Deep learning-based function body level C or C + + smart contract vulnerability detection method

Through the function body-level detection method based on deep learning, the problem of limited scope of vulnerability detection of C/C++ smart contracts in the existing technology is solved, and comprehensive vulnerability detection of C/C++ smart contracts is achieved, which is suitable for a variety of blockchain systems.

CN120145388APending Publication Date: 2025-06-13ZHONGYUAN ENGINEERING COLLEGE +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510171399.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-17
Publication Date
2025-06-13

AI Technical Summary

Technical Problem

The existing technology is difficult to fully detect vulnerabilities in C/C++ smart contracts. The detection range is limited and it does not have growth potential. It is only applicable to specific blockchain systems.

Method used

A function body-level C or C++ smart contract vulnerability detection method is designed based on deep learning. By obtaining the function body slices in the dataset, initializing and modifying the function body labels, encoding the function body vectors, and using these vectors to train the detection model to realize vulnerability detection of a given function body.

Benefits of technology

This method can improve the growth and accuracy of detection as the data set is continuously improved. It is not limited to a certain blockchain, but is suitable for vulnerability detection of all C/C++ smart contracts.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120145388A_ABST
    Figure CN120145388A_ABST
Patent Text Reader

Abstract

The invention discloses a function body level C or C + + smart contract vulnerability detection method based on deep learning, and the method comprises the steps: obtaining a data set, and obtaining all function body slices in the data set; initializing the function body and modifying function body tags, and identifying vulnerability function body tags and vulnerability-free function body tags; coding the identified function body labels with the vulnerabilities and the function body labels without the vulnerabilities to obtain function body vectors; training a detection model by using the function body vector and the corresponding vulnerability function body label to obtain a detection module; and detecting a given function body by using the detection model. According to the method, the defect of C / C + + smart contract source code vulnerability is overcome, the processed function body code information is used, data flow and control flow information in the code is obtained as much as possible, and it is guaranteed that the structure of the source code is not damaged.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of C / C++ smart contract vulnerability detection, and particularly relates to a method for detecting C or C++ smart contract vulnerabilities at the function body level based on deep learning. Background Technique

[0002] As an important part of the blockchain, a smart contract is stored in the blockchain system as a protocol. In essence, it is a special program written in code. Like general software application programs, it also has various vulnerabilities. The smart contracts of EOSIO and VNT blockchains are written in C / C++ smart contracts and are executed in the blockchain virtual machine after being compiled into a specific bytecode WebAssembly (Wasm) format. Wasm is a Web standard for specifying the binary instruction format of a stack-based virtual machine, and it can run in Web browsers and other environments. The complex execution environment makes it not easy to ensure the security of smart contracts, especially for the C / C++ smart contract language that is different from the Solidity smart contract language. Currently, huge losses have been caused due to vulnerability problems in EOSIO. Therefore, it is of great significance to build an effective vulnerability detection tool for C / C++ smart contracts.

[0003] Unfortunately, due to the difficulty of obtaining the source code of C / C++ smart contracts, it is impossible to directly detect vulnerabilities from the perspective of the source code. Therefore, some researchers start from the perspective of the compiled bytecode wasm. For example, He et al. proposed EOSAFE, which is the first static analysis framework for automatically detecting vulnerabilities at the Wasm bytecode level of the EOS blockchain. This framework consists of a symbolic execution engine and an EOSIO smart contract customized library simulator, and four heuristic detectors are designed to identify false tokens, false receptions, rollbacks, and permission check vulnerabilities. Subsequently, Quan et al. proposed a static analysis tool EVulHunter, which focuses on detecting false transfer vulnerabilities in EOSIO Wasm code, reducing the vulnerability detection scope and focusing on one type of vulnerability, thus improving the accuracy. In addition to using static program analysis techniques, some scholars have also adopted fuzz testing techniques. Li et al. implemented GFuzzer based on WebAssembly, selected test cases through fuzz testing feedback information, and proposed a mutation strategy based on ABI parameters, successfully detecting transfer vulnerabilities, forged transfer notification vulnerabilities, and block information dependency vulnerabilities. Huang et al. designed a general black-box fuzz testing framework EOSFuzzer, which generates inputs and attack behaviors by simulating the scenarios of smart contracts to detect vulnerabilities. Fuzz testing techniques need to generate a large amount of test data, with unclear targets and easy to waste a large amount of resources. Therefore, some scholars have proposed symbolic execution techniques. Jin et al. designed a vulnerability detection tool EXGEN based on symbolic execution. Although it is mainly used for the detection of Solidity smart contracts, it can also identify integer overflow vulnerabilities in C / C++ smart contracts. With the continuous development of artificial intelligence, machine learning / deep learning techniques have also been applied in the field of vulnerability detection. Zhuang et al. constructed a contract graph to represent the syntax and semantic structure of smart contracts, and proposed a degree-free graph convolutional neural network (DR-GCN) and a time message propagation network (TMP) to detect infinite loop vulnerabilities in C / C++ smart contracts of the VNT blockchain. Although these methods can solve the lack of C / C++ smart contract vulnerability detection to a certain extent, they have certain limitations. First, the scope of vulnerabilities they detect is limited and does not have growth potential. Second, they can only be detected in specific blockchain systems.

