Control flow integrity detection method and device, electronic equipment and storage medium

By storing the address and hash value of each function in the target mapping table and matching hash value when performing forward jump, the problem of difficulty in detecting and protecting program control flow integrity in the prior art is solved, and a high-security control flow integrity detection is achieved.

CN119989367APending Publication Date: 2025-05-13BEIJING X RING TECHNOLOGY CO LTD
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202510128860.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-27
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

The prior art is difficult to effectively detect and protect the integrity of the control flow of programs, resulting in the system being vulnerable to control flow hijacking attacks.

Method used

The legality of the jump is determined by storing the address and hash value of each function in the target mapping table, and when performing the forward jump, matching the hash value corresponding to the target address and the hash value generated at compile time.

Benefits of technology

While achieving accurate detection of control flow integrity, the code can be stored in executable memory, which improves the security of running code and further improves the system security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119989367A_ABST
    Figure CN119989367A_ABST
Patent Text Reader

Abstract

The invention provides a control flow integrity detection method and device, electronic equipment and a storage medium, and relates to the technical field of operating system kernel security. Comprising the following steps: in response to an obtained forward jump target address, traversing a target mapping table based on the target address, and obtaining a first hash value corresponding to the target address; obtaining a second hash value corresponding to the target address generated during code compiling; and determining whether the forward jump is legal based on whether the first hash value is matched with the second hash value. Therefore, the address and the Hash value corresponding to each function in the software are stored in the mapping table, and when each forward jump is executed, the Hash value corresponding to the jump target address in the mapping table is matched with the expected Hash value, so that the integrity of the control flow can be accurately detected, and meanwhile, the integrity of the control flow can be accurately detected. Therefore, the code can be stored in the only executable memory, the security of running the code is improved, and the system security is further improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of operating system kernel security technology, and in particular to a control flow integrity detection method, device, electronic device and storage medium. Background Art

[0002] Control flow hijacking is a very harmful attack method that allows attackers to gain control of the target machine, or even perform privilege escalation operations to fully control the target machine. Control flow integrity (CFI) is a technology used to protect programs from control flow attacks. It prevents the injection and execution of malicious code by limiting the control flow during program execution.

[0003] Therefore, how to detect control flow integrity has become an important research direction. Summary of the invention

[0004] The present disclosure aims to solve one of the technical problems in the related art at least to some extent.

[0005] The first embodiment of the present disclosure provides a control flow integrity detection method, including:

[0006] In response to obtaining a target address of the forward jump, traversing a target mapping table based on the target address to obtain a first hash value corresponding to the target address, wherein the target mapping table includes a plurality of mutually related addresses and hash values;

[0007] Obtain a second hash value corresponding to the target address generated when the code is compiled;

[0008] Whether the forward jump is legal is determined based on whether the first hash value matches the second hash value.

[0009] The second aspect of the present disclosure provides a control flow integrity detection device, including:

[0010] A first acquisition module, configured to, in response to acquiring a target address of a forward jump, traverse a target mapping table based on the target address to acquire a first hash value corresponding to the target address, wherein the target mapping table includes a plurality of mutually related addresses and hash values;

[0011] A second acquisition module, used to acquire a second hash value corresponding to the target address generated when the code is compiled;

[0012] A determination module is used to determine whether the forward jump is legal based on whether the first Hash value matches the second Hash value.

[0013] The third aspect embodiment of the present disclosure proposes an electronic device, comprising: a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the program, the control flow integrity detection method proposed in the first aspect embodiment of the present disclosure is implemented.

[0014] The fourth aspect embodiment of the present disclosure proposes a computer-readable storage medium storing a computer program. When the computer program is executed by a processor, the control flow integrity detection method proposed in the first aspect embodiment of the present disclosure is implemented.

[0015] The fifth aspect of the present disclosure provides a computer program product, including a computer program, which, when executed by a processor, implements the control flow integrity detection method proposed in the first aspect of the present disclosure.

[0016] The sixth aspect embodiment of the present disclosure provides a chip, including a processing unit and an interface circuit, wherein the processing unit obtains program instructions through the interface circuit, and the program instructions are executed by the processing unit, and the processing unit is used to execute the control flow integrity detection method proposed in the first aspect embodiment of the present disclosure.

[0017] The control flow integrity detection method, device, electronic device and storage medium provided by the present disclosure have the following beneficial effects:

[0018] In the disclosed embodiment, in response to obtaining the target address of the forward jump, the target mapping table can be traversed based on the target address to obtain the first hash value corresponding to the target address, obtain the second hash value corresponding to the target address generated when the code is compiled, and finally determine whether the forward jump is legal based on whether the first hash value matches the second hash value. Thus, the address and hash value corresponding to each function in the software are stored in the mapping table, and when each forward jump is executed, the hash value corresponding to the target address of the jump in the mapping table is matched with the expected hash value, so that the code can be stored in the executable memory while accurately detecting the integrity of the control flow, thereby improving the security of running the code and further improving the security of the system.

