Software vulnerability version identification method and device, electronic equipment and storage medium
By performing abstract syntax tree analysis and vulnerability signature generation on the patch files of open source software, combined with version backtracking technology, the problem of inaccurate identification of vulnerable versions in the existing technology is solved, and the accurate identification of vulnerable versions of open source software is achieved.
Patent Information
- Application Number
- CN202411911994.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-24
- Publication Date
- 2025-05-27
AI Technical Summary
In the prior art, the vulnerable version identification of open source software has problems with false positives or inaccurate results, making it difficult to accurately locate the vulnerable version range.
By obtaining the patch file of the vulnerability, performing abstract syntax tree analysis, determining the vulnerability signature, and performing version backtracking based on the vulnerability signature to accurately locate the vulnerability introduced version.
It realizes accurate identification of open source software vulnerability versions, improves the accuracy of vulnerability version information, and reduces the risk of false alarms.
Smart Images

Figure CN120046151A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of software development, and in particular to a method, device, electronic device and storage medium for identifying vulnerable versions of software. Background Art
[0002] Vulnerability version identification in open source software is a technology that accurately locates the range of open source software versions with vulnerabilities by analyzing the vulnerability introduction version and the patch submission version. Due to its efficiency and cost advantages in software development, different versions of open source software are widely used. However, during the development process, integrating a specific version of open source software may introduce security risks because some open source software versions may have vulnerabilities. Some vulnerability version information is stored in the National Vulnerability Database, which is currently recognized as the largest public vulnerability database. However, due to the lack of specific analysis, the database often mistakenly reports the version before the introduction of the vulnerability as a vulnerable version, or only marks the version where the vulnerability was first introduced as a vulnerable version. Therefore, the accuracy of its vulnerability version information is low. Summary of the invention
[0003] The present invention provides a method, device, electronic device and storage medium for identifying a software vulnerability version, so as to solve the defects in the prior art and realize accurate identification of the vulnerability version.
[0004] The present invention provides a method for identifying a software vulnerability version, comprising: Obtain a patch file for the vulnerability, and perform abstract syntax tree parsing on the patch file to obtain a parsing result; Based on the analysis result, determining a vulnerability signature of the vulnerability; Perform version backtracking based on the vulnerability signature to determine the version in which the vulnerability was introduced.
[0005] According to a method for identifying a vulnerable version of software provided by the present invention, determining a vulnerability signature of the vulnerability based on the parsing result includes: Based on the parsing result, determining a slicing statement associated with a patch revision variable in the patch file by using a program slicing technique; Analyzing the correlation between the slicing statement and the vulnerability; A target slice statement is determined based on the association, and the vulnerability signature is formed based on the target slice statement.
[0006] According to a method for identifying a vulnerable version of software provided by the present invention, the method of determining a slicing statement associated with a patch revision variable based on program slicing technology includes: Based on the parsing result, extracting the slice statement affected by the patch modification variable by a forward slicing technique; and Based on the parsing result, the slicing statement affecting the patch modification variable is extracted through backward slicing technology.
[0007] According to a method for identifying a vulnerable version of software provided by the present invention, the analyzing the correlation between the slicing statement and the vulnerability includes: Analyzing the calling relationship between the slicing statement and the preset dangerous function, and analyzing the context relationship of the slicing statement; Based on the calling relationship and the context relationship, the correlation between the slicing statement and the vulnerability is determined.
[0008] According to a method for identifying a software vulnerability version provided by the present invention, the version backtracking based on the vulnerability signature to determine the version in which the vulnerability is introduced includes: Obtain multiple version files of the software, and calculate the similarity between the vulnerability signature and the version statements in the version files; Based on the similarity, version backtracking is performed to determine the version into which the vulnerability was introduced.
[0009] According to a method for identifying a software vulnerability version provided by the present invention, the calculating the similarity between the vulnerability signature and the version statement in the version file includes: The similarity between the vulnerability signature and the version statement in the version file is calculated by using the AST semantic similarity algorithm.
