Method and system for positioning known vulnerabilities of industrial control system
By detecting and analyzing the vulnerability information of the industrial control system, generating a module logic diagram and comparing the similarity of the function execution path, the vulnerability positioning problem of industrial control system is solved, and vulnerability identification with high accuracy and low missed rate is achieved.
Patent Information
- Application Number
- CN202510171613.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-17
- Publication Date
- 2025-05-23
AI Technical Summary
The existing technology is difficult to specifically locate vulnerabilities in industrial control systems, and there is a lack of effective methods to identify and repair vulnerabilities.
By periodically detecting newly released industrial control vulnerability information, parsing executable files, disassembling patch files, generating module logic diagrams, comparing the similarity of function execution paths, and positioning vulnerability locations.
It realizes accurate identification and positioning of vulnerabilities in the industrial control system, improves detection accuracy and reduces the missed rate.
Smart Images

Figure CN120030551A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of industrial control security, and particularly relates to a method and system for locating known vulnerabilities in an industrial control system. Background Art
[0002] As a critical infrastructure, the secure and stable operation of an industrial control system is crucial for ensuring social order and people's livelihood. With the development of intelligent manufacturing, industrial control systems are increasingly relying on network technologies, which makes the systems potentially vulnerable to threats from the cyber space. Security issues in industrial control systems can be used as means of attack. Due to the complexity and sensitivity of industrial control systems, there is often little public information about vulnerabilities in industrial control systems, and details are often lacking. How to achieve the specific location of vulnerabilities in industrial control systems based on existing resources has become a key problem to be solved urgently. Summary of the Invention
[0003] The purpose of the present invention is to overcome the above-mentioned disadvantages of the prior art and provide a method and system for locating known vulnerabilities in an industrial control system, so as to solve the problem that it is difficult to specifically locate vulnerabilities in industrial control systems in the prior art.
[0004] To achieve the above purpose, the present invention adopts the following technical solutions: A method for locating known vulnerabilities in an industrial control system includes the following steps: Periodically detect newly released industrial control vulnerability information and store the industrial control vulnerability information in a database; Obtain the key information of the target vulnerability from the updated industrial control vulnerability information, and parse the executable file of the target vulnerability; disassemble the executable file to obtain the binary execution code of the executable file. Based on the binary execution code, divide each executable file into multiple industrial control modules according to functions. Each of the industrial control modules includes multiple functions with mutual call relationships, and obtain the module logic diagram of the industrial control module based on the functions with mutual call relationships; based on the key information of the target vulnerability, locate the industrial control modules that the vulnerability may be associated with, and obtain the fuzzy location module of the vulnerability. Disassemble the patch file of the industrial control vulnerability information, and generate the module logic diagram of the patch file based on the functions of the patch file; standardize and translate the binary execution code of the fuzzy location module and the binary code of the patch file to obtain the translated fuzzy location module and patch file; compare the function execution paths in the translated fuzzy location module and the patch file, and measure the similarity of the function execution paths. If the measurement result is less than the set threshold, the fuzzy location module where the corresponding function is located is the location of the vulnerability.
[0005] A further improvement of the present invention lies in: Preferably, the industrial control vulnerability information is stored in the database by field matching of an industrial control key information table.
[0006] Preferably, the executable file is disassembled by a static analysis tool to obtain the binary execution code, program data, resource files and function call information of the executable file.
[0007] Preferably, each of the industrial control modules includes at least one module entry function.
[0008] Preferably, before comparing the function execution paths in the fuzzy location module, the repeatedly called public functions in the fuzzy location module are deleted.
[0009] Preferably, the specific process of comparing the translated fuzzy position module and the function execution path in the patch file is to call their respective module logic diagrams and the functions therein through the module entry function of the fuzzy position module and the patch entry function of the patch file, and measure the execution path of the function in the fuzzy position module and the patch file. If the output semantic similarity is less than the set threshold, the fuzzy position module where the corresponding function is located is the location of the vulnerability.