[0019] Additional aspects and advantages of the present disclosure will be given in part in the following description and in part will be obvious from the following description or learned through practice of the present disclosure. BRIEF DESCRIPTION OF THE DRAWINGS

[0020] The above and / or additional aspects and advantages of the present disclosure will become apparent and easily understood from the following description of the embodiments in conjunction with the accompanying drawings, in which:

[0021] Figure 1A flow chart of a control flow integrity detection method provided by an embodiment of the present disclosure;

[0022] Figure 2 A flow chart of a control flow integrity detection method provided by another embodiment of the present disclosure;

[0023] Figure 3 A flow chart of a control flow integrity detection method provided by another embodiment of the present disclosure;

[0024] Figure 4 A schematic diagram of the structure of a control flow integrity detection device provided by another embodiment of the present disclosure;

[0025] Figure 5 A block diagram of an exemplary electronic device suitable for implementing the embodiments of the present disclosure is shown;

[0026] Figure 6 It is a schematic diagram of the structure of a chip proposed in an embodiment of the present disclosure. DETAILED DESCRIPTION

[0027] Some embodiments of the present disclosure will be described in detail here, and examples thereof are shown in the accompanying drawings. When the following description refers to the drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. Various changes, modifications and equivalents of the methods, devices and / or systems described herein will become apparent after understanding the present disclosure. For example, the order of operations described herein is merely an example and is not limited to those orders set forth herein, but can be changed as becomes apparent after understanding the present disclosure, except for operations that must be performed in a specific order. In addition, for clarity and brevity, descriptions of features known in the art may be omitted.

[0028] The embodiments described in some embodiments of the present disclosure below do not represent all embodiments consistent with the present disclosure. Instead, they are merely examples of devices and methods consistent with some aspects of the present disclosure as detailed in the appended claims.

[0029] In the related art, there is a 32-bit value before the entry point of each function, which represents the prototype of the function. This value is a hash value calculated by the compiler based on the function prototype (function name, parameters and type). When the program makes an indirect call, it reads the hash value from the entry point code of the function and matches the hash value with the expected hash value hard-coded in the program during compilation. If the match is successful, the original call will continue; if it does not match, the execution of the program will be interrupted. This protects the integrity of the control flow.

[0030] However, since the hash value needs to be read from the code at the entry point of the function, the code cannot be stored in Execute Only Memory (XOM), which reduces security.

[0031] Therefore, in the disclosed embodiment, the address and hash value corresponding to each function in the software are stored in the mapping table, so that when each forward jump is executed, the hash value corresponding to the jump target address in the mapping table can be matched with the expected hash value, so that the control flow integrity can be accurately detected while the code can be stored in the executable memory, which improves the security of running the code and further improves the system security.

[0032] The following describes the control flow integrity detection method, device, electronic device and storage medium of the embodiments of the present disclosure with reference to the accompanying drawings.

[0033] Figure 1 A flow chart of a control flow integrity detection method provided in an embodiment of the present disclosure.

[0034] The embodiment of the present disclosure takes the control flow integrity detection method being configured in a control flow integrity detection device as an example. The control flow integrity detection device can be applied to any electronic device or chip so that the electronic device or chip can perform the control flow integrity detection function.

[0035] like Figure 1 As shown, the control flow integrity detection method may include the following steps:

[0036] Step 101, in response to obtaining a target address of a forward jump, traverse a target mapping table based on the target address to obtain a first hash value corresponding to the target address.

[0037] Among them, forward jump refers to the process in which the instruction stream jumps from the current position forward (i.e., the direction of increasing memory address) to another position to continue execution during program execution. The "forward" here is relative to the current execution position of the program. In assembly language and low-level programming languages, forward jump is usually implemented through specific jump instructions.

[0038] The target address of the forward jump is the memory address of the next instruction to be executed in the currently running software after the current forward jump instruction jumps. The currently running software may be an application, a driver, a library file, etc. This disclosure does not limit this.

[0039] In some embodiments, the target address may be directly given in the forward jump instruction, or the forward jump instruction may give an offset relative to the current forward jump instruction address, and then the target address is calculated based on the offset and the current forward jump instruction address.

[0040] The target mapping table includes a plurality of interrelated addresses and hash values. In some embodiments, the target mapping table includes the function address and hash value corresponding to each function in the currently running software. The hash value may also be referred to as a function signature value. The function signature value may be a hash value calculated based on the function prototype (function name, parameters, type, etc.).

[0041] In some embodiments, when the compiler compiles the image corresponding to the currently running software, a target mapping table can be generated according to the function address and function signature value of each function. Thus, during the software running process, if the target address of the forward jump is obtained, the target mapping table can be traversed based on the target address to obtain the first hash value corresponding to the target address.

[0042] In some embodiments, the file format of the target mapping table may be "*.cfit". Taking the kernel image file (kernel.img) of the Linux operating system as an example, the kernel.cfit format may be as shown in Table 1:

[0043] Table 1

[0044] Addr(address) Sig (hash value) 0xffff0000 0x5a5a5a5a 0xffff8000 0xa5a5a5a5 ... ...

