Java deserialization vulnerability mining method and device
Through the combination of static analysis and dynamic search, a program feature map is constructed and a three-dimensional variant payload is generated, which solves the problem of insufficient accuracy and efficiency of Java deserialization vulnerability mining in the existing technology, and realizes automated vulnerability mining and verification.
Patent Information
- Application Number
- CN202510111550.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-23
- Publication Date
- 2025-06-06
AI Technical Summary
In the prior art, static analysis is difficult to deal with Java dynamic characteristics and many false alarms. Dynamic testing lacks the ability to modify the serialization process itself, resulting in the mining of Java deserialization vulnerability inaccurate and efficient enough.
By statically analyzing the Java program files of the software system to be tested, building a program feature map, searching for suspicious function call sequences, evaluating and updating the feature map in real time, generating three-dimensional mutated payloads to verify the vulnerability.
It realizes automatic mining and verification of Java deserialization vulnerabilities, improves the accuracy and efficiency of vulnerability mining, can better handle Java dynamic features and effectively modify the serialization process.
Smart Images

Figure CN120105428A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer technology, and in particular to a Java deserialization vulnerability mining method and device. Background Art
[0002] Java's serialization and deserialization mechanism plays an important role in scenarios such as distributed computing, data persistence, and remote method calls. However, this mechanism has security risks. Attackers can use the deserialization mechanism to execute certain dangerous functions based on the object-oriented characteristics of the Java language through carefully constructed malicious data, ultimately achieving remote code execution, sensitive information theft, and other malicious behaviors.
[0003] Identifying Java deserialization vulnerabilities is of great significance to maintaining the security of cyberspace. Existing methods for identifying Java deserialization vulnerabilities include solutions based on static program analysis and dynamic testing, but both solutions have limitations. For example, static analysis has difficulty in handling Java dynamic characteristics and has many false positives, and dynamic testing lacks the ability to modify the serialization process itself. Summary of the invention
[0004] The present invention provides a Java deserialization vulnerability mining method and device, which are used to solve the defects in the prior art that static analysis is difficult to handle Java dynamic characteristics and has many false positives, and dynamic testing lacks the ability to modify the serialization process itself, and realizes automatic mining and verification of Java deserialization vulnerabilities.
[0005] The present invention provides a Java deserialization vulnerability mining method, comprising the following steps.
[0006] Performing static analysis on the Java program files of the software system to be tested to construct a program feature graph for the Java program files, wherein the program feature graph is used to represent control flow information, data flow information, and function call relationship information of the Java program; Searching the program feature graph to find suspicious function call sequences, where the suspicious function call sequences are function calls that have security risks or potential vulnerabilities in the Java program; Evaluate the suspicious function call sequence, and update the program feature graph in real time according to the evaluation result; The program feature graph updated in real time is searched. If the search output is a complete calling sequence from a deserialized function to a dangerous function, a payload corresponding to the complete calling sequence is generated in a three-dimensional mutation manner based on the search results, wherein the three-dimensional mutation includes field value mutation, method call mutation, and class change mutation.
[0007] According to the Java deserialization vulnerability mining method provided by the present invention, the Java program file is a Java archive file or a directory containing Java class files; The static analysis of the Java program files of the software system to be tested to construct a program feature graph for the Java files specifically includes: Perform static analysis on the input Java program file and each class in the current class path to extract the class name, interface method name, and parameter type; Build a virtual call graph by merging paths that share the same name method to identify potential calling relationships between interface methods; Performing taint analysis on the virtual call graph and marking a data source node and a data sink node, wherein the data source node is a method for deserializing input data, and the initial value of the data sink node is a predefined suspicious method; In the virtual call graph, each interface method is added to the virtual call edge of the Java dynamic proxy processing function to generate a program feature graph for the Java file.
[0008] According to the Java deserialization vulnerability mining method provided by the present invention, searching the program feature graph to find suspicious function call sequences specifically includes: Starting from a data source node in the program feature graph, searching for a function call sequence to a data sink node; The found function calling sequence is determined as a suspicious function calling sequence.
[0009] According to the Java deserialization vulnerability mining method provided by the present invention, the evaluation of the suspicious function call sequence specifically includes: Decomposing the suspicious function call sequence into paths each having a length of 1; A challenge-based fuzzy test is performed on each path from the data sink node to the data source node to determine whether the path is a feasible path or a false positive call edge.
[0010] According to the Java deserialization vulnerability mining method provided by the present invention, the program feature graph is updated in real time according to the evaluation result, specifically including: If the path is a feasible path, the caller is included in the data sink node set to add additional attention to the path in subsequent analysis; If the path is a false positive call edge, the path is marked as an uncontrollable edge in the program feature graph to exclude the edge in subsequent analysis.
