Detection method and system for binding service vulnerabilities of application program

By decoding, disassembly and static analysis of Android system applications, combined with dynamic fuzz testing, vulnerability detection of custom binding services was successfully achieved, solving the problem of difficult to detect application binding services in the existing technology, and improving detection efficiency and accuracy.

CN120124064AActive Publication Date: 2025-06-10HUAZHONG UNIV OF SCI & TECH

Patent Information

Application Number
CN202510126993.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-27
Publication Date
2025-06-10
Estimated Expiration
2045-01-27

AI Technical Summary

Technical Problem

The prior art is difficult to effectively detect and identify application custom binding service vulnerabilities in Android systems, making it difficult to detect and resolve security risks.

Method used

By extracting the application's installation package file, decoding and parsing the application manifest file, disassembly and statically analyzing the binary file, obtaining the RPC implementation method of the service that can be bound, filtering the interface call processing method, generating input variable test cases, and vulnerability detection is performed through dynamic fuzzing testing.

Benefits of technology

It realizes effective vulnerability detection for applying custom binding services to Android systems, improves the efficiency and accuracy of vulnerability detection, reduces the workload of manual analysis, and narrows the scope of analysis and verification.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120124064A_ABST
    Figure CN120124064A_ABST
Patent Text Reader

Abstract

The invention discloses a method and a system for detecting binding service vulnerabilities of an application program. The method comprises the following steps: firstly, collecting related information of a to-be-detected application, completing preliminary extraction of application component information, and screening out candidate applications and service components; positioning to a binding service RPC interface disclosed by the application, extracting all callable methods of the application, obtaining decompiled method codes, constructing input for triggering method vulnerabilities, generating a corresponding test application case, performing fuzzy testing on candidate RPC methods on test equipment, analyzing influences and discovering vulnerabilities; therefore, vulnerability detection of the Android system application custom binding service is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of vulnerability detection, and in particular to a method and system for detecting application program bound service vulnerabilities. Background Art

[0002] A bound service refers to associating a certain service (such as a database, API or other application program) with a client program in a network or software system, enabling the client to call the functions of the service. In the Android operating system, the bound service is an important component for implementing inter-process communication (IPC).

[0003] The IPC (Inter-Process Communication) mechanism is a mechanism for communication between different processes. In the Android operating system, since application programs and system services usually run in different processes, a mechanism is needed to support communication and data exchange between them. The IPC mechanism of the Android system is mainly based on the Binder driver. Binder is an IPC mechanism in the Android system, which provides an efficient cross-process communication method. In the Binder mechanism, there are three main roles, including the client, the server, and the Binder driver responsible for handling communication between the two. A Service is a component used to perform long-running tasks or handle remote requests in the background. A Service can communicate with a client through a binding mechanism (returning a Binder object implementing an interface). The binding mechanism allows the client to establish a connection with the Service and interact through this connection. Most core functions of the Android system are decomposed into separate system service components, System Service, allowing third-party application programs to safely and indirectly access protected resources.

[0004] Due to the fact that Android system services possess a large amount of system resources and high-level permissions, their security issues have attracted much attention. In recent years, there have been a great deal of research works, and many security issues have also been discovered, including: imperfect documentation, permission re-delegation, inconsistent access control, lack of input exception handling, etc. With people's deep dependence on mobile applications for various life needs, application programs themselves have also become an important source of user-sensitive data, especially basic applications providing services such as office work, social networking, and shopping. In addition, for some privileged pre-installed applications, the exposed services also pose relatively large security risks. However, the problems existing in the custom service interfaces of Android system applications are rarely discussed and studied at present. Summary of the Invention

[0005] The present invention realizes the vulnerability detection of the custom binding service of Android system applications by providing a detection method and system for the vulnerabilities of application binding services.

[0006] The present invention provides a detection method for the vulnerabilities of application binding services, including:

[0007] Extract the installation package file from the application to be detected;

[0008] Decode the installation package file to obtain the application manifest file, and parse the application manifest file to obtain the exposed service components;

[0009] Disassemble the binary file of the application to be detected to obtain the assembly code, perform static analysis on the assembly code, and find the services that can be bound from the exposed service components;

[0010] Obtain the RPC implementation method of the service that can be bound;

[0011] Screen out the interface call processing method from the RPC implementation method, extract and parse the abstract syntax tree of the interface call processing method, obtain the call interface number and name description information, as well as the related operations of reading and writing packages, analyze the conditional information of the branches of the interface, obtain the type of input variables and the constraint information of the call method, and also extract the field composition of the custom type input variables used to construct complex variable types. Use the call interface number, the name description information, the type of input variables, the constraint information of the call method, and the field composition of the custom type input variables as the input information of the RPC implementation method call interface;