[0045] Step 102: Obtain a second hash value corresponding to the target address generated when the code is compiled.

[0046] In some embodiments, when the code is compiled, a hash calculation is performed on each function prototype (including function name, parameters and type) in the software to obtain a hash value, which is hard-coded in the program corresponding to the software. Thus, during the execution of the software program, a second hash value corresponding to the function at the target address can be obtained from the currently running program.

[0047] Step 103: Determine whether the forward jump is legal based on whether the first hash value matches the second hash value.

[0048] In some embodiments, if the first hash value matches the second hash value, the forward jump is determined to be legal.

[0049] It should be noted that, when the first hash value matches the second hash value, it means that the current target address is the correct jump address, and the forward jump is determined to be legal, and then the jump can be made to the target address to continue execution.

[0050] In some embodiments, if the first hash value does not match the second hash value, the forward jump is determined to be illegal.

[0051] It should be noted that when the first hash value does not match the second hash value, it means that the current target address may be maliciously tampered with. If a jump is performed based on the target address, the attacker may take away control. Therefore, it is determined that the forward jump is illegal, and the execution of the program can be interrupted, or an error is reported and the exception handling process is entered.

[0052] In the disclosed embodiment, in response to obtaining the target address of the forward jump, the target mapping table can be traversed based on the target address to obtain the second hash value corresponding to the target address generated when the code is compiled, and the second hash value generated when the code is compiled is obtained. Finally, based on whether the first hash value matches the second hash value, it is determined whether the forward jump is legal. Thus, the address and hash value corresponding to each function in the software are stored in the mapping table, and when each forward jump is executed, the hash value corresponding to the target address of the jump in the mapping table is matched with the expected hash value, so that the code can be stored in the executable memory while accurately detecting the integrity of the control flow, thereby improving the security of running the code and further improving the security of the system.

[0053] Figure 2 A flow chart of a control flow integrity detection method provided by an embodiment of the present disclosure is shown as follows: Figure 2 As shown, the control flow integrity detection method may include the following steps:

[0054] Step 201, in response to obtaining a target address of a forward jump, obtaining a target mapping table based on a base address in a first register.

[0055] The target mapping table includes a plurality of interrelated addresses and hash values.

[0056] The first register area stores the target mapping table corresponding to the currently running software and the base address in the memory, so that the storage address of the target mapping table can be determined based on the base address in the first register to obtain the target mapping table.

[0057] In some embodiments, the first register stores only one base address, ie, the base address of the target mapping table corresponding to the currently running software.

[0058] In some embodiments, the first register may also be referred to as a Control Flow Integrity Table Base Register (CFITBR).

[0059] In some embodiments, the first register may be an 8-bit register, a 16-bit register, a 32-bit register, a 64-bit register, etc. The present disclosure does not limit the size of the first register.

[0060] For example, the meaning of each field in the first register may be shown in Table 2.

[0061] Table 2

[0062]

[0063] RES0 represents a reserved bit, and its value is 0. As shown in Table 2, the 48th to 63rd bits in the first register are reserved bits.

[0064] BADDR represents the base address of the target mapping table. As shown in Table 2, the 0th to 47th bits in the first register are used to store the base address of the target mapping table.

[0065] In some embodiments, an executable and linkable format (ELF) file of the software to be run is parsed to obtain a target mapping table, the target mapping table is loaded into the system memory, the base address of the target mapping table is obtained, and the base address of the target mapping table is stored in the first register.

[0066] In some embodiments, after determining the mapping table corresponding to the software, the mapping table can be stored in the ELF file corresponding to the software. Thus, when the software to be run is loaded, the ELF file corresponding to the software to be run can be parsed to obtain the target mapping table.

[0067] The base address of the target mapping table may be the starting address of the target mapping table in the system memory.

[0068] In some embodiments, a mapping table corresponding to each software may be predetermined, and a base address in the memory, so that when any software is running, the base address corresponding to any software may be written into the first register.

[0069] In some embodiments, in order to protect the memory area occupied by the target mapping table from being maliciously modified, a memory area protection unit can be used to protect the memory area and set it as a read-only attribute. The memory area protection unit can be, for example, an ARM TrustZone Address Space Controller (TrustZone Address Space Controller, TZC) 400, etc. This disclosure does not limit this.

[0070] Step 202: traverse the target mapping table based on the target address to obtain a first hash value corresponding to the target address.

[0071] Step 203: Obtain a second hash value corresponding to the target address generated when the code is compiled.

[0072] Step 204: Determine whether the forward jump is legal based on whether the first hash value matches the second hash value.

[0073] The specific implementation forms of steps 202 to 204 can refer to the detailed descriptions in other embodiments of the present disclosure, and will not be described in detail here.