[0011] According to the Java deserialization vulnerability mining method provided by the present invention, generating a payload corresponding to the complete call sequence in a three-dimensional variation manner according to the search results specifically includes: If the search output is a complete call sequence from the deserialization function to the dangerous function, for the object to be input, randomly select the attributes of the object and randomly transform the object to complete the field value mutation; For the object to be input, execute the method of its corresponding class with random parameters to complete the method call mutation; For the object to be input, the modified class is used to replace the originally loaded class to complete the class change mutation.
[0012] According to the Java deserialization vulnerability mining method provided by the present invention, after generating the payload, the method further includes: Based on the payload, the software system to be tested is verified to determine whether the software system has a deserialization vulnerability.
[0013] The present invention also provides a Java deserialization vulnerability mining device, comprising the following modules: A program feature graph construction module is used to perform static analysis on the Java program files of the software system to be tested to construct a program feature graph for the Java program files, wherein the program feature graph is used to represent control flow information, data flow information, and function call relationship information of the Java program; A search module, used to search the program feature graph to find suspicious function call sequences, where the suspicious function call sequences are function calls that have security risks or potential vulnerabilities in the Java program; A program feature graph updating module is used for evaluating the suspicious function call sequence and updating the program feature graph in real time according to the evaluation result; The payload generation module is used to search the program feature graph that is updated in real time. If the search output is a complete calling sequence from a deserialized function to a dangerous function, a payload corresponding to the complete calling sequence is generated in a three-dimensional mutation manner based on the search results, wherein the three-dimensional mutation includes field value mutation, method call mutation and class change mutation.
[0014] The present invention also provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the computer program, the Java deserialization vulnerability mining method described in any one of the above methods is implemented.
[0015] The present invention also provides a non-transitory computer-readable storage medium on which a computer program is stored. When the computer program is executed by a processor, the Java deserialization vulnerability mining method described in any one of the above is implemented.
[0016] The present invention also provides a computer program product, including a computer program, wherein when the computer program is executed by a processor, the method for mining Java deserialization vulnerabilities as described above is implemented.
[0017] The Java deserialization vulnerability mining method and device provided by the present invention, through static analysis of the Java program file of the software system to be tested, to construct a program feature graph for the Java program file, the program feature graph is used to represent the control flow information, data flow information and function call relationship information of the Java program; the program feature graph is searched to find suspicious function call sequences, the suspicious function call sequences are function calls with security risks or potential vulnerabilities in the Java program; the suspicious function call sequences are evaluated, and the program feature graph is updated in real time according to the evaluation results; the program feature graph after real-time update is searched, if the search output is a complete call sequence from the deserialization function to the dangerous function, then according to the search results, a payload corresponding to the complete call sequence is generated in a three-dimensional mutation manner, wherein the three-dimensional mutation includes field value mutation, method call mutation and class change mutation. The present invention uses dynamic test results to improve the program feature graph obtained by static program analysis, and uses a dynamic search strategy on the program feature graph to screen suspicious function call sequences, thereby improving the accuracy and efficiency of Java deserialization vulnerability mining. BRIEF DESCRIPTION OF THE DRAWINGS
[0018] In order to more clearly illustrate the technical solutions in the present invention or the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.
[0019] Figure 1 It is a flow chart of the Java deserialization vulnerability mining method provided by the present invention.
[0020] Figure 2 This is a workflow diagram of the vulnerability digger provided by the present invention.
[0021] Figure 3 It is a schematic diagram of the process of constructing a program feature graph provided by the present invention.
[0022] Figure 4It is an implementation scheme of the Java deserialization vulnerability mining method provided by the present invention in a real scenario.
[0023] Figure 5 It is a structural schematic diagram of a Java deserialization vulnerability mining device provided by the present invention.
[0024] Figure 6 It is a structural schematic diagram of the electronic device provided by the present invention. DETAILED DESCRIPTION
[0025] In order to make the purpose, technical solution and advantages of the present invention clearer, the technical solution of the present invention will be clearly and completely described below in conjunction with the drawings of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0026] The present invention is described in detail below in conjunction with the accompanying drawings of the specification. The specific operating method in the method embodiment can also be applied to the device embodiment or the system embodiment. In the description of the present invention, unless otherwise specified, "at least one" includes one or more. "Multiple" refers to two or more. For example, at least one of A, B and C includes: A exists alone, B exists alone, A and B exist at the same time, A and C exist at the same time, B and C exist at the same time, and A, B and C exist at the same time. In the present invention, " / " means or, for example, A / B can mean A or B; "and / or" in this article is only a kind of association relationship that describes the associated objects, indicating that there can be three relationships. For example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone.
[0027] Deserialization vulnerabilities are a type of vulnerability that is extremely harmful and has a wide impact. They generally occur in systems that use object-oriented languages such as Java.