[0010] Preferably, the module entry function is based on protocol operation mode identification, including two ways: Method 1: For protocols based on the normal process startup mode, when the protocol is running, a new protocol process is established in the system, and the entry function is identified based on the protocol process; Method 2: For the protocol based on the daemon operation mode, the entry function of the daemon process that meets the characteristics is obtained through the characteristics of the daemon process.
[0011] Preferably, the security mechanism is removed before the patch file is compared.
[0012] Preferably, before comparing the patch files, the vulnerability repairability of the patch files is determined.
[0013] A known vulnerability location system for an industrial control system, comprising: A detection storage unit is used to periodically detect newly released industrial control vulnerability information and store the industrial control vulnerability information in a database; A fuzzy positioning unit is used to obtain key information of a target vulnerability from updated industrial control vulnerability information and parse the executable file of the target vulnerability; disassemble the executable file to obtain the binary execution code of the executable file; based on the binary execution code, each executable file is divided into multiple industrial control modules according to function, each of the industrial control modules includes multiple functions with mutual calling relationships, and the module logic diagram of the industrial control module is obtained based on the functions with mutual calling relationships; based on the key information of the target vulnerability, the industrial control module that may be associated with the vulnerability is located to obtain the fuzzy position module of the vulnerability; The precise positioning unit is used to disassemble the patch file of the industrial control vulnerability information, generate the module logic diagram of the patch file based on the function of the patch file; perform standardized translation of the binary execution code of the fuzzy position module and the binary code of the patch file to obtain the translated fuzzy position module and patch file; compare the function execution paths in the translated fuzzy position module and the patch file, measure the similarity of the function execution paths, and if the measurement result is less than the set threshold, the fuzzy position module where the corresponding function is located is the location of the vulnerability.
[0014] Compared with the prior art, the present invention has the following beneficial effects: The present invention discloses a method and system for locating known vulnerabilities of an industrial control system. The method periodically obtains vulnerability information released by the industrial control system, obtains a corresponding executable file based on a target vulnerability, obtains a binary code of the executable file after disassembling the executable file, obtains a module entry function from the binary code of the target vulnerability, and completes the positioning of modules that may be related to the vulnerability; further, a patch file is executed on the function in the module, and the difference between the function in the module before and after the patch file is executed is compared, and finally the vulnerability position is accurately determined. The method can accurately identify the vulnerability position by performing a binary comparison between the corresponding module of the industrial control system program and the patch file, and has the characteristics of high detection accuracy and low false negative rate. BRIEF DESCRIPTION OF THE DRAWINGS
[0015] Figure 1 An overall flow chart of an attack path detection system based on behavioral gene recognition provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0016] In the following, the terms "first", "second", "third", and "fourth" are used for descriptive purposes only and should not be understood as indicating or implying relative importance or implicitly indicating the number of the indicated technical features. Therefore, a feature defined as "first", "second", "third", and "fourth" may explicitly or implicitly include one or more of the features.
[0017] The co-shooting method provided in the embodiment of the present application can be applied to terminal devices such as mobile phones, tablet computers, wearable devices, vehicle-mounted devices, augmented reality (AR) / virtual reality (VR) devices, laptop computers, ultra-mobile personal computers (UMPC), netbooks, personal digital assistants (PDA), etc. The embodiment of the present application does not impose any restrictions on the specific type of the terminal device.
[0018] It should be noted that the terms "first", "second", etc. in the specification and drawings of the present invention are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged where appropriate, so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units that are clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0019] The first aspect of the present invention discloses a method for locating known vulnerabilities in an industrial control system, which is mainly divided into two steps. First, fuzzy positioning is performed based on vulnerability information and binary disassembly, and then precise positioning is achieved based on the fuzzy positioning combined with binary comparison of patch files.
[0020] S1, periodically detects the latest industrial control vulnerability information and stores it in the database; (1) Establish an industrial control key information table for subsequent screening of industrial control related information from open source information.