[0012] Perform static analysis on the conditional statements, loop structures, and data flows in the code of the RPC implementation method to obtain the input variable dependency relationship of the RPC implementation method;

[0013] Adopt a constraint-based test generation method and combinatorial testing technology, and generate input values that meet the set conditions based on the input information of the RPC implementation method call interface and the input variable dependency relationship of the RPC implementation method to obtain input variable test cases;

[0014] Store the input information of the RPC implementation method call interface, the input variable test cases, and the information of the exposed service components to which the RPC implementation method belongs in the test device, install the test program on the test device for dynamic fuzz testing, and obtain the vulnerability detection conclusion.

[0015] Specifically, the performing static analysis on the assembly code and finding the services that can be bound from the exposed service components includes:

[0016] Traverse the exposed service class codes one by one according to the service names of the exposed service components, and check whether the class methods contain binding methods;

[0017] If no binding method is found in the current service class, continue to check whether its inherited parent class overrides the binding method until the service base class is traced and the binding method is found;

[0018] Check whether the return type of the binding method is the Binder class and its subclasses, and judge whether it inherits the Binder class by extracting the class inheritance relationship of each class; if so, the service can be bound, and the bindable service is obtained.

[0019] Specifically, the RPC implementation method for obtaining the bindable service includes:

[0020] Obtain all interface methods registered in the interface inheritance chain of the return Binder class of the bindable service, and find the RPC implementation methods of all the interface methods from all subclasses.

[0021] Specifically, in the process of finding the RPC implementation methods of all the interface methods from all subclasses, search from subclasses to parent classes in sequence, and ensure that the RPC implementation methods in subclasses are not overwritten by parent classes; if the current class does not implement the interface, extract the code of all methods of the class and its subclasses.

[0022] Specifically, the method of screening out the interface call processing method from the RPC implementation methods includes:

[0023] Decompile the RPC implementation method to obtain programming code;

[0024] Input the programming code into the analysis model for analysis, and output sensitive candidate RPC implementation methods;

[0025] Screen out the interface call processing method from the candidate RPC implementation methods.

[0026] The present invention also provides a detection system for application program binding service vulnerabilities, including:

[0027] An installation package file extraction module, configured to extract the installation package file from the application program to be detected;

[0028] A file parsing module, configured to decode the installation package file to obtain an application manifest file, and parse the application manifest file to obtain exposed service components;

[0029] A static analysis module, which is used to disassemble the binary file of the application to be detected to obtain assembly code, perform static analysis on the assembly code, and find the bindable services from the exposed service components;

[0030] An RPC implementation method acquisition module, which is used to acquire the RPC implementation methods of the bindable services;

[0031] A call interface input information generation module, which is used to screen out the interface call processing methods from the RPC implementation methods, extract the abstract syntax tree of the interface call processing methods and parse them, obtain the call interface numbers and name description information, as well as the related operations of reading and writing packets, analyze the conditional information of the branches of the interfaces, obtain the types of input variables and the constraint information of the call methods, and also extract the field compositions of the custom type input variables used to construct complex variable types. The call interface numbers, the name description information, the types of input variables, the constraint information of the call methods, and the field compositions of the custom type input variables are used as the RPC implementation method call interface input information;

[0032] An input variable dependency relationship generation module, which is used to perform static analysis on the conditional statements, loop structures, and data flows in the code of the RPC implementation methods to obtain the input variable dependency relationships of the RPC implementation methods;

[0033] An input variable test case generation module, which is used to adopt a constraint-based test generation method and combinatorial testing technology, and based on the RPC implementation method call interface input information and the RPC implementation method input variable dependency relationships, generate input values that meet the set conditions to obtain input variable test cases;

[0034] A vulnerability detection module, which is used to store the RPC implementation method call interface input information, the input variable test cases, and the information of the exposed service components to which the RPC implementation methods belong in a test device, install a test program on the test device for dynamic fuzz testing, and draw a vulnerability detection conclusion.

[0035] Specifically, the static analysis module includes:

[0036] A disassembly unit, which is used to disassemble the binary file of the application to be detected to obtain assembly code;

[0037] A binding method query unit, which is used to traverse the exposed service class codes one by one according to the service names of the exposed service components, and check whether the class methods contain binding methods; if no binding method is found in the current service class, continue to check whether its inherited parent class overrides the binding method until the service base class is traced and the binding method is found;

[0038] A bound service query unit is used to check whether the return type of the binding method is the Binder class and its subclasses, and determine whether it inherits the Binder class by extracting the class inheritance relationship of each class; if so, the service can be bound, and the bindable service is obtained.