[0004] To address the above problems and more comprehensively detect vulnerabilities in the field of C / C++ smart contracts, a method for detecting C or C++ smart contract vulnerabilities at the function body level based on deep learning is designed. Summary of the Invention

[0005] To solve the above technical problems, the present invention proposes a method for detecting vulnerabilities in C or C++ smart contracts at the function body level based on deep learning. This method can continuously grow as the dataset is continuously improved, and it is not limited to a certain blockchain. As long as it is a C / C++ smart contract, vulnerability detection can be performed.

[0006] The present invention provides a method for detecting vulnerabilities in C or C++ smart contracts at the function body level based on deep learning, including:

[0007] Obtain a dataset and obtain all function body slices in the dataset;

[0008] Initialize the function body and modify the function body label to identify the vulnerable function body label and the non-vulnerable function body label;

[0009] Encode the identified vulnerable function body label and non-vulnerable function body label to obtain a function body vector;

[0010] Use the function body vector and the corresponding vulnerable function body label to train a detection model to obtain a detection module;

[0011] Use the detection model to detect a given function body.

[0012] Optionally, initializing the function body includes:

[0013] For all slices in the function body without specific vulnerability markings, initialize the label to a vulnerable label.

[0014] Optionally, modifying the function body label to obtain the function body label includes:

[0015] Compare the vulnerable code and the non-vulnerable code to obtain a modified file;

[0016] Match the code in the function body with the code in the modified file, and modify the function body label according to the matching result.

[0017] Optionally, matching the code in the function body with the code in the modified file and modifying the function body label according to the matching result includes:

[0018] If the code in the function body can match the code in the modified file, modify the corresponding label to a non-vulnerable label;

[0019] Otherwise, do not modify.

[0020] Optionally, encoding the vulnerable function body label and the non-vulnerable function body label to obtain a function body vector includes:

[0021] Obtain the tags of vulnerable function bodies and non-vulnerable function bodies to be encoded;

[0022] Input the tags of the vulnerable function bodies and non-vulnerable function bodies to be encoded into a vector conversion model to obtain function body vectors. Among them, the vector conversion model is obtained by training with a training set, the training set is corpus data, and the vector conversion model is a deep learning model for generating word vectors.

[0023] Optionally, obtaining the training set includes:

[0024] Split the function body slices into corpus files to obtain the training set, where the function body includes vulnerable function bodies and non-vulnerable function bodies.

[0025] The present invention mainly provides a C or C++ intelligent contract vulnerability detection system at the function body level based on deep learning, including: a vulnerable function body acquisition module, an annotation module, an encoding module, and a detection module;

[0026] The vulnerable function body acquisition module is used to obtain vulnerable function bodies;

[0027] The annotation module is used to initialize the vulnerable function body and modify the vulnerable function body tag to obtain the vulnerable function body tag;

[0028] The encoding module is used to encode the vulnerable function body to obtain function body vectors;

[0029] The detection module is used to train a detection model using the function body vectors and the corresponding vulnerable function body tags, and use the detection model to detect a given function body.

[0030] Compared with the prior art, the present invention has the following advantages and technical effects:

[0031] 1. The present invention makes up for the deficiency of C / C++ intelligent contract source code vulnerabilities: using the processed function body code information, obtaining as much data flow and control flow information in the code as possible, and ensuring that the structural nature of the source code is not damaged.