[0010] According to a method for identifying a software vulnerability version provided by the present invention, after performing version backtracking based on the vulnerability signature and determining the version in which the vulnerability is introduced, the method further includes: An associated software version associated with the vulnerability is determined based on the vulnerability introduction version and the patch file.
[0011] The present invention also provides a software vulnerability version identification device, comprising: An acquisition module is configured to acquire a patch file of a vulnerability and perform an abstract syntax tree analysis on the patch file to obtain a parsing result; A first determination module is configured to determine a vulnerability signature of the vulnerability based on the parsing result; The second determination module is configured to perform version backtracking based on the vulnerability signature to determine the version in which the vulnerability was introduced.
[0012] The present invention also provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the program, a method for identifying a vulnerable version of software as described in any one of the above is implemented.
[0013] The present invention also provides a non-transitory computer-readable storage medium on which a computer program is stored. When the computer program is executed by a processor, the method for identifying a vulnerable version of software as described in any one of the above is implemented.
[0014] The present invention also provides a computer program product, including a computer program, wherein when the computer program is executed by a processor, the method for identifying a vulnerable version of software as described in any one of the above is implemented.
[0015] The software vulnerability version identification method, device, electronic device and storage medium provided by the present invention perform abstract syntax tree parsing on the patch file of the vulnerability to obtain the parsing result, determine the vulnerability signature based on the parsing result, the vulnerability signature reflects the characteristic code fragment related to the vulnerability in the patch file, and perform version backtracking based on the vulnerability signature to accurately determine the version introduced by the vulnerability. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] In order to more clearly illustrate the technical solutions in the present invention or the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.
[0017] Figure 1 It is a flowchart of the method for identifying a vulnerable version of software provided by the present invention.
[0018] Figure 2 It is a schematic diagram of the method for identifying vulnerable versions of software provided by the present invention.
[0019] Figure 3 It is a structural schematic diagram of the software vulnerability version identification device provided by the present invention.
[0020] Figure 4 It is a structural schematic diagram of the electronic device provided by the present invention. DETAILED DESCRIPTION
[0021] In order to make the purpose, technical solution and advantages of the present invention clearer, the technical solution of the present invention will be clearly and completely described below in conjunction with the drawings of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0022] Combine the following Figure 1-Figure 4 The present invention describes a method, device, electronic device and storage medium for identifying a vulnerable version of software.
[0023] Figure 1 FIG. 1 is a flowchart of a method for identifying a software vulnerability version according to an exemplary embodiment. Figure 1 As shown, in an exemplary embodiment, the method for identifying a vulnerable version of software includes steps 110 to 130, which are described in detail as follows.
[0024] Step 110, obtaining a patch file for the vulnerability, and performing an abstract syntax tree analysis on the patch file to obtain a parsing result.
[0025] In an embodiment of the present invention, the patch file is parsed by an Abstract Syntax Tree (AST), that is, a lexical and grammatical analysis is performed to obtain a corresponding abstract syntax tree. The abstract syntax tree is a tree representation of the abstract syntax structure of the code in the patch file, and each node on the tree represents a structure in the code. During the translation and compilation of the code, the syntax analyzer creates a parse tree and then generates an AST from the parse tree. The nodes in the abstract syntax tree are normalized, and irrelevant information is removed to retain the syntax structure to obtain the final parsing result.
[0026] Step 120: Determine a vulnerability signature of the vulnerability based on the parsing result.
[0027] In the embodiment of the present invention, a vulnerability signature of the vulnerability is determined based on the parsing result. The vulnerability signature refers to a characteristic code fragment related to a specific vulnerability in the code in the patch file, which can be used to identify and locate potential vulnerabilities in open source software.
[0028] Step 130: Perform version backtracking based on the vulnerability signature to determine the version into which the vulnerability was introduced.
