISMap<Var,Location, MayMustIS> .
[0109] inVISMap represents the interval information of the variables flowing into the current node, where Var represents the name of the variable. For each given var, its MayMustIS can be obtained; outVISMap represents the interval information of the variables flowing out of the current node, where Location represents the position of the variable, and takes a value in {Left, Right}. The introduction of Location is mainly for the case where a variable appears on both the left and right sides of the equation. Left represents the variable var on the left side of the equation, and Right represents the variable var on the left side of the equation. For each given pair<var,loc> The interval information MayMustIS corresponding to the variable can be uniquely determined.
[0110] Figure 5 This is the second schematic diagram of the extended value flow graph provided by the present invention, such as Figure 5 As shown, the inVISMap of node n3 is { <a, >, <b, >}, outVISMap is { <a,Left, >, <a,Right >, <b,Right >}.
[0111] ; ; ; ; .
[0112] According to the interval information of the variables flowing into the current node and the interval information of the variables flowing out of the current node, the variable range information corresponding to the constraint condition is determined. This process is mainly realized by the calculation of the aggregation function and the conversion function.
[0113] Figure 6 It is a schematic diagram of the inter-node interval information dependency relationship provided by the present invention, such as Figure 6 As shown, the aggregation function calculation formula can be expressed as: in, is the current node, is the predecessor node, is the number of nodes, It is the interval information of the guard condition. In the extended value flow graph, there is a dependency relationship between any node and its predecessor node. The guard condition is the attribute of the dependency relationship. The guard condition includes the relationship between the variables contained in the node and its predecessor node from definition to use, the relationship between the array from definition to use of its array elements, etc. The condition that the value dependency information of the predecessor node can be transmitted to the node is that the guard condition is satisfied.
[0114] The conversion function calculation formula can be expressed as: in, is the conversion function.
[0115] Figure 7 It is a schematic diagram of the node interval information calculation process provided by the present invention, such as Figure 7 As shown, the process includes: Step 1: Use the aggregation function calculation formula to calculate the interval information flowing into the node .
[0116] Step 2: Then judge Is it empty (null): If the interval information flowing into the node is empty, it means that no variable interval information flows into the node, that is, the node is unreachable, and the interval information of the node is set to empty; Step 3: If the interval information flowing into the node is not empty, further determine whether the node is included in the predecessor node of the node, that is, whether the node has a self-loop.
[0117] Step 4: If the node is not included in the predecessor node of the node, that is, the node does not have a self-loop, then the interval information of the node is obtained according to the interval information flowing into the node and the type of the node.
[0118] Step 5: If the node is included in the predecessor node of the node, that is, the node has a self-loop, then the node and the guard condition of the self-loop are taken as a module.
[0119] Step 6: Further determine whether it is a simple loop. If it is a simple loop, simulate the loop execution and set the execution result to .
[0120] Step 7: If it is not a simple loop, first use the conversion function calculation formula to obtain the temporary interval information (tempoutVISMap) of the node based on the interval information flowing into the node and the type of the node, and then intersect it with the interval information (Map) corresponding to the condition for jumping out of the loop to ensure conservatism.
[0121] The buffer overflow vulnerability decision-making method based on the extended value flow graph provided by the embodiment of the present invention uses a set of intervals where the variable may exist and a set of intervals where the variable must exist to describe the value range information of the variable, which is more precise than using only one interval set to describe the value range information of the variable.
[0122] In some embodiments, the process of solving the alias information of the pointer involved in the constraint condition is as follows: Due to the flexibility of array and pointer conversion in C language, buffer overflow (ITERATOR_BOV) caused by pointer iteration often occurs. Therefore, an alias pointer equivalence class (peClass) is established for each pointer or array. All elements in the equivalence class point to the same memory space. Accessing any element in the equivalence class is equivalent to accessing all elements in the equivalence class. Then, the alias analysis Steensgaard algorithm is implemented on this basis.