[0074] In the disclosed embodiment, in response to obtaining the target address of the forward jump, based on the base address in the first register, the target mapping table is obtained, the target mapping table is traversed based on the target address, the first hash value corresponding to the target address is obtained, the second hash value corresponding to the target address generated when the code is compiled is obtained, and whether the forward jump is legal is determined based on whether the first hash value matches the second hash value. Thus, the storage location of the target mapping table can be stored in the first register, so that when a forward jump is encountered, the target mapping table can be obtained based on the base address in the first register, so that the target mapping table can be obtained quickly and accurately, and then the code can be stored in the executable-only memory while accurately detecting the integrity of the control flow, further improving the security of running the code.

[0075] Figure 3 A flow chart of a control flow integrity detection method provided by an embodiment of the present disclosure is shown as follows: Figure 3 As shown, the control flow integrity detection method may include the following steps:

[0076] Step 301, parse the executable and linkable format ELF file of the software to be run to obtain a target mapping table.

[0077] The specific implementation form of step 301 can refer to the detailed description in other embodiments of the present disclosure, and will not be described in detail here.

[0078] Step 302: Set the value of the first information field in the second register to a first value, wherein the first value is used to indicate that the software to be run is software that requires integrity protection.

[0079] The second register may also be referred to as a control flow integrity unit enable register (CFI Unit Enable Register, CFIUENR).

[0080] In some embodiments, the second register may be an 8-bit register, a 16-bit register, a 32-bit register, a 64-bit register, etc. The present disclosure does not limit the size of the second register.

[0081] In some embodiments, if the value of the first information field is the fourth value, it indicates that the software to be run is software that does not require integrity protection.

[0082] It should be noted that the first value is different from the fourth value. For example, if the first value is 0, the fourth value is 1, and if the first value is 1, the fourth value is 0. The present disclosure does not limit the specific values ​​of the first value and the fourth value.

[0083] In some embodiments, the first information field may include one bit or multiple bits, which is not limited in the present disclosure.

[0084] In some embodiments, when the first information field includes one bit, the value of the first information field is set to the first value, indicating that the software to be run is software that needs to be integrity protected.

[0085] In some embodiments, when the first information field includes multiple bits, the target bit is determined according to the function associated with the address included in the target mapping table, and the value of the target bit is set to the first value, wherein different bits in the first information field correspond to different functions. Thus, the CFI function can be selectively turned on (or off) for the function as needed, and the performance overhead caused by CFI is minimized while ensuring the integrity of the software as much as possible.

[0086] In some embodiments, one bit may correspond to one function or multiple functions, which is not limited in the present disclosure.

[0087] In some embodiments, the first bit in the first information field corresponds to the first function in the mapping table, and the second bit corresponds to the first function in the mapping table. The present disclosure does not limit the correspondence between bits and functions.

[0088] In some embodiments, when the value of a bit is a first value, one or more functions corresponding to any bit are determined to be functions that require integrity protection. When the value of another bit is a fourth value, one or more functions corresponding to any bit are determined to be functions that do not require integrity protection.

[0089] In some embodiments, when the first information field includes multiple bits, it is also possible to determine whether the software to be run needs to be integrity protected in different time periods based on different bits.

[0090] For example, there are two bits in the first information field, the first bit corresponds to the first time period, and the second bit corresponds to the second time period. If the first bit is the first value and the second bit is the fourth value, it means that in the first time period, the software to be run is software that requires integrity protection, and in the second time period, the software to be run is software that does not require integrity protection.

[0091] In some embodiments, when a modification instruction for a first information field is received, the value of the second information field in the second register is determined, and when the value of the second information field is the second value, the value of the first information field is not modified; or, when the value of the second information field is a third value, the value of the first information field is modified to the target value indicated in the modification instruction.

[0092] In the embodiment of the present disclosure, when the second information field is the second value, it is used to indicate that the value of the first information field can be modified, and when the second information field is the third value, it is used to indicate that the value of the first information field cannot be modified.

[0093] It should be noted that the second value is different from the third value. For example, if the second value is 0, the third value is 1, and if the second value is 1, the third value is 0. The present disclosure does not limit the specific values ​​of the first value and the fourth value.

[0094] In some embodiments, the second information field may include one bit or multiple bits, which is not limited in the present disclosure.

[0095] In some embodiments, if the first information field includes multiple bits, it can be determined whether the first information field can be modified in different time periods according to different bits.

[0096] For example, there are two bits in the second information field, the first bit corresponds to the first time period, and the second bit corresponds to the second time period. If the first bit is the second value and the second bit is the third value, it means that the first information field can be modified within the first time period, and the first information field cannot be modified within the second time period.

[0097] For example, the second register may be as shown in Table 3.

[0098] Table 3

[0099]

[0100] RES0 represents a reserved bit in the second register, and its value is 0. As shown in Table 3, the 2nd to 63rd bits in the second register are reserved bits.

[0101] Wherein, LOCK represents the second information field. As shown in Table 3, the first bit in the second register is the second information field.

[0102] Wherein, EN represents the first information field. As shown in Table 3, the 0th bit in the second register is the first information field.

[0103] It should be noted that Table 3 is an example of the second register. The present disclosure does not limit the size of the second register, or the positions of the first information field and the second information field in the second register.