[0029] In the embodiment of the present invention, the characteristic information in the vulnerability signature can accurately describe the vulnerability so as to realize the search of similar vulnerability codes. Therefore, the version backtracking can be performed based on the vulnerability signature, the open source software version can be backtracked and the earliest vulnerability introduction version that introduced the vulnerability can be accurately located.
[0030] In an embodiment of the present invention, an abstract syntax tree is parsed on a patch file of a vulnerability to obtain a parsing result. A vulnerability signature is generated based on the parsing result. The vulnerability signature reflects a characteristic code fragment related to the vulnerability in the patch file. Version backtracking is performed based on the vulnerability signature to accurately determine the version in which the vulnerability is introduced.
[0031] In an exemplary embodiment of the present invention, determining the vulnerability signature of the vulnerability based on the parsing result includes: Based on the parsing result, determining a slicing statement associated with a patch revision variable in the patch file by using a program slicing technique; Analyzing the correlation between the slicing statement and the vulnerability; A target slice statement is determined based on the association, and the vulnerability signature is formed based on the target slice statement.
[0032] In an embodiment of the present invention, the program slicing technology achieves analysis and understanding of the program by calculating slices for each point of interest in the program. Therefore, the program slicing technology is used to determine the slice statement associated with the patch revision variable in the patch file, and the patch revision variable is a variable in the patch file that needs to be revised in the source code. The association with the patch revision variable can be affected by the patch revision variable, or it can affect the patch revision variable.
[0033] The correlation between the slice statement and the vulnerability is analyzed, the target slice statement is determined based on the correlation, and a vulnerability signature unique to the vulnerability is formed based on the target slice statement.
[0034] In an exemplary embodiment of the present invention, determining a slicing statement associated with a patch revision variable based on a program slicing technique includes: Based on the parsing result, extracting the slice statement affected by the patch modification variable by a forward slicing technique; and Based on the parsing result, the slicing statement affecting the patch modification variable is extracted through backward slicing technology.
[0035] In the embodiment of the present invention, a forward slicing technique is used to extract slicing statements affected by a patch-modified variable, and a backward slicing technique is used to extract slicing statements affecting the patch-modified variable.
[0036] The forward slicing technique starts slicing backwards from the program entry, that is, starting from the starting point of the program (such as an function), the slices are gradually expanded according to the calling relationship and data dependency of the function until the target code fragment is reached, that is, the slice statement associated with the patch revision variable. The forward slicing technique can accurately determine the dependency of the target code fragment.
[0037] Backward slicing technology starts from the target code fragment of the program and slices forward, that is, starting from the target code fragment, gradually expanding the slice according to data dependencies and control dependencies until reaching the starting point of the program. Backward slicing can take into account unknown dependencies.
[0038] In an exemplary embodiment of the present invention, analyzing the correlation between the slicing statement and the vulnerability includes: Analyzing the calling relationship between the slicing statement and the preset dangerous function, and analyzing the context relationship of the slicing statement; Based on the calling relationship and the context relationship, the correlation between the slicing statement and the vulnerability is determined.
[0039] In an embodiment of the present invention, dangerous functions are pre-set, and these dangerous functions are related to vulnerabilities. The slicing statements are analyzed to see whether they call these preset dangerous functions, and then the contextual relationship between the slicing statements is analyzed, that is, whether there is data flow or control flow between the slicing statements.
[0040] Based on the calling relationship and context relationship, determine the correlation between the slice statement and the vulnerability. Specifically, assign weights to the slice statements based on the calling relationship and context relationship. For slice statements that reference preset dangerous functions, the context relationship is control flow and can cause software vulnerabilities. For example, if the control flow causes the software to exit, these slice statements are assigned heavier weights. The assigned weights are used as the correlation of each slice statement, and the slice statements with weights higher than the preset weight threshold are combined to generate vulnerability signatures.