[0123] The construction algorithm of the pointer equivalence class is as follows: Line 1 pointerSet ← getPointersInAnalysisNode(thisNode); Line 2 For each p ∈ pointerSet Line 3 p.peClass ← { p}; Line 4 updatePEC(thisNode,p.peClass); Line 5 worklist ← {thisNode}; Line 6 do Line 7 worklist ← worklist - {node}; Line 8 For each node ∈ {node.preds ∪ node.succs} do Line 9 updatePEC (node, p. peClass); Line 10: worklist ← worklist ∪ { node}; Line 11 End Line 12 While worklist ≠ Line 13 End In line 1, find the pointers involved in the current analysis node thisNode and store them as a pointer set pointerSet, then execute the algorithm from lines 3 to 13 for each pointer p in pointerSet; in line 3, initialize the pointer equivalence class peClass of p to {p}; in line 4, add all the alias pointers of p in the current node to the pointer equivalence class peClass of p through the updatePEC method; in line 5, initialize the worklist to {thisNode}; execute the algorithm from lines 6 to 13 until the worklist is empty: pop the top node node from the worklist, use the updatePEC method to process the popped node node to update the pointer equivalence class, and add all the predecessor and successor nodes of node to the worklist. The updatePEC algorithm is as follows: Line 1 For each q ϵ p. peClass Line 2If r=q or q= r existIn node then Line 3 p.peClass ← p.peClass ∪ {r} Line 4ElseIf r=*q or *q= r or q=&r existIn node then Line 5 p.peClass ← p.peClass ∪ {&r} Line 6ElseIf r=&q or q= *r or *r= q existIn node then Line 7 p.peClass ← p.peClass ∪ {*r} Line 8 End Line 9 End The following describes a system provided by an embodiment of the present invention. The system described below and the method described above can be referenced to each other.
[0124] Figure 8 It is one of the structural schematic diagrams of the buffer overflow vulnerability decision-making system based on the extended value flow graph provided by the present invention, such as Figure 8 As shown, the system includes: An extended value flow graph determining unit 810 is used to analyze the abstract syntax tree corresponding to the program to be detected and determine the extended value flow graph corresponding to the program to be detected; The vulnerable node extraction unit 820 is used to traverse each node in the extended value flow graph to determine the vulnerable node corresponding to the program to be detected; the vulnerable node is a node where a buffer overflow vulnerability may occur; The constraint condition generating unit 830 is used to determine the constraint condition corresponding to the vulnerable node; the constraint condition is used to ensure that the vulnerable node does not overflow the buffer; The vulnerability information detection unit 840 is used to determine the buffer overflow vulnerability detection result of the program to be detected based on the solution result of the constraint condition.
[0125] The buffer overflow vulnerability decision-making and determination system based on the extended value flow graph provided by the embodiment of the present invention analyzes the abstract syntax tree corresponding to the program to be detected to determine the extended value flow graph corresponding to the program to be detected; traverses each node in the extended value flow graph to determine the vulnerable node corresponding to the program to be detected; the vulnerable node is a node where a buffer overflow vulnerability may occur; determines the constraint condition corresponding to the vulnerable node; the constraint condition is used to ensure that the vulnerable node does not have a buffer overflow; based on the solution result of the constraint condition, determines the buffer overflow vulnerability detection result of the program to be detected; due to the use of a static detection method, the extended value flow graph that can fully reflect the dependency relationship between variables, especially pointers, is analyzed to determine the vulnerable node, and the buffer overflow vulnerability detection result is determined according to the solution of the constraint condition corresponding to the vulnerable node, so that the vulnerability can be discovered earlier and more detailed vulnerability information can be given, thereby improving the detection accuracy of the buffer overflow vulnerability; since only the vulnerable node is analyzed, the analysis of the node irrelevant to the vulnerability is avoided, thereby improving the detection efficiency of the buffer overflow vulnerability.
[0126] Taking vulnerability detection of C language programs as an example, a buffer overflow vulnerability decision-making system with human-computer interaction is designed.
[0127] Fig. 9 This is the second structural diagram of the buffer overflow vulnerability decision-making system based on the extended value flow graph provided by the present invention, such as Fig. 9 As shown, the system includes a user interaction module 910 , a vulnerable node extraction module 920 , a constraint generation module 930 , a constraint solving module 940 and a vulnerability information reporting module 950 .
[0128] From the perspective of the sorting process, the user interaction module obtains the C language program or project to be tested based on the user's input, and then the vulnerable node extraction module finds the vulnerable nodes that may have buffer overflow vulnerabilities. Next, the constraint generation module generates different constraints for different vulnerable nodes, and then the constraint solution module determines whether the constraint is satisfied. If it is not satisfied, the vulnerability category information and path information are handed over to the user interaction module through the vulnerability information reporting module to display to the user. The following is an introduction one by one.