[0021] (2) Build an industrial control vulnerability information database based on open source information, periodically detect the latest released vulnerability information, and screen the vulnerability information related to industrial control scenarios in the released vulnerability information through field matching of the industrial control key information table and combining with the large language model technology, obtain this part of the industrial control vulnerability information and store it in the database.
[0022] S2, fuzzy positioning based on vulnerability information and binary disassembly, the specific content is: (1) Traverse the vulnerability data updated in the industrial control vulnerability information database and extract the key information of the target vulnerability contained in the vulnerability data.
[0023] (2) Based on the key information of the target vulnerability, locate the industrial control system service with the vulnerability and parse the executable files involved in the vulnerability.
[0024] (3) Use static analysis tools to disassemble the vulnerable industrial control system executable files to generate the executable file's binary execution code, program data, resource files, and function call information.
[0025] (4) Divide the binary code of the executable file into multiple industrial control modules according to their functions. The industrial control module is a combination of functions in the binary code that have a mutual calling relationship, and a complete set of processing logic is formed through the calling relationship. Executing the processing logic can complete the function of the industrial control module. Each industrial control module contains at least one module entry function.
[0026] Data packets are acquired through the module entry function, and other related functions in the module perform protocol parsing, state transition, and function processing. Data transmission depends on the transmission protocol, so the module entry function is related to the reception of specific types of protocol packets.
[0027] The module entry function is often the starting point of each module function, and forms a complete module function through the calling relationship with other functions.
[0028] (5) Search for the module entry function in the text segment of the binary execution code, and identify all module entry functions based on the protocol operation mode. There are two main ways to identify the module entry function based on the protocol: 1) For protocols based on the normal process startup mode, when the protocol is running, a new process is established in the system, and the entry function is implemented based on this protocol process for identification.
[0029] 2) For protocols based on the daemon operation mode, the daemon entry function that meets the characteristics is found through the characteristics of the daemon, which mainly has the characteristics of self-starting at startup, always surviving, having a loop structure, and maintaining status.
[0030] The module logic diagram of the industrial control module is generated according to the function call relationship in the disassembled binary code. A module logic diagram of a sub-functional industrial control module in each industrial control system takes the entry function as the starting point and is the set of all reachable functions in the process. If a function is reachable by multiple entry functions, it is determined that the function belongs to the module logic diagrams of multiple modules at the same time.
[0031] In the case where the module logic diagram is incomplete due to indirect function calls, based on the fact that functions in the same module have similar addresses in the address space, by setting the offset threshold of the function's relative address offset in the text segment, functions whose address distance from the entry function is less than the set offset threshold are also counted in the module range.
[0032] Through the relevant information in the vulnerability information library, according to the vulnerability cause, vulnerability component, affected version and other information, the module where the vulnerability may exist is located and marked as the fuzzy location module of the vulnerability.
[0033] Step 3: Accurate positioning Accurately locate industrial control vulnerabilities, specifically: (1) Patch file disassembly. Obtain the official patch file corresponding to the vulnerability, disassemble the patch file, obtain the binary code corresponding to each function in the patch file, and generate the patch binary code module logic diagram based on the calling relationship of each function in the patch file. Each corresponding patch file also has a patch entry function, through which each function in the patch file can be called.
[0034] (2) Disassembly code standardization. Define standardized instruction statements and translate the disassembly binary codes of patch files and fuzzy location modules in a standardized manner, thereby resolving the differences in disassembly codes caused by different compilation environments.
[0035] (3) For the simplification of multiple fuzzy position module functions, there are a large number of common functions that are repeatedly called in different fuzzy position modules. Delete the common functions in the module logic diagram. When calling the functions in the fuzzy position module, they are all called through the above module entry function.