[0041] In an exemplary embodiment of the present invention, performing version backtracking based on the vulnerability signature to determine the version into which the vulnerability was introduced includes: Obtain multiple version files of the software, and calculate the similarity between the vulnerability signature and the version statements in the version files; Based on the similarity, version backtracking is performed to determine the version into which the vulnerability was introduced.
[0042] In an embodiment of the present invention, all version files of the software are obtained, and the similarity between the vulnerability signature and the version statement in the version file is calculated starting from the latest version file. Based on the similarity, version backtracking is performed to accurately determine the vulnerability introduction version that first introduced the vulnerability.
[0043] In an exemplary embodiment of the present invention, the calculating the similarity between the vulnerability signature and the version statement in the version file includes: The similarity between the vulnerability signature and the version statement in the version file is calculated by using the AST semantic similarity algorithm.
[0044] In the embodiment of the present invention, the AST semantic similarity algorithm is a program code similarity measurement method based on an abstract syntax tree, which is used to detect and evaluate the similarity between program codes. In program code similarity detection, semantic similarity refers to the functional or logical similarity of the program, not just the surface similarity of the code.
[0045] The AST semantic similarity algorithm is implemented based on the tree edit distance calculation. Edit distance is a common method for measuring the difference between strings, which is implemented by calculating the minimum number of edit operations required to convert a string into another string. Therefore, the similarity of code snippets can be calculated based on the edit distance to identify the version files with the vulnerability. In the version backtracking process, the specific version that introduced the vulnerability can be determined by comparing the code differences in different version files, so as to effectively analyze the introduction and repair of vulnerabilities in the code evolution process.
[0046] In an exemplary embodiment of the present invention, after performing version backtracking based on the vulnerability signature to determine the version in which the vulnerability was introduced, the method further includes the following steps, which are described in detail as follows.
[0047] An associated software version associated with the vulnerability is determined based on the vulnerability introduction version and the patch file.
[0048] In the embodiment of the present invention, the vulnerable open source software version range and the associated version files containing the vulnerability are determined by accurately locating the vulnerability introduction version and patch files, thereby comprehensively covering the versions containing the vulnerability.
[0049] like Figure 2 As shown, the present invention provides a vulnerability signature generation scheme based on AST analysis and code slice statement weighted calculation, which can effectively extract key statements related to vulnerabilities in patch files and their features, improve the robustness of the generated vulnerability signatures, and reduce the noise introduced by irrelevant statements, so as to more accurately identify whether there are vulnerabilities in open source software.
[0050] The present invention also introduces an AST semantic similarity algorithm based on the above vulnerability signature. The algorithm is based on grammatical similarity comparison and semantic similarity comparison, and can more accurately calculate the similarity between the vulnerability signature and the currently detected open source software version file, so as to make a more accurate judgment on whether the version is vulnerable to attack. At the same time, due to the robustness and conciseness of the vulnerability signature, the efficiency of version analysis can be improved and automated analysis can be achieved.
[0051] Compared with the prior art, the technical solution proposed in the present invention can more accurately locate the version of a vulnerability introduced in the open source software and the vulnerable version range, greatly improving the accuracy and completeness of risk version judgment. At the same time, the solution proposed in the present invention to analyze whether the vulnerability is in a certain version file through the AST semantic similarity algorithm also has extremely high accuracy, which is higher than the commonly used line mapping method and hash value comparison method in the prior art.
[0052] The following is a description of the software vulnerability version identification device provided by the present invention. The software vulnerability version identification device described below and the software vulnerability version identification method described above can be referred to each other. It should be noted that the device provided in the following embodiment and the method provided in the above embodiment belong to the same concept, and the specific manner in which each module and unit performs the operation has been described in detail in the method embodiment, which will not be repeated here.
[0053] In an exemplary embodiment of the present invention, see Figure 3 , Figure 3 A device for identifying a software vulnerability version according to an exemplary embodiment includes the following modules.