[0129] 1. User Interaction Module The user interaction module is mainly used for user interaction, receiving user input requests, and outputting test results to users. This module mainly implements three functions: login function, project and file management function, and user management function.
[0130] The login function means that users can log in to the system using their username and password. To implement the login function, the following three sub-functions must be implemented: input processing (receiving user input and determining whether the user input complies with the specifications, such as the username must start with a letter and cannot start with an underscore or a number), background query (query the background database to see if the user exists and determine whether the entered password is correct), and interface jump (if the user exists in the database and the entered password is correct, jump to the user interface).
[0131] The project and file management function refers to the management of the projects and files to be tested, which consists of three sub-functions: project management, file management, and project and file information configuration. Project management: users can create new projects to be tested, import existing projects, and delete projects that are no longer used in the system main interface; file management: users can add, delete, modify, and check files in existing projects; users can set the type of compiler such as GCC (GNU Compiler Collection) or MingGW (GCC ported to Windows).
[0132] User management refers to the management of different users. Users are divided into two categories, one is ordinary users and the other is system administrators. Ordinary users only have login permissions, project and file management permissions, test result viewing permissions, and result export permissions. In addition to the above four permissions, administrators also have user management permissions, such as modifying user information, deleting users, adding users, etc. 2. Vulnerable Node Extraction Module The user interaction module passes the C program to be detected to the vulnerable node extraction module, which analyzes the program to generate the corresponding vulnerable node set and passes it to the constraint generation module for analysis. The vulnerable node extraction module is mainly composed of three components: preprocessor, basic analyzer, and vulnerable node generator.
[0133] The function of the preprocessor is to convert the input C source program into an abstract syntax tree. The CDT (C / C++ Development Tooling) framework of the Eclipse development platform is used in the analysis process, which can smoothly generate an abstract syntax tree even if the C program fails to compile.
[0134] The basic analyzer takes the abstract syntax tree output by the preprocessor as input, performs control flow analysis, function call relationship analysis, data flow analysis, and value flow analysis on the program, and generates corresponding control flow graphs, function call graphs, definition use chains, and value flow graphs. The value flow graph with only one dependency is expanded to generate an extended value flow graph with four dependencies.
[0135] The vulnerable node generator analyzes the extended value flow graph output by the basic analyzer to find the nodes where buffer overflow vulnerabilities may occur, and generates a vulnerable node set, which is handed over to the constraint generation module for processing.
[0136] 3. Constraint Generation Module The function of the constraint generation module is to generate a constraint condition based on the input vulnerability node quadruple.<VEN,Type,VONS,Slice> Generate the corresponding constraint. The constraint generation module is mainly composed of two components. First, the security policy generator combines the Type in the vulnerability node quadruple to generate the corresponding security policy SP, and then the constraint generator combines the VEN node and SP to generate the corresponding constraint C (Constraint).
[0137] 4. Constraint Solving Module The function of the constraint solving module is to generate corresponding constraints (Constraint) and vulnerable node quads according to the input. The interval information calculator is used to obtain the range information of the variables involved in the constraints, and the alias information calculator is used to obtain the alias information of the pointers involved in the constraints. Then, the open source operator SMTInterpol is used to determine whether the constraint expression is satisfied. If it is not satisfied, the quad and its corresponding SP and Constraint are passed to the vulnerability information reporting module to feedback to the user.
[0138] The interval information calculator has two main calculation units: the aggregation function calculation unit and the conversion function calculation unit. The alias information calculator is used to solve the pointers involved in the constraint conditions.
[0139] V. Vulnerability Information Reporting Module If the constraint condition solving module determines that the constraint condition cannot be satisfied, the incoming vulnerable node quadruple is considered to be a node where a buffer overflow may occur, and the vulnerability information must be reported to the user. The vulnerability information reporting module is the module that performs this function. This module mainly has two components: the result displayer and the detection result exporter.
[0140] The main function of the result displayer is to display the category information and path information of the buffer overflow vulnerability to the user. The main function of the detection result exporter is to export the detailed information of the buffer overflow vulnerability from the web page to the user's local computer in the form of an Excel table.