[0104] It should be noted that whether integrity protection is needed can be understood as, after obtaining the target address, whether it is necessary to traverse the target mapping table based on the target address, obtain the first hash value corresponding to the target address, and obtain the second hash value generated during compilation, and then match the first hash value with the second hash value to determine whether the forward jump is legal.

[0105] Step 303: load the target mapping table into the system memory to obtain the base address of the target mapping table.

[0106] Step 304: store the base address of the target mapping table into the first register.

[0107] The specific implementation forms of step 303 to step 304 can refer to the detailed descriptions in other embodiments of the present disclosure, and will not be described in detail here.

[0108] Step 305 , in response to obtaining the target address of the forward jump, traverse the mapping table based on the target address to obtain a first hash value corresponding to the target address.

[0109] The target mapping table includes a plurality of interrelated addresses and hash values.

[0110] In some embodiments, in response to obtaining the target address and the value of the first information field in the second register being the first value, the mapping table is traversed based on the target address to obtain a first hash value corresponding to the target address.

[0111] It should be noted that if the value of the first information field in the second register is the first value, it means that the running software is software that needs to be integrity protected. Then, the target mapping table can be traversed based on the target address to obtain the first hash value corresponding to the target address, and it is determined whether the first hash value matches the second hash value generated during compilation, and whether the forward jump is legal, thereby achieving integrity protection of the software.

[0112] In some embodiments, in response to obtaining the target address and the value of the target bit in the first information field being the first value, a mapping table is traversed based on the target address to obtain a first hash value corresponding to the target address.

[0113] Among them, the target bit corresponds to the function associated with the target address.

[0114] It should be noted that if the value of the target bit in the first information field is the first value, it means that the function corresponding to the target bit is a function that needs to be integrity protected. Therefore, in the embodiment of the present disclosure, when the address of the forward jump is the address corresponding to the function of the target bit, the mapping table is traversed based on the target address to obtain the first hash value corresponding to the target address, and it is determined whether the first hash value matches the second hash value generated during compilation to determine whether the forward jump is legal.

[0115] Step 306, obtaining a second hash value corresponding to the target address generated when the code is compiled.

[0116] Step 307: Determine whether the forward jump is legal based on whether the first hash value matches the second hash value.

[0117] The specific implementation forms of step 306 to step 307 can refer to the detailed descriptions in other embodiments of the present disclosure, and will not be described in detail here.

[0118] In the disclosed embodiment, after parsing the executable and linkable format ELF file of the software to be run and obtaining the target mapping table, the value of the first information field in the second register can also be set to the first value to indicate that the software to be run is software that needs integrity protection, so that when the target address of the forward jump is obtained, the target mapping table can be traversed based on the target address to obtain the first hash value corresponding to the target address, and then the first hash value is matched with the second hash value generated during compilation to determine whether the forward jump is legal. Therefore, when the software to be run is software that needs integrity protection, the control flow integrity of the software can be detected, thereby saving system overhead.

[0119] In order to implement the above embodiments, the present disclosure also proposes a control flow integrity detection device.

[0120] Figure 4 A schematic diagram of the structure of a control flow integrity detection device provided in an embodiment of the present disclosure.

[0121] like Figure 4 As shown, the control flow integrity detection device 400 may include:

[0122] A first acquisition module 401 is used for, in response to acquiring a target address of a forward jump, traversing a target mapping table based on the target address to acquire a first hash value corresponding to the target address, wherein the target mapping table includes a plurality of mutually related addresses and hash values;

[0123] The second acquisition module 402 is used to acquire a second hash value corresponding to the target address generated when the code is compiled;

[0124] The determination module 403 is used to determine whether the forward jump is legal based on whether the first hash value matches the second hash value.

[0125] In some embodiments, the first acquisition module 401 is used to:

[0126] Based on the base address in the first register, obtaining a target mapping table;

[0127] The target mapping table is traversed based on the target address to obtain a first hash value corresponding to the target address.

[0128] In some embodiments, the system further includes a first processing module for:

[0129] Parse the executable and linkable format ELF file of the software to be run to obtain the target mapping table;

[0130] Load the target mapping table into the system memory to obtain the base address of the target mapping table;

[0131] The base address of the target mapping table is stored in the first register.

[0132] In some embodiments, the system further includes a second processing module for:

[0133] The value of the first information field in the second register is set to a first value, wherein the first value is used to indicate that the software to be run is software that requires integrity protection.

[0134] In some embodiments, the second processing module is used to:

[0135] In a case where the first information field includes one bit, setting the value of the first information field to a first value;

[0136] When the first information field includes multiple bits, the target bit is determined according to the address-associated function included in the target mapping table, and the value of the target bit is set to the first value, wherein different bits in the first information field correspond to different functions.

[0137] In some embodiments, the first acquisition module 401 is used to:

[0138] In response to obtaining the target address and the value of the first information field in the second register being the first value, traversing the mapping table based on the target address to obtain a first hash value corresponding to the target address;

[0139] In response to obtaining the target address and the value of the target bit in the first information field being a first value, a mapping table is traversed based on the target address to obtain a first hash value corresponding to the target address, wherein the target bit corresponds to a function associated with the target address.