[0039] Specifically, the RPC implementation method acquisition module is specifically used to obtain all the interface methods registered in the interface inheritance chain of the return Binder class of the bindable service, and find the RPC implementation methods of all the interface methods from all the subclasses.

[0040] Specifically, the call interface input information generation module includes:

[0041] A decompilation unit is used to decompile the RPC implementation method to obtain programming code;

[0042] A sensitive candidate RPC implementation method analysis unit is used to input the programming code into an analysis model for analysis, and output sensitive candidate RPC implementation methods;

[0043] An interface call processing method screening unit is used to screen out interface call processing methods from the candidate RPC implementation methods;

[0044] A call interface input information generation unit is used to extract the abstract syntax tree of the interface call processing method and parse it, obtain the call interface number and name description information, as well as the related operations of reading and writing packages, analyze the conditional information of the branches of the interface, obtain the types of input variables and the constraint information of the call method, and also extract the field composition of the custom type input variables used to construct complex variable types. The call interface number, the name description information, the types of input variables, the constraint information of the call method, and the field composition of the custom type input variables are used as the RPC implementation method call interface input information.

[0045] One or more technical solutions provided in the present invention have at least the following technical effects or advantages:

[0046] 1. First, collect relevant information of the application to be detected, complete the preliminary extraction of application component information, and screen out candidate applications and service components; then locate the publicly available bound service RPC interface of the application, extract all the callable methods thereof, obtain the decompiled method code, construct the input that triggers the method vulnerability, and generate corresponding test application cases to perform fuzz testing on the candidate RPC methods on the test device, analyze the impact and discover vulnerabilities, thereby realizing the vulnerability detection of the custom bound service of Android system applications.

[0047] 2. The present invention realizes a candidate RPC method for effectively extracting application-defined bound services and identifying potential security risks. Through disassembling the application installation package and performing precise static analysis, and combining with using large models for method screening, it can quickly lock potential targets under attack, reduce manual input, narrow the scope of analysis and verification, and improve the efficiency of vulnerability detection.

[0048] 3. The present invention uses dynamic fuzz testing method to perform further vulnerability discovery and exploitation on the candidate RPC methods detected statically. By collecting input information and its dependencies through static analysis, using constraint-based test generation method and combinatorial testing technology to construct input features that can trigger vulnerabilities, and relying on test programs to automatically execute tests in test devices or simulators, and discovering vulnerabilities by analyzing and observing test logs and device states, and further completing vulnerability verification. Description of the Drawings

[0049] Figure 1 It is a flowchart of the detection method for application program bound service vulnerabilities provided by the embodiment of the present invention;

[0050] Figure 2 It is a schematic diagram of the detection method for application program bound service vulnerabilities provided by the embodiment of the present invention;

[0051] Figure 3 It is a module diagram of the detection system for application program bound service vulnerabilities provided by the embodiment of the present invention. Detailed Embodiments

[0052] The embodiment of the present invention realizes the vulnerability detection of Android system application-defined bound services by providing a detection method and system for application program bound service vulnerabilities.

[0053] The technical solutions in the embodiments of the present invention are to achieve the above technical effects, and the general idea is as follows:

[0054] Attack scenarios for application program bound services: Assume that an attacker discovers an exposed bindable service in a certain application. He can try to bind the vulnerable application service by releasing a malicious third-party application, and inject carefully constructed transaction inputs into the obtained handle object (for example: Binder). The server-side application parses the input parameters in the handle object and calls the corresponding functions, which may bring a series of problems, such as: causing denial-of-service attacks, privilege escalation, arbitrary code execution, or leaking sensitive information, affecting the normal execution of business functions, etc., depending on the payload and the target of the malicious transaction.

[0055] In order to detect whether there is a vulnerability in the bound service of an application, an embodiment of the present invention proposes a detection method for the vulnerability of the bound service of an application. The method includes: 1) Reverse and disassemble the application installation package through a reverse engineering tool, and combine static analysis techniques such as inheritance relationship analysis, control flow graph analysis, and type inference to accurately extract the custom bound services of the application and the exposed RPC methods. Based on the decompiled code, use a large model to screen out candidate RPC methods with security risks, which can quickly lock potential attack targets and narrow the scope of analysis and verification; 2) Clearly define the attack model by deeply analyzing the communication process of the bound service, and use the dynamic fuzzing test method to perform further vulnerability discovery and exploitation on the candidate RPC methods detected statically. Collect input information and its dependencies through static analysis, and use constraint-based test generation methods and combinatorial testing techniques to construct input features that can trigger vulnerabilities. Automatically execute tests in a real device or simulator relying on a test program, and discover vulnerabilities by analyzing and observing test logs and device status, and further complete vulnerability verification. Through a combination of static and dynamic analysis, relevant vulnerabilities can be discovered efficiently and accurately, and the vulnerability exploitation scenario can be directly reproduced.