[0141] Compared with the static code analyzer (Klocwork) in the related art: (1) The false alarm rate of Klocwork is about 4.2%, and the false alarm rate of the buffer overflow vulnerability decision-making system provided by the embodiment of the present invention is about 4.0%; (2) The running speed of Klocwork is about 221 lines / second, and the running speed of the buffer overflow vulnerability decision-making system provided by the embodiment of the present invention is about 742 lines / second.
[0142] From the above comparison, it can be seen that the buffer overflow vulnerability decision-making and determination system provided by the embodiment of the present invention has higher detection accuracy and higher detection efficiency.
[0143] Fig.10 is a schematic diagram of the structure of the electronic device provided by the present invention, such as Fig.10As shown, the electronic device may include: a processor (Processor) 1010, a communication interface (Communications Interface) 1020, a memory (Memory) 1030 and a communication bus (Communications Bus) 1040, wherein the processor 1010, the communication interface 1020, and the memory 1030 communicate with each other through the communication bus 1040. The processor 1010 may call the logic command in the memory 1030 to execute the method described in the above embodiment, for example: Analyze the abstract syntax tree corresponding to the program to be tested to determine the extended value flow graph corresponding to the program to be tested; traverse each node in the extended value flow graph to determine the vulnerable node corresponding to the program to be tested; the vulnerable node is a node where a buffer overflow vulnerability may occur; determine the constraint conditions corresponding to the vulnerable node; the constraint conditions are used to ensure that the vulnerable node does not have a buffer overflow; based on the solution results of the constraint conditions, determine the buffer overflow vulnerability detection result of the program to be tested.
[0144] In addition, the logic commands in the above-mentioned memory can be implemented in the form of software functional units and can be stored in a computer-readable storage medium when sold or used as an independent product. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product, which is stored in a storage medium and includes several commands to enable a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present invention. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), disk or optical disk, etc., which can store program code.
[0145] The processor in the electronic device provided in the embodiment of the present invention can call the logic instructions in the memory to implement the above method. Its specific implementation method is consistent with the implementation method of the aforementioned method and can achieve the same beneficial effects, which will not be repeated here.
[0146] An embodiment of the present invention further provides a computer-readable storage medium on which a computer program is stored. When the computer program is executed by a processor, the method provided in the above embodiments is implemented.
[0147] Its specific implementation is consistent with the aforementioned method implementation and can achieve the same beneficial effects, so it will not be repeated here.
[0148] An embodiment of the present invention provides a computer program product, including a computer program. When the computer program is executed by a processor, the method described above is implemented.
[0149] The device embodiments described above are merely illustrative, wherein the units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place, or they may be distributed on multiple network units. Some or all of the modules may be selected according to actual needs to achieve the purpose of the scheme of this embodiment. Ordinary technicians in this field can understand and implement it without paying creative labor.
[0150] Through the description of the above implementation methods, those skilled in the art can clearly understand that each implementation method can be implemented by means of software plus a necessary general hardware platform, and of course, can also be implemented by hardware. Based on this understanding, the above technical solution is essentially or the part that contributes to the prior art can be embodied in the form of a software product, and the computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, a disk, an optical disk, etc., including a number of instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.
[0151] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A buffer overflow vulnerability decision-making method based on an extended value flow graph, characterized in that: include: Analyze the abstract syntax tree corresponding to the program to be detected, and determine the extended value flow graph corresponding to the program to be detected; Traversing each node in the extended value flow graph to determine a vulnerable node corresponding to the program to be detected; the vulnerable node is a node where a buffer overflow vulnerability may occur; Determining a constraint condition corresponding to the vulnerable node; the constraint condition is used to ensure that the vulnerable node does not have a buffer overflow; Based on the solution result of the constraint condition, a buffer overflow vulnerability detection result of the program to be detected is determined.
2. The buffer overflow vulnerability decision-making method based on the extended value flow graph according to claim 1 is characterized in that: The analyzing the abstract syntax tree corresponding to the program to be detected to determine the extended value flow graph corresponding to the program to be detected includes: Determine an abstract syntax tree corresponding to the program to be detected; Performing value flow analysis on the abstract syntax tree to determine entry dependency, flow dependency, pointer dereference dependency and address fetch dependency corresponding to the program to be detected; Determine an extended value flow graph corresponding to the program to be detected based on the entry dependency, the flow dependency, the pointer dereference dependency and the address fetch dependency; Among them, the entry dependency refers to the dependency from the program entry node to the variable declaration node; the flow dependency refers to the dependency from the variable definition node to the variable direct use node; the pointer dereference dependency refers to the dependency from the variable definition node to the node that dereferences the variable; the address dependency refers to the dependency from the variable definition node to the node that performs address operations on the variable.