[0054] The acquisition module 310 is configured to acquire a patch file of the vulnerability and perform an abstract syntax tree analysis on the patch file to obtain a parsing result; A first determination module 320 is configured to determine a vulnerability signature of the vulnerability based on the parsing result; The second determination module 330 is configured to perform version backtracking based on the vulnerability signature to determine the vulnerability introduction version.
[0055] In an exemplary embodiment of the present invention, the first determining module 320 includes: A first determination submodule is configured to determine a slicing statement associated with a patch revision variable in the patch file by using a program slicing technique based on the parsing result; An analysis submodule, configured to analyze the correlation between the slicing statement and the vulnerability; A submodule is formed, configured to determine a target slicing statement based on the association, and to form the vulnerability signature based on the target slicing statement.
[0056] In an exemplary embodiment of the present invention, the first determining submodule includes: A first extraction unit is configured to extract the slice statement affected by the patch modification variable through a forward slicing technique based on the parsing result; and The second extraction unit is configured to extract the slicing statement that affects the patch modification variable through a backward slicing technique based on the parsing result.
[0057] In an exemplary embodiment of the present invention, the analysis submodule is configured to include: An analysis unit configured to analyze a calling relationship between the slicing statement and a preset dangerous function, and to analyze a context relationship of the slicing statement; A determination unit is configured to determine the correlation between the slicing statement and the vulnerability based on the calling relationship and the context relationship.
[0058] In an exemplary embodiment of the present invention, the second determining module 330 includes: A calculation submodule, configured to obtain multiple version files of the software, and calculate the similarity between the vulnerability signature and the version statement in the version file; The second determination submodule is configured to perform version backtracking based on the similarity to determine the version in which the vulnerability was introduced.
[0059] In an exemplary embodiment of the present invention, the computing submodule includes: The calculation unit is configured to calculate the similarity between the vulnerability signature and the version statement in the version file through an AST semantic similarity algorithm.
[0060] In an exemplary embodiment of the present invention, the apparatus for identifying a vulnerable version of software further includes: The third determination module is configured to determine the associated software version associated with the vulnerability based on the vulnerability introduction version and the patch file.
[0061] Figure 4 An example of a physical structure diagram of an electronic device is shown in FIG. Figure 4 As shown, the electronic device may include: a processor 410, a communication interface 420, a memory 430 and a communication bus 440, wherein the processor 410, the communication interface 420 and the memory 430 communicate with each other through the communication bus 440. The processor 410 may call the logic instructions in the memory 430 to execute the method for identifying the vulnerability version of the software, the method comprising: obtaining a patch file of the vulnerability, and performing an abstract syntax tree analysis on the patch file to obtain a parsing result; Based on the analysis result, determining a vulnerability signature of the vulnerability; Perform version backtracking based on the vulnerability signature to determine the version in which the vulnerability was introduced.
[0062] In addition, the logic instructions in the above-mentioned memory 430 can be implemented in the form of a software functional unit and can be stored in a computer-readable storage medium when it is sold or used as an independent product. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art or the part of the technical solution, can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present invention. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), disk or optical disk, etc. Various media that can store program codes.
[0063] On the other hand, the present invention further provides a computer program product, the computer program product includes a computer program, the computer program can be stored on a non-transitory computer-readable storage medium, when the computer program is executed by a processor, the computer can execute the software vulnerability version identification method provided by the above methods, the method includes: obtaining a patch file of the vulnerability, and performing an abstract syntax tree analysis on the patch file to obtain a parsing result; Based on the analysis result, determining a vulnerability signature of the vulnerability; Perform version backtracking based on the vulnerability signature to determine the version in which the vulnerability was introduced.
[0064] In another aspect, the present invention further provides a non-transitory computer-readable storage medium having a computer program stored thereon, wherein when the computer program is executed by a processor, the method for identifying a software vulnerability version provided by the above methods is implemented, the method comprising: obtaining a patch file of the vulnerability, and performing an abstract syntax tree analysis on the patch file to obtain a analysis result; Based on the analysis result, determining a vulnerability signature of the vulnerability; Perform version backtracking based on the vulnerability signature to determine the version in which the vulnerability was introduced.