[0028] Java's serialization and deserialization mechanism plays an important role in distributed computing, data persistence, and remote method calls. Its role is to encode the state and class information of objects in the Java language into byte streams for storage or transmission, and decode and restore them to the original objects when needed. However, this mechanism has become a potential source of security risks in applications. Specifically, when an application deserializes external input data, if the source or content of the data is not fully verified, attackers can use the deserialization mechanism to execute certain dangerous functions based on the object-oriented characteristics of the Java language through carefully constructed malicious data, and ultimately achieve remote code execution, sensitive information theft and other malicious behaviors.
[0029] Identifying Java deserialization vulnerabilities is of great significance to maintaining cyberspace security. The automated detection of deserialization vulnerabilities has attracted widespread attention from academia and industry in recent years. In recent years, researchers have proposed a variety of methods to address this challenge, mainly including solutions based on static program analysis and solutions based on dynamic testing.
[0030] Solutions based on static analysis usually build a global representation graph of the program, analyze the interaction between data flow and control flow, and identify suspicious call sequences. Although static analysis methods cover a wide range, they still face limitations. First, the Java language has many flexible dynamic features, such as dynamic proxy and reflective call, which facilitate the implementation of functions, but they become obstacles in the static program analysis process. Considering these features will significantly increase the complexity of the program graph, which will lead to state explosion and analysis failure in the subsequent analysis process, greatly reducing the feasibility of the analysis. Secondly, the number of results obtained by static analysis is huge, and most of these results often contain constraints that cannot be met in actual execution, resulting in a large number of false positives in solutions based solely on static analysis methods, and a lot of manpower is required to analyze the results.
[0031] The scheme based on dynamic testing makes up for the shortcomings of static analysis to a certain extent. Some academic work uses directed fuzz testing technology to construct attack payloads based on the results given by static analysis schemes, and use this to verify the correctness of static analysis results. However, in practice, this problem still lacks a complete solution. First, although the control flow and data flow information extracted from the static analysis graph can assist in the generation of injection objects, it cannot directly provide a blueprint for building the object hierarchy. Secondly, the current existing schemes still only mutate the objects used for injection to bypass various potential constraints in the deserialization process. However, in some cases, the payload construction needs to change the serialization process itself, not just the objects used for injection, but also the classes used in the serialization process. The current dynamic verification solution focuses on the changes in the object structure and lacks the ability to effectively mutate the classes used in the serialization process, and thus cannot effectively verify potential deserialization vulnerabilities.
[0032] In summary, the current mainstream solutions have problems such as difficulty in analyzing Java dynamic characteristics, high complexity of exploit chain search, and lack of modification of the serialization process itself. Therefore, it is necessary to develop a more efficient and comprehensive Java deserialization vulnerability mining method that can reduce the analysis overhead as much as possible while considering Java dynamic characteristics, and support modification of the deserialization process itself when constructing attack payloads.
[0033] In view of the defects existing in the prior art, the present invention proposes a Java deserialization vulnerability mining method to solve the problems in the prior art such as high complexity of exploit chain search due to the dynamic characteristics of Java and lack of ability to modify the serialization process itself.
[0034] The present invention will be described in detail below in conjunction with specific implementation modes.
[0035] In some specific embodiments of the present invention, Figure 1 As shown, this solution provides a Java deserialization vulnerability mining method, including: Step 100: statically analyze the Java program file of the software system to be tested to construct a program feature graph for the Java program file, wherein the program feature graph is used to represent control flow information, data flow information, and function call relationship information of the Java program; Step 200: Search the program feature graph to find suspicious function call sequences, where the suspicious function call sequences are function calls that have security risks or potential vulnerabilities in the Java program; Step 300: Evaluate the suspicious function call sequence, and update the program feature graph in real time according to the evaluation result; Step 400: Search the program feature graph after real-time update. If the search output is a complete calling sequence from the deserialization function to the dangerous function, generate a payload corresponding to the complete calling sequence in a three-dimensional mutation manner based on the search results, wherein the three-dimensional mutation includes field value mutation, method call mutation and class change mutation.
[0036] It should be noted that the existing vulnerability mining solutions cannot fully consider the dynamic characteristics of Java, resulting in a high false positive rate. The control flow and data flow information extracted from the static analysis graph cannot directly provide a blueprint for building the object hierarchy, making it difficult to fully guide the dynamic testing process. They also lack the ability to modify the serialization process itself, and thus cannot effectively verify potential deserialization vulnerabilities, limiting the depth and breadth of vulnerability mining.
[0037] Therefore, the present invention improves the program feature graph obtained by static program analysis by combining dynamic test results, and uses a dynamic search strategy on the graph to screen suspicious function call sequences, thereby improving the accuracy and efficiency of vulnerability mining. At the same time, the present invention adopts multi-angle mutation to improve vulnerability coverage.