3. The buffer overflow vulnerability decision-making method based on the extended value flow graph according to claim 1 is characterized in that: The traversing each node in the extended value flow graph to determine the vulnerability node corresponding to the program to be detected includes: Determining that a current node in the extended value flow graph is a vulnerable node; Generate a vulnerable node quadruple corresponding to the current node based on the current node, the buffer overflow vulnerability type corresponding to the current node, the vulnerability root node set and the extended value flow graph slice; The extended value flow graph slice is an extended value flow graph from each node in the vulnerability root node set to the current node.
4. The buffer overflow vulnerability decision-making method based on the extended value flow graph according to claim 1 is characterized in that: The determining of the constraint conditions corresponding to the vulnerable nodes includes: Based on the vulnerable node quadruple corresponding to the current node, determine the buffer overflow vulnerability type corresponding to the current node; Based on the buffer overflow vulnerability type corresponding to the current node, determine the security policy corresponding to the current node; the security policy is a rule to be followed to ensure that there is no buffer overflow vulnerability in the program; Based on the security policy and the current node, a constraint condition corresponding to the current node is generated.
5. The buffer overflow vulnerability decision-making method based on the extended value flow graph according to claim 1 is characterized in that: The determining of the buffer overflow vulnerability detection result of the program to be detected based on the solution result of the constraint condition includes: Solve the constraint conditions corresponding to the current node, and determine the variable value range information and pointer alias information corresponding to the constraint conditions; When the constraint condition is not satisfied, determining that a buffer overflow vulnerability exists in the program to be detected; Determine the category information and path information of the buffer overflow vulnerability based on the vulnerable node quadruple corresponding to the current node; Based on the category information and path information of the buffer overflow vulnerability, a buffer overflow vulnerability detection result of the program to be detected is generated.
6. The buffer overflow vulnerability decision-making method based on the extended value flow graph according to claim 5 is characterized in that: Solving the constraint conditions corresponding to the current node and determining variable range information and pointer alias information corresponding to the constraint conditions includes: Determine a first interval set and a second interval set corresponding to the current node; the first interval set is an interval set where the variable may exist; the second interval set is an interval set where the variable must exist; Determine interval information of variables flowing into the current node and interval information of variables flowing out of the current node based on the first interval set and the second interval set; Based on the interval information of the variables flowing into the current node and the interval information of the variables flowing out of the current node, the variable range information corresponding to the constraint condition is determined.
7. The buffer overflow vulnerability decision determination method based on the extended value flow graph according to any one of claims 1 to 6, characterized in that: Buffer overflow vulnerability types include buffer overflow caused by formatted strings, buffer overflow caused by data copying, buffer overflow caused by memory initialization, buffer overflow caused by external input, buffer overflow caused by pointer iteration, and buffer overflow caused by array subscript out of bounds.
8. A buffer overflow vulnerability decision-making system based on an extended value flow graph, characterized in that: include: An extended value flow graph determination unit, used to analyze an abstract syntax tree corresponding to a program to be detected, and determine an extended value flow graph corresponding to the program to be detected; A vulnerable node extraction unit, used to traverse each node in the extended value flow graph to determine the vulnerable node corresponding to the program to be detected; the vulnerable node is a node where a buffer overflow vulnerability may occur; A constraint condition generating unit, used for determining the constraint condition corresponding to the vulnerable node; the constraint condition is used for ensuring that the vulnerable node does not have a buffer overflow; The vulnerability information detection unit is used to determine the buffer overflow vulnerability detection result of the program to be detected based on the solution result of the constraint condition.
9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the computer program, the buffer overflow vulnerability decision-making and determination method based on the extended value flow graph described in any one of claims 1 to 7 is implemented.
10. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the buffer overflow vulnerability decision-making and determination method based on the extended value flow graph described in any one of claims 1 to 7 is implemented.
Citation Information
Cited By
Method and device for generating hybrid vulnerability variant descriptor
KR102989013B1
Method and device for generating hybrid vulnerability variant descriptor
KR102989097B1