[0056] To better understand the above technical solution, the above technical solution will be described in detail below in conjunction with the accompanying drawings of the specification and specific implementation manners.

[0057] As Figure 1 and Figure 2 shown, the detection method for the vulnerability of the bound service of an application provided by the embodiment of the present invention includes:

[0058] Step S110: Extract the installation package file from the application to be detected;

[0059] Specifically explain this step. Crawl applications to be analyzed from major mobile application markets and extract them from real devices. Use python crawler technology and the ARIA2 tool to batch download third-party applications from mainstream application markets (such as Xiaomi, Huawei, Samsung, etc.). Pre-installed applications are pre-installed on the device by the device manufacturer or operator at the time of factory, and are usually integrated into the system partition of the device and generally cannot be obtained from the application market. In order to collect as many pre-installed applications in the systems of mobile phone manufacturers as possible, due to the inability to collect a sufficient number of real devices, use a static analysis tool to extract the installation package files of pre-installed applications from the system image file, such as: APK files.

[0060] Step S120: Decode the installation package file to obtain the application manifest file, and parse the application manifest file to obtain the exposed service components;

[0061] Specifically describe this step. Based on the JEB reverse engineering tool, unpack the installation package file, and obtain the exposed service components by parsing the manifest file. After opening the installation package file, generate an analysis context environment. Analyze the metadata and manifest file of the application, extract the service nodes with the android:exported attribute set to true by parsing the application manifest file, or check whether the nodes contain intent-filter implicit intent filtering to identify the exported Service components. Finally, obtain the information of the exposed service components of the application, including the service name, implicit intent filtering rules, and the permissions required to call the service.

[0062] Step S130: Disassemble the binary file of the application to be detected to obtain assembly code, perform static analysis on the assembly code, and find the services that can be bound from the exposed service components;

[0063] Among them, performing static analysis on the assembly code and finding the services that can be bound from the exposed service components includes:

[0064] Traverse the exposed service class code one by one according to the service name of the exposed service components, and check whether the class methods contain binding methods;

[0065] If the binding method cannot be found in the current service class, continue to check whether the parent class it inherits overrides the binding method until the service base class is traced and the binding method is found;

[0066] Check whether the return type of the binding method is the Binder class and its subclasses, and judge whether it inherits the Binder class by extracting the class inheritance relationship of each class; if so, the service can be bound, and the service that can be bound is obtained.

[0067] Specifically, first traverse the exposed service class code one by one according to the service name, and check whether the class methods contain a binding method named onBind with the parameter of the intent object (Intent), which is responsible for receiving the binding intent passed through Binder communication. If the binding method cannot be found in the current service class, continue to check whether the parent class it inherits overrides the binding method until the bound service is found.

[0068] Next, analyze the binding method in the bound service class and the return object type of the method. Construct a control flow graph (CFG) for the code block of the method, and extract the exit blocks (ExitBlocks) for analysis. Traverse the exit blocks one by one, check whether the last executed statement contains a return instruction, and obtain the returned type and value. Since the analyzed code is assembly instructions, the parameter information (if any) obtained in relevant instructions such as return is only the value and type of the register. Therefore, it is necessary to continue analyzing the subsequent instructions for type inference. According to the instruction content, instructions for setting the target register to a constant and an instance object are mainly analyzed. During the analysis, the integration relationship between classes and interfaces and reference assignment statements are considered for dynamic type inference. This is due to the polymorphic nature of the Java language, that is, the type of an object is not determined by the declared type, but by the specific type of the object at runtime. This makes the judgment of the object type more accurate, and can reduce false positives when further analyzing class call methods and fields.

[0069] Finally, check whether the return type of the binding method is the Binder class and its subclasses. Determine whether it inherits the Binder class by extracting the class inheritance relationship of each class. If so, the bound service can be bound.

[0070] Step S140: Obtain the RPC implementation method of the service that can be bound;

[0071] Specifically explain this step. Obtaining the RPC implementation method of the service that can be bound includes:

[0072] Obtain all interface methods registered in the interface inheritance chain of the returned Binder class of the service that can be bound, and find the RPC implementation methods of all interface methods from all subclasses.