[0032] 2. The present invention reduces the problem of information loss when converting code into vectors: directly using the word2vec model to convert vectors will cause a certain degree of information loss. For this reason, the present invention adds a step of training the word2vec model, and uses the corpus generated by its own training data to train the word2vec model, which can reduce the problem of information loss to a certain extent.

[0033] 3. The present invention enhances the vulnerability detection scope and accuracy: By using deep learning technology, without relying on expert rule definitions, it can discover some potential vulnerabilities and a wider range of vulnerabilities during training. Moreover, since the function body contains data flow and control flow information in the code, the accuracy of the training model is improved, thereby enhancing the performance of the tool. BRIEF DESCRIPTION OF THE DRAWINGS

[0034] The accompanying drawings, which form a part of this application, are used to provide a further understanding of this application. The illustrative embodiments of this application and their descriptions are used to explain this application and do not constitute an improper limitation to this application. In the drawings:

[0035] Figure 1 is a flowchart of a method for detecting C or C++ smart contract vulnerabilities at the function body level based on deep learning according to an embodiment of the present invention;

[0036] Figure 2 is a model framework diagram of a method for detecting C or C++ smart contract vulnerabilities at the function body level based on deep learning according to an embodiment of the present invention;

[0037] Figure 3 is an example of extracting a vulnerable function body according to an embodiment of the present invention;

[0038] Figure 4 is an example of generating an automatically tagged diff file according to an embodiment of the present invention;

[0039] Figure 5 is an example of modifying the mark of a vulnerable function body according to an embodiment of the present invention;

[0040] Figure 6 is an example of an integer overflow vulnerability contract according to an embodiment of the present invention;

[0041] Figure 7 is a vulnerability report according to an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0042] It should be noted that, without conflict, the embodiments in this application and the features in the embodiments can be combined with each other. The following will refer to the accompanying drawings and combine with the embodiments to detail this application.

[0043] It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer executable instructions. And, although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than here.

[0044] This embodiment proposes a method for detecting C or C++ smart contract vulnerabilities at the function body level based on deep learning, as Figure 1As shown in the figure, it specifically includes the following steps:

[0045] Obtain a data set and obtain all function body slices in the data set;

[0046] Initialize the function body and modify the function body labels to identify vulnerable function body labels and non-vulnerable function body labels;

[0047] Encode the identified vulnerable function body labels and non-vulnerable function body labels to obtain function body vectors;

[0048] Use the function body vectors and the corresponding vulnerable function body labels to train a detection model to obtain a detection module;

[0049] Use the detection model to detect a given function body.

[0050] Specifically, first, quickly locate and obtain the vulnerable function body through the function name. Secondly, automatically label the function body slices using the generated tagging file. Then vectorize the function body to generate data that can be recognized by the deep learning model. Finally, train the generated vectors to generate a C / C++ smart contract vulnerability detection tool that can display the vulnerability types of the function body and their positions in the code.

[0051] Furthermore, the initialization of the vulnerable function body includes:

[0052] For all slices in the function body that do not have specific vulnerability markings, initialize their labels as vulnerable labels.

[0053] Specifically, as Figure 3 shown, the extraction of vulnerable function body information: Its main purpose is to obtain the main data flow and control flow information in the C / C++ smart contract source code. Detailed data flow and control flow information can increase the success rate of deep learning and thus improve the accuracy of training the C / C++ smart contract vulnerability detection tool.

[0054] Furthermore, modifying the function body labels to obtain the function body labels includes:

[0055] Compare the vulnerable code and the non-vulnerable code to obtain a modified file;

[0056] Match the code in the function body with the code in the modified file and modify the function body labels according to the matching results.

[0057] Specifically, the initialization of the vulnerable function body label: For the function body information obtained without specific vulnerability slice markings, in this embodiment, it is first assumed that all the function bodies extracted are vulnerable slices, and their labels are all initialized to "1", that is, there is a vulnerability marking.

[0058] Further, match the code in the function body with the code in the modified file. According to the matching result, modify the function body tags including:

[0059] If the code in the function body can be matched with the code in the modified file, modify the corresponding tag to a non-vulnerable tag;

[0060] Otherwise, do not make any modifications.