[0140] In some embodiments, a third processing module is further included, configured to:

[0141] Upon receiving a modification instruction for the first information field, determining a value of the second information field in the second register;

[0142] When the value of the second information field is the second value, the value of the first information field is not modified.

[0143] In some embodiments, the third processing module is further configured to:

[0144] When the value of the second information field is the third value, the value of the first information field is modified to the target value indicated in the modification instruction.

[0145] In some embodiments, the determination module 403 is configured to:

[0146] In the case where the first hash value matches the second hash value, determining that the forward jump is legal;

[0147] In the event that the first hash value does not match the second hash value, it is determined that the forward jump is not legal.

[0148] The functions and specific implementation principles of the above modules in the embodiments of the present disclosure can be referred to the above method embodiments, and will not be repeated here.

[0149] The control flow integrity detection device of the disclosed embodiment first responds to the acquisition of the target address of the forward jump, and can traverse the target mapping table based on the target address to obtain the first hash value corresponding to the target address, obtain the second hash value corresponding to the target address generated when the code is compiled, and finally determine whether the forward jump is legal based on whether the first hash value matches the second hash value. Thus, the address and hash value corresponding to each function in the software are stored in the mapping table, and when each forward jump is executed, the hash value corresponding to the target address of the jump in the mapping table is matched with the expected hash value, so that the control flow integrity can be accurately detected while the code can be stored in the executable memory, which improves the security of running the code and further improves the system security.

[0150] In order to implement the above embodiments, the present disclosure further proposes an electronic device, including: a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the program, the control flow integrity detection method proposed in the above embodiments of the present disclosure is implemented.

[0151] Figure 5 A block diagram of an exemplary electronic device suitable for implementing embodiments of the present disclosure is shown. Figure 5 The electronic device 12 shown is only an example and should not bring any limitation to the functions and scope of use of the embodiments of the present disclosure.

[0152] like Figure 5 As shown, the electronic device 12 is in the form of a general purpose computing device. The components of the electronic device 12 may include, but are not limited to: one or more processors or processing units 16, a system memory 28, and a bus 18 that connects various system components (including the system memory 28 and the processing unit 16).

[0153] The bus 18 represents one or more of several types of bus structures, including a memory bus or memory controller, a peripheral bus, a graphics acceleration port, a processor or a local bus using any of a variety of bus structures. For example, these architectures include but are not limited to Industry Standard Architecture (ISA) bus, Micro Channel Architecture (MAC) bus, Enhanced ISA bus, Video Electronics Standards Association (VESA) local bus and Peripheral Component Interconnection (PCI) bus.

[0154] The electronic device 12 typically includes a variety of computer system readable media. These media can be any available media that can be accessed by the electronic device 12, including volatile and non-volatile media, removable and non-removable media.

[0155] The memory 28 may include computer system readable media in the form of volatile memory, such as random access memory (RAM) 30 and / or cache memory 32. The electronic device 12 may further include other removable / non-removable, volatile / non-volatile computer system storage media. By way of example only, the storage system 34 may be used to read and write non-removable, non-volatile magnetic media ( Figure 5 not shown, usually called a "hard drive"). Although Figure 5Not shown in the figure, a disk drive for reading and writing a removable non-volatile disk (e.g., a "floppy disk"), and an optical disk drive for reading and writing a removable non-volatile optical disk (e.g., a compact disc read only memory (CD-ROM), a digital versatile disc read only memory (DVD-ROM), or other optical media) may be provided. In these cases, each drive may be connected to the bus 18 via one or more data medium interfaces. The memory 28 may include at least one program product having a set (e.g., at least one) of program modules configured to perform the functions of the various embodiments of the present disclosure.

[0156] A program / utility 40 having a set (at least one) of program modules 42 may be stored, for example, in the memory 28, such program modules 42 including but not limited to an operating system, one or more application programs, other program modules, and program data, each of which or some combination may include an implementation of a network environment. The program modules 42 generally perform the functions and / or methods of the embodiments described in the present disclosure.

[0157] The electronic device 12 may also communicate with one or more external devices 14 (e.g., keyboards, pointing devices, displays 24, etc.), may also communicate with one or more devices that enable a user to interact with the electronic device 12, and / or may communicate with any device that enables the electronic device 12 to communicate with one or more other computing devices (e.g., network cards, modems, etc.). Such communication may be performed via an input / output (I / O) interface 22. Furthermore, the electronic device 12 may also communicate with one or more networks (e.g., a local area network (LAN), a wide area network (WAN), and / or a public network, such as the Internet) via a network adapter 20. As shown, the network adapter 20 communicates with other modules of the electronic device 12 via a bus 18. It should be understood that, although not shown in the figure, other hardware and / or software modules may be used in conjunction with the electronic device 12, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems.

[0158] The processing unit 16 executes various functional applications and data processing by running programs stored in the system memory 28, such as implementing the methods mentioned in the above embodiments.