[0073] To accurately find all RPC implementation methods, during the process of finding the RPC implementation methods of all interface methods from all subclasses, search from subclasses to superclasses in order, and ensure that the RPC implementation methods in subclasses are not overwritten by superclasses; if the current class does not implement the interface, extract the code of all methods of this class and its subclasses.

[0074] Step S150: Screen out the interface call processing method (onTransact method) from the RPC implementation method, extract the abstract syntax tree (AST) of the interface call processing method and parse it to obtain the call interface number and name description information, as well as the relevant operations of reading and writing packages, analyze the conditional information of the interface branches, obtain the types of input variables and the constraint information of the call method, and also extract the field composition of the custom type input variables used to construct complex variable types. Take the call interface number, name description information, type of input variables, constraint information of the call method, and field composition of the custom type input variables as the RPC implementation method call interface input information;

[0075] To exclude non-sensitive RPC implementation methods and reduce the workload of manual inspection, screen out the interface call processing method from the RPC implementation method, including:

[0076] Decompile the RPC implementation method to obtain the programming code;

[0077] Input the programming code into the analysis model for analysis and output the sensitive candidate RPC implementation methods; specifically, by calling the ChatGPT-3.5-turbo large model, adjust the Prompt and set custom instructions to guide the output of the model. When constructing the prompt words, follow the following design principles: 1) Role setting; 2) Clear and definite instructions; 3) Provide necessary context; 4) Standardize the result output; 5) Multiple rounds of testing and adjustment. Specifically, specify in the task description that the model judges whether there are security risks in the method, clarify the attack scenario and supplement the domain background knowledge. Since there are nested function calls in the code, it is also necessary to extract the relevant method code to improve the analysis context. Considering the maximum nesting depth of 5, the implementation code of the abstract call method is also extracted.

[0078] Screen out the interface call processing method from the candidate RPC implementation methods.

[0079] Step S160: Perform static analysis on the conditional statements, loop structures, and data flows in the code of the RPC implementation method to obtain the input variable dependency relationship of the RPC implementation method;

[0080] Step S170: Adopt a constraint-based test generation method and combinatorial testing technology. Based on the RPC implementation method call interface input information and the RPC implementation method input variable dependency relationship, generate input values that meet the set conditions and systematically explore different value combinations of variables, so as to improve the test coverage rate and obtain input variable test cases;

[0081] Step S180: Store the input information of the RPC implementation method call interface, the input variable test cases, and the information of the exposed service components to which the RPC implementation method belongs in the test device, install the test program on the test device for dynamic fuzz testing, and obtain the vulnerability detection conclusion.

[0082] Specifically explain this step. Write a test application for executing test cases on a specific interface. This test application can be a simple client responsible for calling the RPC method in the application under test. According to the component information to which the candidate RPC method belongs, in the case where specific permissions need to be granted for service method calls, it is necessary to modify the Manifest file when writing the test program to set the package name and permissions of the application, and finally package the test application. The test program reads the input file, sets the intent object according to the call interface information and component information, and then assigns values and instantiates variables according to the input variable test cases to construct the data packet carried in the intent, and directly triggers the Binder event to call the method transact.

[0083] Before testing, install the test application and the application under test on the test device or emulator respectively. Open the test application and start the test. The system will automatically execute the constructed test cases and monitor the response of the device. During this process, errors, abnormal behaviors, and potential vulnerabilities can be detected by observing the test logs, monitoring the device status, and capturing network traffic. During the test, various abnormal situations may be triggered, such as unhandled exceptions, crashes, or performance degradation. These problems can be analyzed in detail through the captured log information to help the development team identify the root cause. In addition, an alarm mechanism can be set according to specific abnormal patterns to detect and record potential vulnerabilities in a timely manner. Finally, based on the observation results, a detailed application vulnerability detection report is generated.

[0084] As Figure 3 shown, the detection system for application binding service vulnerabilities provided by the embodiments of the present invention includes:

[0085] An installation package file extraction module 100, configured to extract the installation package file from the application to be detected;

[0086] Specifically, the installation package file extraction module 100 is specifically used to crawl applications to be analyzed from major mobile application markets and extract them from real devices. The python crawler technology and the ARIA2 tool are used to batch download third-party applications from mainstream application markets (such as Xiaomi, Huawei, Samsung, etc.). Pre-installed applications are pre-installed on the device by the device manufacturer or operator at the time of factory, and are usually integrated into the system partition of the device and generally cannot be obtained from the application market. In order to collect as many pre-installed applications in the systems of mobile phone manufacturers as possible, considering that it is impossible to collect a sufficient number of real devices, a static analysis tool is used to extract the installation package files of pre-installed applications from the system image file, such as: APK files.