[0036] (4) Removing security mechanisms. Some patches introduce security mechanisms to further enhance security protection capabilities. This part of the content has no direct correlation with the vulnerability content. If a binary comparison is performed directly, it will cause false positives for security repair items. In order to further locate the actual vulnerability location and reduce the false positive rate of vulnerability location, it is necessary to detect whether there is a relevant security mechanism in the patch binary and delete the part of the patch that only introduces the security mechanism without bringing other changes.
[0037] (5) Determine the vulnerability repairability of the patch file. Simulate the difference in basic blocks before and after the function is patched, compare the difference in execution status, and measure the similarity of the function before and after the patch. If the more identical execution states are when the instructions of the two modules are terminated, the higher the semantic similarity of the two instructions. The patch pair with a similarity above the threshold is determined to be a safe patch, which is the real vulnerability repair content after determination.
[0038] (6) Accurately locate the vulnerability point. Traverse the function items in the binary code module logic diagram of the patch file and the module logic diagram of the industrial control module, calculate and compare the execution paths of the two functions in the two modules, and measure the similarity of the function execution paths. If the semantic similarity calculated by the input is less than the threshold, it is determined that the patch has modified the content of this part, and this part is the location of the vulnerability.
[0039] The following is further described in conjunction with specific embodiments.
[0040] Example 1 Figure 1 A flow chart of a method for locating known vulnerabilities in an industrial control system provided by an embodiment of the present invention is as follows: Establish a key information table for industrial control, which mainly includes (1) industrial control manufacturers, such as Schneider, ABB, and Hollysys; (2) industrial control equipment and systems, such as DCS, PLC, HMI, etc.; (3) industrial control scenarios, such as electricity, water, and production, etc., for subsequent screening of industrial control related information from open source information.
[0041] An industrial control vulnerability information database is built based on open source information, which mainly refers to CVE vulnerability information. The latest vulnerability information is checked every half an hour. The vulnerability information related to the industrial control scenario is screened out in the published vulnerability information through field matching of the industrial control key information table and combined with the large language model technology. The industrial control vulnerability information is obtained and stored in the database.
[0042] Traverse the vulnerability data updated in the industrial control vulnerability information database and extract the key information of the target vulnerability contained in the vulnerability data, including the products affected by the vulnerability, the affected software version, the vulnerability type, etc.
[0043] Since industrial control systems are very large and complex, each industrial control system contains a large number of services and executable modules. Generally, vulnerabilities only exist in a single service. Each service corresponds to a large number of executable modules. According to the key information of the target vulnerability, the industrial control system service with the vulnerability is located and the executable files involved in the vulnerability are parsed.
[0044] Use static analysis tools such as IDA Pro to disassemble the executable files of the industrial control system with vulnerabilities and generate binary execution code, program data, resource files, and function call information.
[0045] The binary code of the executable file is merged into modules. Each module is a combination of functions with mutual calling relationships, and a complete set of processing logic is formed through the calling relationship. Each industrial control module contains at least one module entry function, which is similar to the main function in the code logic.
[0046] The module entry function acquires data packets, and other related functions in the module perform protocol parsing, state transition, function processing, etc. Data transmission depends on the transmission protocol, so the module entry function is related to the reception of specific types of protocol data packets. The scenario in which the embodiment of the present invention is applied is an industrial control scenario, and the transmission protocols involved include the application and identification of traditional information protocols and industrial control protocols. Therefore, the functions that have a calling relationship with the module entry function functionally involve the processing logic of traditional information protocols and industrial control protocols.
[0047] The module entry function is often the starting point of each module function, and forms a complete module function through the calling relationship with other functions. The embodiment provided by the present invention searches for the module entry function in the text segment of the binary execution code, and identifies all module entry functions based on the protocol operation mode. The protocol operation modes provided by the embodiment of the present invention are mainly 2 types: (1) Normal process startup mode. When the protocol is running, a new process is established in the system and the application protocol service starts running. This type of protocol startup has a fixed startup mode, based on which the entry function is identified.