[0159] In order to implement the above embodiments, the present disclosure further proposes a computer-readable storage medium storing a computer program. When the computer program is executed by a processor, the control flow integrity detection method proposed in the above embodiments of the present disclosure is implemented.

[0160] In order to implement the above embodiments, the present disclosure further proposes a computer program product, including a computer program, which implements the control flow integrity detection method proposed in the above embodiments of the present disclosure when the computer program is executed by a processor.

[0161] Figure 6 is a schematic diagram of the structure of the chip proposed in the embodiment of the present disclosure. Figure 6 The structure of the chip 600 is shown, but is not limited to this.

[0162] The chip 600 includes a processing circuit 601 , and the processing circuit 601 is configured to execute any of the above methods.

[0163] In some embodiments, the chip 600 further includes one or more interface circuits 602. Optionally, the interface circuit 602 is connected to the memory 603, and the interface circuit 602 can be used to receive signals from the memory 603 or other devices, and the interface circuit 602 can be used to send signals to the memory 603 or other devices. For example, the interface circuit 602 can read instructions stored in the memory 603 and send the instructions to the processing circuit 601.

[0164] In some embodiments, the interface circuit 602 performs at least one of the communication steps such as sending and / or receiving in the above method, and the processing circuit 601 performs other steps.

[0165] In some embodiments, terms such as interface circuit, interface, transceiver pin, and transceiver may be used interchangeably.

[0166] In some embodiments, the chip 600 further includes one or more memories 603 for storing instructions. Optionally, all or part of the memory 603 may be outside the chip 600.

[0167] The collection, storage, use, processing, transmission, provision and disclosure of user personal information involved in this disclosure shall comply with the relevant laws and regulations and shall not violate public order and good morals.

[0168] In the description of this specification, the description with reference to the terms "one embodiment", "some embodiments", "example", "specific example", or "some examples" etc. means that the specific features, structures, materials or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the present disclosure. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described may be combined in any one or more embodiments or examples in a suitable manner. In addition, those skilled in the art may combine and combine the different embodiments or examples described in this specification and the features of the different embodiments or examples, without contradiction.

[0169] In addition, the terms "first" and "second" are used for descriptive purposes only and should not be understood as indicating or implying relative importance or implicitly indicating the number of the indicated technical features. Thus, a feature defined as "first" or "second" may explicitly or implicitly include at least one of the features. In the description of the present disclosure, "plurality" means at least two, such as two, three, etc., unless otherwise clearly and specifically defined.

[0170] Any process or method description in a flowchart or otherwise described herein may be understood to represent a module, segment or portion of code that includes one or more executable instructions for implementing the steps of a custom logical function or process, and the scope of the preferred embodiments of the present disclosure includes additional implementations in which functions may not be performed in the order shown or discussed, including performing functions in a substantially simultaneous manner or in reverse order depending on the functions involved, which should be understood by technicians in the technical field to which the embodiments of the present disclosure belong.

[0171] The logic and / or steps represented in the flowchart or otherwise described herein, for example, can be considered as an ordered list of executable instructions for implementing logical functions, and can be embodied in any computer-readable medium for use by an instruction execution system, device or apparatus (such as a computer-based system, a system including a processor, or other system that can fetch instructions from an instruction execution system, device or apparatus and execute the instructions), or in combination with these instruction execution systems, devices or apparatuses. For the purpose of this specification, "computer-readable medium" can be any device that can contain, store, communicate, propagate or transmit a program for use by an instruction execution system, device or apparatus, or in combination with these instruction execution systems, devices or apparatuses. More specific examples of computer-readable media (a non-exhaustive list) include the following: an electrical connection with one or more wires (electronic device), a portable computer disk box (magnetic device), a random access memory (RAM), a read-only memory (ROM), an erasable and programmable read-only memory (EPROM or flash memory), a fiber optic device, and a portable compact disk read-only memory (CDROM). In addition, the computer-readable medium may even be paper or other suitable medium on which the program is printed, since the program may be obtained electronically, for example, by optically scanning the paper or other medium and then editing, interpreting or otherwise processing in a suitable manner if necessary, and then stored in a computer memory.

[0172] It should be understood that the various parts of the present disclosure can be implemented in hardware, software, firmware or a combination thereof. In the above-mentioned embodiments, multiple steps or methods can be implemented in software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented in hardware, as in another embodiment, any one of the following technologies known in the art or a combination thereof can be used to implement: a discrete logic circuit having a logic gate circuit for implementing a logic function for a data signal, a dedicated integrated circuit having a suitable combination of logic gate circuits, a programmable gate array (PGA), a field programmable gate array (FPGA), etc.

[0173] A person skilled in the art may understand that all or part of the steps in the method for implementing the above-mentioned embodiment may be completed by instructing related hardware through a program, and the program may be stored in a computer-readable storage medium, which, when executed, includes one or a combination of the steps of the method embodiment.