[0087] The file parsing module 200 is used to decode the installation package file to obtain the application manifest file, and parse the application manifest file to obtain the exposed service components;

[0088] Specifically, the file parsing module 200 is specifically used to unpack the installation package file based on the JEB reverse tool, and obtain the exposed service components by parsing the manifest file. After opening the installation package file, an analysis context environment is generated. Analyze the metadata and manifest file of the application, extract the service nodes with the android:exported attribute set to true by parsing the application manifest file, or check whether the node contains an intent-filter implicit intent filter to identify the exported Service components. Finally, the information of the exposed service components of the application will be obtained, and these information include the service name, the implicit intent filtering rule, and the permissions required to call the service.

[0089] The static analysis module 300 is used to disassemble the binary file of the application to be detected to obtain the assembly code, perform static analysis on the assembly code, and find the bindable services from the exposed service components;

[0090] Specifically, the static analysis module 300 includes:

[0091] The disassembly unit is used to disassemble the binary file of the application to be detected to obtain the assembly code;

[0092] The binding method query unit is used to traverse the exposed service class code one by one according to the service name of the exposed service components, and check whether the class method contains a binding method; if the binding method cannot be found in the current service class, continue to check whether its inherited parent class overrides the binding method until the service base class is traced and the binding method is found;

[0093] The bound service query unit is used to check whether the return type of the binding method is the Binder class and its subclasses, and determine whether it inherits the Binder class by extracting the class inheritance relationship of each class; if so, the service can be bound, and the bindable service is obtained.

[0094] The RPC implementation method acquisition module 400 is used to obtain the RPC implementation method of the bindable service;

[0095] Specifically, the RPC implementation method acquisition module 400 is specifically used to obtain all the interface methods registered in the interface inheritance chain of the returned Binder class of the bindable service, and find the RPC implementation methods of all the interface methods from all the subclasses.

[0096] The call interface input information generation module 500 is used to filter out the interface call processing method (onTransact method) from the RPC implementation method, extract and parse the abstract syntax tree (AST) of the interface call processing method, obtain the call interface number and name description information and the related operations of reading and writing packages, analyze the conditional information of the branches of the interface, obtain the type of the input variable and the constraint information of the call method, and also extract the field composition of the custom type input variable used to construct the complex variable type, and use the call interface number, name description information, type of the input variable, constraint information of the call method, and field composition of the custom type input variable as the RPC implementation method call interface input information;

[0097] Specifically, the call interface input information generation module 500 includes:

[0098] The decompilation unit is used to decompile the RPC implementation method to obtain the programming code;

[0099] The sensitive candidate RPC implementation method analysis unit is used to input the programming code into the analysis model for analysis, and output the sensitive candidate RPC implementation methods; specifically, by calling the ChatGPT-3.5-turbo large model, adjusting the Prompt and setting custom instructions to guide the output of the model. When constructing the prompt words, follow the following design principles: 1) Role setting; 2) Clear and definite instructions; 3) Provide necessary context; 4) Standardize the result output; 5) Multiple rounds of testing and adjustment. Specifically, specify the model judgment method for whether there is a security risk in the task description, clarify the attack scenario and supplement the domain background knowledge. Since there are nested function calls in the code, it is also necessary to extract the relevant method code to improve the analysis context. Considering that the maximum nesting depth is 5, the implementation code of the abstract call method is also extracted.

[0100] The interface call processing method filtering unit is used to filter out the interface call processing method from the candidate RPC implementation methods.

[0101] The interface call input information generation unit is used to extract the Abstract Syntax Tree (AST) of the interface call processing method and parse it, obtain the interface call number and name description information, as well as the related operations of reading and writing packages, analyze the conditional information of the branches of the interface, obtain the types of input variables and the constraint information of the call method, and also extract the field composition of the custom type input variables used to construct complex variable types. The interface call number, name description information, types of input variables, constraint information of the call method, and field composition of the custom type input variables are used as the RPC implementation method call interface input information.