[0048] (2) Daemon process operation mode. For application protocol services running in daemon process mode, this type of protocol service usually does not interact with the terminal or user, but is automatically started when the system starts and continues to run to provide certain functions or services. The daemon process entry function that meets the characteristics can be found through the characteristics of the daemon process. In the embodiment of the present invention, the protocol service running in daemon process mode has the characteristics of self-starting at startup, always surviving, having a loop structure, and maintaining status.
[0049] The module logic diagram is generated based on the function call relationship in the disassembled binary code. The module logic diagram of a sub-function of each industrial control system is the set of all reachable functions in the process starting from the entry function. In particular, there is often a function that can be reached by multiple entry functions, and it is determined that the function belongs to the module logic diagram of multiple modules at the same time.
[0050] In view of the indirect function calls in the industrial control software code logic in the embodiment of the present invention, it will result in the inability to parse all the called functions after static disassembly when calling the function, thereby causing an incomplete module logic diagram. In the embodiment provided by the present invention, functions based on the same module have similar addresses in the address space. By setting the offset threshold of the relative address offset of the function in the text segment, functions whose address distance from the entry function is less than the set offset threshold are also counted in the module logic.
[0051] Through the relevant information in the vulnerability information library, according to the vulnerability cause, vulnerability component, affected version and other information, the module where the vulnerability may exist is located and marked as the fuzzy location module of the vulnerability.
[0052] Accurately locate industrial control vulnerabilities, specifically: (1) Patch file disassembly. Obtain the official patch file corresponding to the vulnerability, disassemble the patch file, and generate a patch binary code module logic diagram.
[0053] (2) Disassembly code standardization. Define standardized instruction statements and translate the disassembly binary codes of patch files and fuzzy location modules in a standardized manner, thereby resolving the differences in disassembly codes caused by different compilation environments.
[0054] (3) Module function simplification: There are a large number of common functions that are repeatedly called in different modules. Delete these common functions in the module logic diagram.
[0055] (4) Removing security mechanisms. Some patches introduce security mechanisms to further enhance security protection capabilities. This part of the content has no direct correlation with the vulnerability content. If a binary comparison is performed directly, it will cause false positives for security repair items. In an embodiment of the present invention, the security mechanisms introduced in the patch include canary protection mechanism, Forward-EdgeCFI, Backward-Edge CFI, PAC mechanism, etc. In order to further locate the actual vulnerability location and reduce the false positive rate of vulnerability location, it is necessary to detect whether there are relevant security mechanisms in the patch binary, and delete the part of the patch that only introduces the security mechanism without bringing other changes.
[0056] (5) Determine the vulnerability repairability of the patch file. Simulate the difference between the basic blocks before and after the function is patched, compare the difference in execution status, and measure the similarity of the functions before and after the patch. If the more identical execution states there are when the instructions of the two modules are terminated, the higher the semantic similarity of the two instructions. The patch pair with a similarity above the threshold is determined to be a safe patch.
[0057] (6) Accurately locate the vulnerability point. Traverse the function items of the two modules, calculate and compare the execution paths within the modules where the two functions are located, and measure the similarity of the function execution paths. If the semantic similarity calculated by the input is less than the threshold, it is determined that the patch has modified the content of this part, and this part is the location of the vulnerability.
[0058] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principle of the present invention should be included in the protection scope of the present invention.
Claims
1. A method for locating known vulnerabilities in an industrial control system, characterized in that: The following steps are involved: Periodically detect newly released industrial control vulnerability information and store it in the database; Obtain key information of the target vulnerability from the updated industrial control vulnerability information and parse the executable file of the target vulnerability; Disassemble the executable file to obtain the binary execution code of the executable file. Based on the binary execution code, divide each executable file into multiple industrial control modules according to function. Each industrial control module includes multiple functions with mutual calling relationships. The module logic diagram of the industrial control module is obtained based on the functions with mutual calling relationships. Based on the key information of the target vulnerability, locate the industrial control module that may be associated with the vulnerability to obtain the fuzzy location module of the vulnerability. The patch file of industrial control vulnerability information is disassembled, and the module logic diagram of the patch file is generated based on the function of the patch file; the binary execution code of the fuzzy position module and the binary code of the patch file are standardized and translated to obtain the translated fuzzy position module and patch file; the function execution paths in the translated fuzzy position module and the patch file are compared to measure the similarity of the function execution paths. If the measurement result is less than the set threshold, the fuzzy position module where the corresponding function is located is the location of the vulnerability.