[0038] The above steps are described in detail below through specific embodiments.
[0039] Step 100: statically analyze the Java program file of the software system to be tested to construct a program feature graph for the Java program file, wherein the program feature graph is used to represent control flow information, data flow information, and function call relationship information of the Java program; In some possible implementations of the present invention, the Java program file is a Java archive file or a directory containing Java class files; The static analysis of the Java program files of the software system to be tested to construct a program feature graph for the Java files specifically includes: Perform static analysis on the input Java program file and each class in the current class path to extract the class name, interface method name, and parameter type; Build a virtual call graph by merging paths that share the same name method to identify potential calling relationships between interface methods; Performing taint analysis on the virtual call graph and marking a data source node and a data sink node, wherein the data source node is a method for deserializing input data, and the initial value of the data sink node is a predefined suspicious method; In the virtual call graph, each interface method is added to the virtual call edge of the Java dynamic proxy processing function to generate a program feature graph for the Java file.
[0040] Specifically, this embodiment provides an implementation method for constructing a program feature graph, by performing static analysis on the input Java program file and each class under the current class path, incorporating classes, interface methods, and parameter types into the program feature graph, and considering the dynamic proxy and reflection characteristics of Java objects, adding virtual call edges to the program feature graph.
[0041] In a possible embodiment, a Java archive (jar) file to be analyzed is statically analyzed to construct a program feature graph, and after the construction is completed, the feature graph is continuously searched to find suspicious call sequences.
[0042] Specifically, we first perform static analysis on the input file and each class in the current class path, then build a virtual call graph by merging the paths of methods that share the same name and perform taint analysis to exclude completely uncontrollable call sequences in the search phase. At the same time, based on the characteristics of Java dynamic proxy functions, we add virtual call edges to the graph to take them into consideration.
[0043] Furthermore, after the graph is constructed, the calling sequence from the data source node to the data sink node will be searched. According to the characteristics of the deserialization vulnerability, the data source node is the method for deserializing input data, and the initial value of the data sink node is a pre-defined suspicious method.
[0044] Step 200: Search the program feature graph to find suspicious function call sequences, where the suspicious function call sequences are function calls that have security risks or potential vulnerabilities in the Java program; In some possible implementations of the present invention, searching the program feature graph to find a suspicious function call sequence specifically includes: Starting from a data source node in the program feature graph, searching for a function call sequence to a data sink node; The found function calling sequence is determined as a suspicious function calling sequence.
[0045] Specifically, this embodiment provides an implementation method for finding suspicious function call sequences, by searching the constructed program feature graph, determining function calls in the Java program that have security risks or potential vulnerabilities, and determining the function calls as permitted function calls.
[0046] Step 300: Evaluate the suspicious function call sequence, and update the program feature graph in real time according to the evaluation result; In some possible implementations of the present invention, the evaluating the suspicious function call sequence specifically includes: Decomposing the suspicious function call sequence into paths each having a length of 1; A challenge-based fuzzy test is performed on each path from the data sink node to the data source node to determine whether the path is a feasible path or a false positive call edge.
[0047] Specifically, this embodiment provides an implementation method for evaluating a found suspicious function call sequence, by performing a fuzzy test on the suspicious function call sequence, and determining whether each path in the sequence is a feasible path or a false positive call edge according to the test result.
[0048] In a possible embodiment, once any suspicious path is searched in the program feature graph, it is disassembled into multiple paths of length 1, and a challenge-based fuzz test is performed on each path from the data sink node to the data source node to determine whether the path is feasible or a false positive call edge.
[0049] In some possible implementations of the present invention, the real-time updating of the program feature graph according to the evaluation result specifically includes: If the path is a feasible path, the caller is included in the data sink node set to add additional attention to the path in subsequent analysis; If the path is a false positive call edge, the path is marked as an uncontrollable edge in the program feature graph to exclude the edge in subsequent analysis.
[0050] Specifically, this embodiment provides an implementation method for real-time updating of the program feature graph. According to the evaluation results of each path in the suspicious function call sequence, for feasible paths, the caller is included in the data sink node set so that extra attention is given to it in subsequent analysis; for false positive call edges, they are marked as uncontrollable edges in the program feature graph so as to exclude the edge in subsequent analysis.
[0051] The above-mentioned setting of this embodiment determines the feasibility of each path of the suspicious function call sequence, and updates the program feature graph in real time according to the determination result. The update result of the feature graph will affect the call sequence search in the graph in real time, thereby greatly reducing the complexity of the graph search and improving the support level of the solution for longer call sequences.