[0102] The input variable dependency relationship generation module 600 is used to perform static analysis on the conditional statements, loop structures, and data flows in the code of the RPC implementation method to obtain the input variable dependency relationship of the RPC implementation method;

[0103] The input variable test case generation module 700 is used to adopt a constraint-based test generation method and combinatorial testing technology, and based on the RPC implementation method call interface input information and the RPC implementation method input variable dependency relationship, generate input values that meet the set conditions, and systematically explore different value combinations of variables, so as to improve the test coverage rate and obtain input variable test cases;

[0104] The vulnerability detection module 800 is used to store the RPC implementation method call interface input information, input variable test cases, and the exposed service component information to which the RPC implementation method belongs in the test device, install the test program on the test device for dynamic fuzz testing, and obtain the vulnerability detection conclusion.

[0105] In summary, the embodiment of the present invention designs a vulnerability detection method for custom binding services of Android system applications. By reverse analysis to collect attack entrances, and combining static analysis modeling and dynamic fuzz testing methods, potential vulnerability types and risks can be identified.

[0106] Those skilled in the art should understand that the embodiments of the present invention can be provided as a method, a system, or a computer program product. Therefore, the present invention can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memories, CD-ROMs, optical memories, etc.) containing computer-usable program codes.

[0107] The present invention is described with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to embodiments of the present invention. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, as well as the combination of flows and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing devices generate means for implementing the functions specified in one flow Figure 1 one flow or multiple flows and / or blocks Figure 1 or multiple blocks.

[0108] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, such that the instructions stored in the computer-readable memory generate a manufactured article including instruction means that implement the functions specified in one flow Figure 1 one flow or multiple flows and / or blocks Figure 1 or multiple blocks.

[0109] These computer program instructions can also be loaded onto a computer or other programmable data processing device, such that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process, so that the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one flow Figure 1 one flow or multiple flows and / or blocks Figure 1 or multiple blocks.

[0110] Details not described in the embodiments of the present invention are all well-known techniques in the technical field to which the present invention pertains. Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit them. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that the technical solutions of the present invention can be modified or equivalently replaced without departing from the spirit and scope of the technical solutions of the present invention, and they should all be covered by the scope of the claims of the present invention.

Claims

1. A method for detecting application binding service vulnerabilities, characterized in that: include: Extract the installation package file from the application to be detected; Decoding the installation package file to obtain an application manifest file, and parsing the application manifest file to obtain exposed service components; Disassembling the binary file of the application to be detected to obtain assembly code, performing static analysis on the assembly code, and finding services that can be bound from the exposed service components; Obtain the RPC implementation method of the service that can be bound; Filter out the interface call processing method from the RPC implementation method, extract and parse the abstract syntax tree of the interface call processing method, obtain the call interface number and name description information and related operations of reading and writing packets, analyze the condition information of the branch of the interface, obtain the type of input variables and constraint information of the call method, and further extract the field composition of the user-defined type input variable used to construct the complex variable type, and use the call interface number, the name description information, the type of the input variable, the constraint information of the call method and the field composition of the user-defined type input variable as the RPC implementation method call interface input information; Performing static analysis on conditional statements, loop structures, and data flows in the code of the RPC implementation method to obtain input variable dependencies of the RPC implementation method; Adopting a constraint-based test generation method and a combination test technology, based on the RPC implementation method call interface input information and the RPC implementation method input variable dependency, generating input values ​​that meet the set conditions, and obtaining input variable test cases; The RPC implementation method call interface input information, the input variable test case and the exposed service component information to which the RPC implementation method belongs are stored in the test device, and the test program is installed on the test device to perform dynamic fuzzy testing to obtain vulnerability detection conclusions.

2. The method for detecting application binding service vulnerabilities according to claim 1, characterized in that: The static analysis of the assembly code to find the services that can be bound from the exposed service components includes: According to the service name of the exposed service component, the exposed service class codes are traversed one by one to check whether the class method contains a binding method; If the binding method cannot be found in the current service class, continue to check whether the parent class it inherits has overridden the binding method until the binding method is found by tracing back to the service base class; Check whether the return type of the binding method is the Binder class and its subclasses, and determine whether each class inherits the Binder class by extracting the class inheritance relationship of each class; if so, the service can be bound, and a bindable service is obtained.

3. The method for detecting application binding service vulnerabilities according to claim 1, characterized in that: The RPC implementation method for obtaining the bindable service includes: Get all interface methods registered in the interface inheritance chain of the returned Binder class of the bindable service, and find RPC implementation methods of all interface methods from all subclasses.

4. The method for detecting application binding service vulnerabilities as claimed in claim 3, characterized in that: In the process of finding the RPC implementation methods of all the interface methods from all the subclasses, the search is sequentially conducted from the subclass to the parent class, and it is ensured that the RPC implementation methods in the subclasses are not overwritten by the parent class; if the current class does not implement the interface, the codes of all the methods of the class and its subclasses are extracted.