[0065] The device embodiments described above are merely illustrative, wherein the units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place, or they may be distributed on multiple network units. Some or all of the modules may be selected according to actual needs to achieve the purpose of the scheme of this embodiment. Ordinary technicians in this field can understand and implement it without paying creative labor.
[0066] Through the description of the above implementation methods, those skilled in the art can clearly understand that each implementation method can be implemented by means of software plus a necessary general hardware platform, and of course, can also be implemented by hardware. Based on this understanding, the above technical solution is essentially or the part that contributes to the prior art can be embodied in the form of a software product, and the computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, a disk, an optical disk, etc., including a number of instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.
[0067] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A method for identifying a vulnerable version of software, characterized in that: include: Obtain a patch file for the vulnerability, and perform abstract syntax tree parsing on the patch file to obtain a parsing result; Based on the analysis result, determining a vulnerability signature of the vulnerability; Perform version backtracking based on the vulnerability signature to determine the version in which the vulnerability was introduced.
2. The method for identifying a vulnerable version of software according to claim 1, characterized in that: Determining the vulnerability signature of the vulnerability based on the parsing result includes: Based on the parsing result, determining a slicing statement associated with a patch revision variable in the patch file by using a program slicing technique; Analyzing the correlation between the slicing statement and the vulnerability; A target slice statement is determined based on the association, and the vulnerability signature is formed based on the target slice statement.
3. The method for identifying a vulnerable version of software according to claim 2, characterized in that: The determining of the slice statement associated with the patch revision variable based on the program slicing technology includes: Based on the parsing result, extracting the slice statement affected by the patch modification variable by a forward slicing technique; and Based on the parsing result, the slicing statement affecting the patch modification variable is extracted through backward slicing technology.
4. The method for identifying a vulnerable version of software according to claim 2, characterized in that: The analyzing the correlation between the slicing statement and the vulnerability includes: Analyzing the calling relationship between the slicing statement and the preset dangerous function, and analyzing the context relationship of the slicing statement; Based on the calling relationship and the context relationship, the correlation between the slicing statement and the vulnerability is determined.
5. The method for identifying a vulnerable version of software according to claim 1, characterized in that: The performing version backtracking based on the vulnerability signature to determine the version in which the vulnerability was introduced includes: Obtain multiple version files of the software, and calculate the similarity between the vulnerability signature and the version statements in the version files; Based on the similarity, version backtracking is performed to determine the version into which the vulnerability was introduced.
6. The method for identifying a vulnerable version of software according to claim 5, characterized in that: The calculating the similarity between the vulnerability signature and the version statement in the version file includes: The similarity between the vulnerability signature and the version statement in the version file is calculated by using the AST semantic similarity algorithm.
7. The method for identifying a vulnerable version of software according to any one of claims 1 to 6, characterized in that: After performing version backtracking based on the vulnerability signature to determine the version in which the vulnerability was introduced, the method further includes: An associated software version associated with the vulnerability is determined based on the vulnerability introduction version and the patch file.
8. A software vulnerability version identification device, characterized in that: include: An acquisition module is configured to acquire a patch file of a vulnerability and perform an abstract syntax tree analysis on the patch file to obtain a parsing result; A first determination module is configured to determine a vulnerability signature of the vulnerability based on the parsing result; The second determination module is configured to perform version backtracking based on the vulnerability signature to determine the version in which the vulnerability was introduced.
9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and running on the processor, characterized in that: When the processor executes the program, the method for identifying a vulnerable version of software as claimed in any one of claims 1 to 7 is implemented.
10. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the method for identifying a vulnerable version of software as claimed in any one of claims 1 to 7 is implemented.
Citation Information
Cited By
Vulnerability defense method and device, electronic equipment, medium and computer program product
CN120750662A
Vulnerability defense method and device, electronic equipment, medium and computer program product
CN120750662B