[0052] Step 400: Search the program feature graph after real-time update. If the search output is a complete calling sequence from the deserialization function to the dangerous function, generate a payload corresponding to the complete calling sequence in a three-dimensional mutation manner based on the search results, wherein the three-dimensional mutation includes field value mutation, method call mutation and class change mutation.
[0053] In some possible implementations of the present invention, generating a payload corresponding to the complete call sequence in a three-dimensional variation manner according to the search results specifically includes: If the search output is a complete call sequence from the deserialization function to the dangerous function, for the object to be input, randomly select the attributes of the object and randomly transform the object to complete the field value mutation; For the object to be input, execute the method of its corresponding class with random parameters to complete the method call mutation; For the object to be input, the modified class is used to replace the originally loaded class to complete the class change mutation.
[0054] Specifically, this embodiment provides an implementation method for generating a payload, by searching a program feature graph that is updated in real time, and based on the search results, a three-dimensional mutation method of field value mutation, method call mutation, and class change mutation is used for the search output as a complete calling sequence from a deserialization function to a dangerous function to generate a payload corresponding to the complete calling sequence.
[0055] In some possible implementations of the present invention, after generating the payload, the method further includes: Based on the payload, the software system to be tested is verified to determine whether the software system has a deserialization vulnerability.
[0056] Specifically, the obtained payload is generated through a three-dimensional mutation strategy, which can be used to verify whether the call sequence can really be exploited to trigger the vulnerability. If the generated payload can be successfully executed in the target system and achieve the expected attack effect (such as remote code execution, sensitive information theft, etc.), it proves that the deserialization vulnerability corresponding to the call sequence is real, thereby verifying the feasibility of the vulnerability.
[0057] In some specific embodiments of the present invention, the Java deserialization vulnerability mining solution proposed by the present invention includes two key modules: a dynamic graph search module and a double-loop fuzzy test module, wherein the double-loop fuzzy test module is divided into a feature graph update loop and an exploit chain verification loop. The main workflow of the solution proposed by the present invention is as follows: First, static analysis is performed on the Java archive (jar) file to be analyzed to build a program feature graph. After the construction is completed, the feature graph will be continuously searched to find suspicious call sequences. Specifically, static analysis is first performed on the input file and each class under the current class path. Then, a virtual call graph is built by merging the paths of methods sharing the same name and taint analysis is performed to exclude completely uncontrollable call sequences during the search phase. At the same time, based on the characteristics of Java dynamic proxy functions, virtual call edges are added to the graph to take them into consideration. After the graph is built, the call sequence from the data source (source) node to the data sink (sink) node will be searched. According to the characteristics of the deserialization vulnerability, the data source (source) node is the method for deserializing the input data, and the initial value of the data sink (sink) node is a pre-defined suspicious method.
[0058] Furthermore, the feature graph update loop will select the preliminary results of the search process for evaluation, and update the feature graph in real time according to the evaluation results. Specifically, once any suspicious path is searched in the program feature graph, the feature graph update loop will decompose it into multiple paths of length 1, and perform challenge-based fuzz testing on each path from the data sink node to the data source node to determine whether the path is feasible or a false positive call edge. For feasible paths, the caller is included in the data sink node set so that it can be given extra attention in the future; for false positive call edges, it is marked as an uncontrollable edge in the program feature graph to exclude the edge in subsequent analysis. The update results of the feature graph will affect the call sequence search in the graph in real time, thereby greatly reducing the complexity of the graph search and improving the support of the solution for longer call sequences.
[0059] Furthermore, once the graph search outputs the complete call sequence from the deserialized entry point to the dangerous function, the exploit chain verification loop will be initiated, which takes the entire call sequence as input and applies a three-dimensional mutation strategy to generate the payload. Specifically, three types of mutations will be performed: field value mutation, method call, and class change. Field value mutation means that for the object to be input, the fuzz tester randomly selects its attributes and randomly transforms them; method call means that for the object to be input, the method of its corresponding class is executed with random parameters; class change means that the fuzz tester replaces the class originally loaded by the Java Virtual Machine (JVM) with a modified class. Based on this, the scheme will adopt a structured approach to build the payload, which can not only mutate the injected object itself, but also change the serialization process itself.
[0060] In some possible implementations of the present invention, when implementing the present invention, it is first necessary to build a Java deserialization vulnerability exploit chain analyzer based on dynamic graph search and double-loop fuzz testing. To this end, it is necessary to implement several functional modules including feature graph update loop and exploit chain verification loop and organize them to collaborate. A feasible module collaboration mode is as follows: Figure 2 shown.