5. The method for detecting application binding service vulnerabilities according to claim 1, characterized in that: The step of filtering out the interface call processing method from the RPC implementation method comprises: Decompiling the RPC implementation method to obtain programming code; Inputting the programming code into the analysis model for analysis, and outputting sensitive candidate RPC implementation methods; An interface call processing method is screened out from the candidate RPC implementation methods.

6. A detection system for application binding service vulnerabilities, characterized in that: include: An installation package file extraction module is used to extract the installation package file from the application to be detected; A file parsing module, used to decode the installation package file to obtain an application manifest file, and parse the application manifest file to obtain exposed service components; A static analysis module, used for disassembling the binary file of the application to be detected to obtain assembly code, performing static analysis on the assembly code, and finding services that can be bound from the exposed service components; An RPC implementation method acquisition module, used to acquire the RPC implementation method of the service that can be bound; A calling interface input information generating module is used to filter out the interface calling processing method from the RPC implementation method, extract the abstract syntax tree of the interface calling processing method and parse it, obtain the calling interface number and name description information and related operations of reading and writing packets, analyze the condition information of the branch of the interface, obtain the type of input variables and the constraint information of the calling method, and further extract the field composition of the user-defined type input variable used to construct the complex variable type, and use the calling interface number, the name description information, the type of the input variable, the constraint information of the calling method and the field composition of the user-defined type input variable as the RPC implementation method calling interface input information; An input variable dependency generation module is used to perform static analysis on conditional statements, loop structures and data flows in the code of the RPC implementation method to obtain input variable dependencies of the RPC implementation method; An input variable test case generation module is used to generate input values ​​that meet set conditions based on the RPC implementation method call interface input information and the RPC implementation method input variable dependency relationship, thereby obtaining an input variable test case by adopting a constraint-based test generation method and a combination test technology; The vulnerability detection module is used to store the RPC implementation method call interface input information, the input variable test case and the exposed service component information to which the RPC implementation method belongs in the test device, install the test program on the test device to perform dynamic fuzzy testing, and draw vulnerability detection conclusions.

7. The system for detecting application binding service vulnerabilities as claimed in claim 6, characterized in that: The static analysis module includes: A disassembly unit, used for disassembling the binary file of the application to be detected to obtain assembly code; A binding method query unit is used to traverse the exposed service class codes one by one according to the service name of the exposed service component, and check whether the class method contains the binding method; if the binding method cannot be found in the current service class, continue to check whether the parent class it inherits has rewritten the binding method, until tracing back to the service base class and finding the binding method; The binding service query unit is used to check whether the return type of the binding method is the Binder class and its subclasses, and to determine whether each class inherits the Binder class by extracting the class inheritance relationship of each class; if so, the service can be bound, and a bindable service is obtained.

8. The system for detecting application binding service vulnerabilities as claimed in claim 6, characterized in that: The RPC implementation method acquisition module is specifically used to obtain all interface methods registered in the interface inheritance chain of the return Binder class of the bindable service, and find the RPC implementation methods of all the interface methods from all subclasses.

9. The system for detecting application binding service vulnerabilities as claimed in claim 6, characterized in that: The calling interface input information generating module comprises: A decompiling unit, used for decompiling the RPC implementation method to obtain programming code; A sensitive candidate RPC implementation method analysis unit, used for inputting the programming code into an analysis model for analysis, and outputting a sensitive candidate RPC implementation method; An interface call processing method screening unit, used to screen out an interface call processing method from the candidate RPC implementation methods; A calling interface input information generating unit is used to extract and parse the abstract syntax tree of the interface calling processing method, obtain the calling interface number and name description information and related operations of reading and writing packages, analyze the condition information of the interface branches, obtain the type of input variables and the constraint information of the calling method, and also extract the field composition of the user-defined type input variable used to construct a complex variable type, and use the calling interface number, the name description information, the type of the input variable, the constraint information of the calling method and the field composition of the user-defined type input variable as the RPC implementation method calling interface input information.

Citation Information

Patent Citations

  • Binder communication overload vulnerability detection method based on static analysis

    CN113139184A

  • Vulnerability detection method and device for application program, medium and equipment

    CN117807601A

  • Java Web framework-oriented data binding vulnerability automatic detection method

    CN118332555A

  • Technique for determining web services vulnerabilities and compliance

    US20060277606A1

  • System and method for detecting and communicating on-device intent with partner applications using streaming pipe inter-process communication

    US20240272966A1

Cited By

  • Vulnerability detection method, device, system and equipment for application program installation package

    CN121479793A