[0174] In addition, each functional unit in each embodiment of the present disclosure may be integrated into a processing module, or each unit may exist physically separately, or two or more units may be integrated into one module. The above-mentioned integrated module may be implemented in the form of hardware or in the form of a software functional module. If the integrated module is implemented in the form of a software functional module and sold or used as an independent product, it may also be stored in a computer-readable storage medium.

[0175] The storage medium mentioned above may be a read-only memory, a magnetic disk or an optical disk, etc. Although the embodiments of the present disclosure have been shown and described above, it can be understood that the above embodiments are exemplary and cannot be understood as limitations of the present disclosure. A person of ordinary skill in the art may change, modify, replace and modify the above embodiments within the scope of the present disclosure.

Claims

1. A control flow integrity detection method, characterized in that: include: In response to obtaining a target address of the forward jump, traversing a target mapping table based on the target address to obtain a first hash value corresponding to the target address, wherein the target mapping table includes a plurality of mutually related addresses and hash values; Obtain a second hash value corresponding to the target address generated when the code is compiled; Whether the forward jump is legal is determined based on whether the first hash value matches the second hash value.

2. The method according to claim 1, characterized in that The traversing the target mapping table based on the target address to obtain a first hash value corresponding to the target address includes: Based on the base address in the first register, obtaining a target mapping table; The target mapping table is traversed based on the target address to obtain a first hash value corresponding to the target address.

3. The method according to claim 2, characterized in that Before traversing the target mapping table based on the target address, the method further includes: Parsing the executable and linkable format ELF file of the software to be run to obtain the target mapping table; Loading the target mapping table into the system memory to obtain a base address of the target mapping table; The base address of the target mapping table is stored in the first register.

4. The method according to claim 3, characterized in that After obtaining the target mapping table, the method further includes: The value of the first information field in the second register is set to a first value, wherein the first value is used to indicate that the software to be run is software that requires integrity protection.

5. The method according to claim 4, characterized in that The step of setting the value of the first information field in the second register to the first value includes any one of the following: In a case where the first information field includes one bit, setting the value of the first information field to a first value; When the first information field includes multiple bits, the target bit is determined according to the address-associated function included in the target mapping table, and the value of the target bit is set to a first value, wherein different bits in the first information field correspond to different functions.

6. The method according to claim 4, characterized in that In response to obtaining the target address of the forward jump, traversing the target mapping table based on the target address to obtain a first hash value corresponding to the target address includes any of the following: In response to obtaining the target address and the value of the first information field in the second register being a first value, traversing a mapping table based on the target address to obtain a first hash value corresponding to the target address; In response to obtaining the target address and the value of the target bit in the first information field being a first value, a mapping table is traversed based on the target address to obtain a first hash value corresponding to the target address, wherein the target bit corresponds to a function associated with the target address.

7. The method according to claim 4, characterized in that The method further comprises: In case of receiving a modification instruction for the first information field, determining a value of the second information field in the second register; When the value of the second information field is the second value, the value of the first information field is not modified.

8. The method according to claim 7, characterized in that After determining the value of the second information field in the second register, the method further includes: When the value of the second information field is the third value, the value of the first information field is modified to the target value indicated in the modification instruction.

9. The method according to any one of claims 1 to 8, characterized in that: The determining whether the forward jump is legal based on whether the first hash value matches the second hash value includes any one of the following: In a case where the first hash value matches the second hash value, determining that the forward jump is legal; In a case where the first hash value does not match the second hash value, it is determined that the forward jump is illegal.

10. A control flow integrity detection device, characterized in that: The device comprises: A first acquisition module, configured to, in response to acquiring a target address of a forward jump, traverse a target mapping table based on the target address to acquire a first hash value corresponding to the target address, wherein the target mapping table includes a plurality of mutually related addresses and hash values; A second acquisition module, used to acquire a second hash value corresponding to the target address generated when the code is compiled; A determination module is used to determine whether the forward jump is legal based on whether the first Hash value matches the second Hash value.

11. An electronic device, characterized in that: The invention comprises a memory, a processor and a computer program stored in the memory and executable on the processor. When the processor executes the program, the control flow integrity detection method as claimed in any one of claims 1 to 9 is implemented.

12. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the control flow integrity detection method as described in any one of claims 1 to 9 is implemented.

13. A computer program product, characterized in that It comprises a computer program, which, when executed by a processor, implements the control flow integrity detection method as described in any one of claims 1 to 9.

14. A chip, characterized in that: The chip includes a processing unit and an interface circuit, the processing unit obtains program instructions through the interface circuit, the program instructions are executed by the processing unit, and the processing unit is used to execute the control flow integrity detection method as described in any one of claims 1-9.

Citation Information

Patent Citations

  • Device and method for validation of virtual function pointers

    CN112889045A

  • Credibility verification method and device of kernel function, electronic equipment and storage medium

    CN114329488A

  • Control flow integrity checking method, system and equipment based on register and medium

    CN117992962A

  • Device and Method for Validation of Virtual Function Pointers

    US20210240820A1

  • Technique for predicting behaviour of control flow instructions

    US20240370266A1