[0061] like Figure 2 In step (1) and step (2), it is first necessary to construct a program feature graph for a Java archive (jar) file. In this embodiment, the Java static program analysis framework Soot is used to construct a program feature graph for a Java archive (jar) file. Specifically, all classes in the current class path and the input Java archive (jar) file are first scanned and necessary information is extracted from them. After the program feature graph is preliminarily constructed using a method similar to other related works, all interface methods in Java are extracted and virtual call edges from these nodes to the Java dynamic proxy processing function are connected. Figure 3 The figure is a schematic diagram of the final program feature graph, which shows the general structure of the feature graph. The path from the ReadObject node to the newInstance node in the figure is a suspicious Java deserialization utilization chain.
[0062] like Figure 2Steps (3) and (4) are used to implement the feature graph update loop and update the feature graph in real time based on it. The loop decomposes the suspicious call sequence into call edges of length 1 and uses them as input. The fuzz tester will extract the basic information of the caller function and the called function of the call edge, and set a random challenge based on the parameter type of the called function, and use this to guide the caller function to call the called function with the same parameters as the challenge, so as to determine the controllability of the call edge. For completely uncontrollable call edges, this call edge will be cropped on the feature graph to ignore the call edge in the subsequent analysis process; for controllable call edges, the called function will be considered as a data sink node set for additional consideration.
[0063] like Figure 2 Step (5) is used to implement the chain verification loop and conduct a more thorough verification of the analysis results based on it. Unlike the feature map update loop, this fuzz test loop uses the complete call sequence from the data source node to the data sink node as input, and uses the directed fuzz test technology in a three-dimensional mutation manner to generate a payload corresponding to the call sequence. For the field mutation dimension in the three-dimensional mutation, the reflection function provided by Java is used in this embodiment to randomly modify the properties of the injected object; for the method execution dimension, similar to the field mutation, the reflection function is still used to execute random methods such as objects with random parameters; for the class mutation dimension, with the help of the Java agent, a set of class replacement strategies are defined, so that the Java virtual machine (JVM) loads our modified class instead when loading the class, thereby realizing the control of the deserialization process itself.
[0064] It is understandable that after the construction of the Java deserialization vulnerability exploit chain analyzer based on dynamic graph search and double-loop fuzz testing is completed, there are many ways to implement it in real scenarios without departing from the principles of the present invention. Figure 4 The figure is a schematic diagram of an implementation scheme in one of the scenarios, which is only used to assist technicians in understanding and implementing the invention. The scenario described in the figure is to mine Java deserialization vulnerabilities in a software system when a Java archive (jar) file is available. When the present invention is implemented on this target, the Java archive file (jar) of the software system to be tested is first extracted and used as the input of the Java deserialization vulnerability analyzer proposed in the present invention. The analyzer will use the payload and its corresponding information as output, and security testers can test the software system based on this, thereby achieving goals such as Java deserialization vulnerability mining.
[0065] Through the above-mentioned configuration of the embodiment of the present invention, compared with the prior art, the Java deserialization vulnerability mining method provided by the present invention has the following outstanding advantages: In-depth integration of static and dynamic analysis: This invention combines the global perspective of static analysis with the actual verification capability of dynamic testing. By optimizing feature graphs in real time and constructing payload verification and utilization chains, it uses dynamic testing results to compensate for the lack of accuracy of static analysis, thus achieving synergy and complementarity between static analysis and dynamic testing.
[0066] Efficient path search and optimization mechanism: Through the feature graph update loop, the present invention can dynamically trim invalid paths and pay extra attention to potential critical paths. This dynamic optimization mechanism based on challenge feedback not only reduces the search space, but also reduces the complexity of path search, which can significantly improve the analysis efficiency, especially when long call chains are involved.
[0067] Comprehensive coverage of three-dimensional mutation strategy: Using chain verification loops to adopt field value mutation, method call and class change three-dimensional mutation strategy, not only multi-angle mutation of injection objects, but also support behavioral modification of the serialization process itself. This comprehensive mutation strategy significantly improves the coverage of the solution for vulnerabilities.
[0068] Improved Java dynamic proxy feature analysis mechanism: This invention effectively solves the analysis problem brought by the dynamic proxy feature in the Java language by dynamically updating the program feature graph. By adding dynamically generated virtual call edges to the feature graph and optimizing the graph structure in real time, the path search complexity is controlled while supporting the analysis of the feature.
[0069] Wide application potential: Through experimental testing, the scheme of the present invention has an overall better effect than the existing most advanced solutions when conducting vulnerability mining on real-world cases. It can provide a new technical means for automated Java deserialization vulnerability mining, showing great application potential and practical value.
[0070] In general, the present invention provides a more complete and effective solution for discovering Java deserialization vulnerabilities through a technical framework that combines dynamic and static analysis.
[0071] The Java deserialization vulnerability mining device provided by the present invention is described below. The Java deserialization vulnerability mining device described below and the Java deserialization vulnerability mining method described above can be referenced to each other.