2. According to claim 1, a method for locating known vulnerabilities in an industrial control system is characterized in that: By matching the fields of the industrial control key information table, the industrial control vulnerability information is stored in the database.
3. The method for locating known vulnerabilities in an industrial control system according to claim 1, characterized in that: The executable file is disassembled through static analysis tools to obtain the binary execution code, program data, resource files and function call information of the executable file.
4. The method for locating known vulnerabilities in an industrial control system according to claim 1, characterized in that: Each of the industrial control modules includes at least one module entry function.
5. The method for locating known vulnerabilities in an industrial control system according to claim 1, characterized in that: Before comparing the function execution paths in the fuzzy location module, the public functions that are repeatedly called in the fuzzy location module are deleted.
6. The method for locating known vulnerabilities in an industrial control system according to claim 1, characterized in that: The specific process of comparing the translated fuzzy location module and the function execution path in the patch file is to call their respective module logic diagrams and the functions therein through the module entry function of the fuzzy location module and the patch entry function of the patch file, and measure the execution path of the function in the fuzzy location module and the patch file. If the output semantic similarity is less than the set threshold, the fuzzy location module where the corresponding function is located is the location of the vulnerability.
7. A method for locating known vulnerabilities in an industrial control system according to claim 6, characterized in that: The module entry function is based on protocol operation mode identification, including two methods: Method 1: For protocols based on the normal process startup mode, when the protocol is running, a new protocol process is established in the system, and the entry function is identified based on the protocol process; Method 2: For the protocol based on the daemon operation mode, the entry function of the daemon process that meets the characteristics is obtained through the characteristics of the daemon process.
8. The method for locating known vulnerabilities in an industrial control system according to claim 1, characterized in that: Before the patch file comparison, the security mechanism is removed.
9. The method for locating known vulnerabilities in an industrial control system according to claim 1, characterized in that: Before comparing the patch files, the vulnerability repairability of the patch files is determined.
10. A system for locating known vulnerabilities in industrial control systems, characterized in that: include: A detection storage unit is used to periodically detect newly released industrial control vulnerability information and store the industrial control vulnerability information in a database; A fuzzy positioning unit is used to obtain key information of the target vulnerability from the updated industrial control vulnerability information and parse the executable file of the target vulnerability; Disassemble the executable file to obtain the binary execution code of the executable file. Based on the binary execution code, divide each executable file into multiple industrial control modules according to function. Each industrial control module includes multiple functions with mutual calling relationships. The module logic diagram of the industrial control module is obtained based on the functions with mutual calling relationships. Based on the key information of the target vulnerability, locate the industrial control module that may be associated with the vulnerability to obtain the fuzzy location module of the vulnerability. The precise positioning unit is used to disassemble the patch file of the industrial control vulnerability information, generate the module logic diagram of the patch file based on the function of the patch file; perform standardized translation of the binary execution code of the fuzzy position module and the binary code of the patch file to obtain the translated fuzzy position module and patch file; compare the function execution paths in the translated fuzzy position module and the patch file, measure the similarity of the function execution paths, and if the measurement result is less than the set threshold, the fuzzy position module where the corresponding function is located is the location of the vulnerability.
Citation Information
Patent Citations
Similar vulnerability detection method and device for binary program
CN113468525A
Vulnerability detection method and system for binary internet of things firmware program
CN115640577A
Vulnerability repairing system and method based on vulnerability information base
CN116644429A
Binary software vulnerability detection method based on patch feature correction
CN118503978A
Source code detection method
CN119442240A