[0072] In some specific embodiments of the present invention, Figure 5 As shown, this solution provides a Java deserialization vulnerability mining device, including the following modules: A program feature graph construction module 51 is used to perform static analysis on the Java program file of the software system to be tested to construct a program feature graph for the Java program file, wherein the program feature graph is used to represent control flow information, data flow information and function call relationship information of the Java program; A search module 52, used to search the program feature graph to find suspicious function call sequences, where the suspicious function call sequences are function calls that have security risks or potential vulnerabilities in the Java program; A program feature graph updating module 53, used for the program feature graph updating module, is used to evaluate the suspicious function call sequence and update the program feature graph in real time according to the evaluation result; The payload generation module 54 is used to search the program feature graph after real-time update. If the search output is a complete calling sequence from a deserialization function to a dangerous function, a payload corresponding to the complete calling sequence is generated in a three-dimensional mutation manner based on the search results, wherein the three-dimensional mutation includes field value mutation, method call mutation and class change mutation.
[0073] The Java deserialization vulnerability mining device provided in the embodiment of the present invention has an implementation principle and beneficial effects similar to the implementation principle and beneficial effects of the Java deserialization vulnerability mining method shown in the above embodiment. Please refer to the implementation principle and beneficial effects of the Java deserialization vulnerability mining method shown in the above embodiment, and no further details will be given here.
[0074] Figure 6 An example of a physical structure diagram of an electronic device is shown in FIG. Figure 6As shown, the electronic device may include: a processor (processor) 610 , a communication interface (Communications Interface) 620 , a memory (memory) 630 and a communication bus 640 , wherein the processor 610 , the communication interface 620 , and the memory 630 communicate with each other through the communication bus 640 . The processor 610 can call the logic instructions in the memory 630 to execute the Java deserialization vulnerability mining method, which includes: performing static analysis on the Java program file of the software system to be tested to construct a program feature graph for the Java program file, wherein the program feature graph is used to represent the control flow information, data flow information and function call relationship information of the Java program; searching the program feature graph to find suspicious function call sequences, wherein the suspicious function call sequences are function calls that have security risks or potential vulnerabilities in the Java program; evaluating the suspicious function call sequences, and updating the program feature graph in real time according to the evaluation results; searching the program feature graph after real-time update, and if the search output is a complete call sequence from the deserialization function to the dangerous function, then generating a payload corresponding to the complete call sequence in a three-dimensional mutation manner according to the search results, wherein the three-dimensional mutation includes field value mutation, method call mutation and class change mutation.
[0075] In addition, the logic instructions in the above-mentioned memory 630 can be implemented in the form of a software functional unit and can be stored in a computer-readable storage medium when it is sold or used as an independent product. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art or the part of the technical solution, can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present invention. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), disk or optical disk, etc. Various media that can store program codes.
[0076] On the other hand, the present invention also provides a computer program product, which includes a computer program, which can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can execute the Java deserialization vulnerability mining method provided by the above methods, which includes: statically analyzing the Java program file of the software system to be tested to construct a program feature graph for the Java program file, wherein the program feature graph is used to represent the control flow information, data flow information and function call relationship information of the Java program; searching the program feature graph to find suspicious function call sequences, wherein the suspicious function call sequences are function calls that have security risks or potential vulnerabilities in the Java program; evaluating the suspicious function call sequences, and updating the program feature graph in real time according to the evaluation results; searching the program feature graph after real-time update, and if the search output is a complete call sequence from the deserialization function to the dangerous function, then generating a payload corresponding to the complete call sequence in a three-dimensional mutation manner according to the search results, wherein the three-dimensional mutation includes field value mutation, method call mutation and class change mutation.
[0077] On the other hand, the present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, is implemented to execute the Java deserialization vulnerability mining method provided by the above-mentioned methods, the method comprising: statically analyzing the Java program file of the software system to be tested to construct a program feature graph for the Java program file, the program feature graph being used to represent the control flow information, data flow information and function call relationship information of the Java program; searching the program feature graph to find suspicious function call sequences, the suspicious function call sequences being function calls that have security risks or potential vulnerabilities in the Java program; evaluating the suspicious function call sequences, and updating the program feature graph in real time according to the evaluation results; searching the program feature graph after real-time update, and if the search output is a complete call sequence from the deserialization function to the dangerous function, then generating a payload corresponding to the complete call sequence in a three-dimensional mutation manner according to the search results, wherein the three-dimensional mutation includes field value mutation, method call mutation and class change mutation.
[0078] The device embodiments described above are merely illustrative, wherein the units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place, or they may be distributed on multiple network units. Some or all of the modules may be selected according to actual needs to achieve the purpose of the scheme of this embodiment. Ordinary technicians in this field can understand and implement it without paying creative labor.
[0079] Through the description of the above implementation methods, those skilled in the art can clearly understand that each implementation method can be implemented by means of software plus a necessary general hardware platform, and of course, can also be implemented by hardware. Based on this understanding, the above technical solution is essentially or the part that contributes to the prior art can be embodied in the form of a software product, and the computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, a disk, an optical disk, etc., including a number of instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.
[0080] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A Java deserialization vulnerability mining method, characterized in that: include: Performing static analysis on the Java program files of the software system to be tested to construct a program feature graph for the Java program files, wherein the program feature graph is used to represent control flow information, data flow information, and function call relationship information of the Java program; Searching the program feature graph to find suspicious function call sequences, where the suspicious function call sequences are function calls that have security risks or potential vulnerabilities in the Java program; Evaluate the suspicious function call sequence, and update the program feature graph in real time according to the evaluation result; The program feature graph updated in real time is searched. If the search output is a complete calling sequence from a deserialized function to a dangerous function, a payload corresponding to the complete calling sequence is generated in a three-dimensional mutation manner based on the search results, wherein the three-dimensional mutation includes field value mutation, method call mutation, and class change mutation.
2. The Java deserialization vulnerability mining method according to claim 1 is characterized in that: The Java program file is a Java archive file or a directory containing Java class files; The static analysis of the Java program files of the software system to be tested to construct a program feature graph for the Java files specifically includes: Perform static analysis on the input Java program file and each class in the current class path to extract the class name, interface method name, and parameter type; Build a virtual call graph by merging paths that share the same name method to identify potential calling relationships between interface methods; Performing taint analysis on the virtual call graph and marking a data source node and a data sink node, wherein the data source node is a method for deserializing input data, and the initial value of the data sink node is a predefined suspicious method; In the virtual call graph, each interface method is added to the virtual call edge of the Java dynamic proxy processing function to generate a program feature graph for the Java file.
3. The Java deserialization vulnerability mining method according to claim 2 is characterized in that: The searching of the program feature graph to find a suspicious function call sequence specifically includes: Starting from a data source node in the program feature graph, searching for a function call sequence to a data sink node; The found function calling sequence is determined as a suspicious function calling sequence.
4. The Java deserialization vulnerability mining method according to claim 1 is characterized in that: The evaluating the suspicious function call sequence specifically includes: Decomposing the suspicious function call sequence into paths each having a length of 1; A challenge-based fuzzy test is performed on each path from the data sink node to the data source node to determine whether the path is a feasible path or a false positive call edge.
5. The Java deserialization vulnerability mining method according to claim 4 is characterized in that: The real-time updating of the program feature graph according to the evaluation result specifically includes: If the path is a feasible path, the caller is included in the data sink node set to add additional attention to the path in subsequent analysis; If the path is a false positive call edge, the path is marked as an uncontrollable edge in the program feature graph to exclude the edge in subsequent analysis.
6. The Java deserialization vulnerability mining method according to claim 1 is characterized in that: Generating a payload corresponding to the complete call sequence in a three-dimensional variation manner according to the search results specifically includes: If the search output is a complete call sequence from the deserialization function to the dangerous function, for the object to be input, randomly select the attributes of the object and randomly transform the object to complete the field value mutation; For the object to be input, execute the method of its corresponding class with random parameters to complete the method call mutation; For the object to be input, the modified class is used to replace the originally loaded class to complete the class change mutation.
7. The Java deserialization vulnerability mining method according to any one of claims 1 to 6, characterized in that: After generating the payload, the method further comprises: Based on the payload, the software system to be tested is verified to determine whether the software system has a deserialization vulnerability.
8. A Java deserialization vulnerability mining device, characterized in that: include: A program feature graph construction module is used to perform static analysis on the Java program files of the software system to be tested to construct a program feature graph for the Java program files, wherein the program feature graph is used to represent control flow information, data flow information, and function call relationship information of the Java program; A search module, used to search the program feature graph to find suspicious function call sequences, where the suspicious function call sequences are function calls that have security risks or potential vulnerabilities in the Java program; A program feature graph updating module is used for evaluating the suspicious function call sequence and updating the program feature graph in real time according to the evaluation result; The payload generation module is used to search the program feature graph that is updated in real time. If the search output is a complete calling sequence from a deserialized function to a dangerous function, a payload corresponding to the complete calling sequence is generated in a three-dimensional mutation manner based on the search results, wherein the three-dimensional mutation includes field value mutation, method call mutation and class change mutation.
9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and running on the processor, characterized in that: When the processor executes the computer program, the Java deserialization vulnerability mining method as described in any one of claims 1 to 7 is implemented.
10. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the Java deserialization vulnerability mining method according to any one of claims 1 to 7 is implemented.
Citation Information
Cited By
Attack detection method and device based on deserialization vulnerability
CN120811690A