[0061] Specifically, as Figure 4 shown, generate an automatically tagged diff file: When generating the dataset in this embodiment, it contains two types of source codes. One is the code with vulnerabilities, called "bad" code, and the other is the code without vulnerabilities generated by fixing the vulnerabilities of the "bad" code, called "good" code. With the available "good" and "bad" codes, this embodiment compares the non-vulnerable code "good" with the vulnerable code "bad". If the match fails in the "bad" code, record the line of code. Through this step, a diff file will be generated, which can be used for subsequent modification of the function body tags. The file generated in this way can effectively identify the differences between the repaired code "good" and the "bad" code.

[0062] As Figure 5 shown, modify the tags of the vulnerable function body. By using the modified file generated in the previous step, compare all the function body information with this file. If a match is found, modify its tag to "0", which means non-vulnerable. If the match fails, do not modify the tag. This method can automatically tag the function body and reduce the problem of manual tag modification.

[0063] Further, encode the tags of the vulnerable function body and the non-vulnerable function body to obtain the function body vector, including:

[0064] Obtain the tags of the vulnerable function body and the non-vulnerable function body to be encoded;

[0065] Input the tags of the vulnerable function body and the non-vulnerable function body to be encoded into the vector conversion model to obtain the function body vector. Among them, the vector conversion model is obtained by training with a training set, the training set is corpus data, and the vector conversion model is a deep learning model for generating word vectors.

[0066] Specifically, a corpus is constructed and a vector conversion model is trained. The vector conversion model is a word2vec model. In deep learning, all inputs are in the format of vectors. Therefore, it is necessary to convert the obtained function body slices into vectors. In this step, if the word2vec model is directly used for vector conversion, information loss will occur, affecting subsequent training. Therefore, before training, the training of the word2vec model is added in this embodiment. The first step is to generate a corpus file from the code to be converted into a vector. This corpus file can be used to train the word2vec model to make the word2vec model more suitable for the vector conversion of this embodiment. During the training of the word2vec model, first, the corpus is loaded as a list of sentences, and after word segmentation, it is sent to the word2vec model for training. And in order to set parameters more suitable for small corpora and C / C++ language-specific corpora (such as special symbols), for example, set vector_size = 30. In a small corpus, the diversity of words is limited. Too high a vector dimension will lead to overfitting, and fewer dimensions reduce the resource requirements for calculation; Skip-Gram = 1, which is more suitable for small corpora and can better learn the representation of low-frequency words; negative = 10, by introducing negative sampling, significantly improves the training efficiency, especially when the vocabulary in the corpus is large. In addition, there are also parameters such as window size (window = 5), low learning rate (alpha = 0.01), full word retention (min_count = 0), randomness control (seed = 1), etc., which are specifically adjusted to be suitable for the corpus of C / C++ smart contract construction, and can maximize the problem of reducing semantic loss after the corpus is converted into a vector.

[0067] Encode the vulnerability function body as a vector. In the previous step, this embodiment trained and generated a word2vec vector conversion model. In this step, the trained model is directly used for vector conversion to convert the function body slice information file of this embodiment into a vector.

[0068] Furthermore, obtaining the training set includes:

[0069] Split the function body slices into corpus files to obtain the training set, where the function body includes vulnerable function bodies and non-vulnerable function bodies.

[0070] Specifically, a detection model is trained using the function body vector and the corresponding vulnerability function body tag to obtain a detection module. Using the detection model to detect a given function body includes: generating vector tags and training. The main purpose is to combine the generated vectors with the tags of the corresponding function bodies, that is, the tag vectors are "1" for vulnerable and "0" for non-vulnerable, and these vectors are placed in a deep model for training to further obtain a C / C++ smart contract vulnerability detection tool based on intelligence. This step uses a Bidirectional Gated Recurrent Unit (BGRU). This model can combine context information, enhance the sequence representation ability, effectively avoid the problem of gradient disappearance, and is suitable for long sequence modeling. Compared with bidirectional LSTM, BGRU has fewer parameters and higher computational efficiency. Indeed, through experimental verification, the experimental effect of the BGRU model is better.

[0071] This embodiment also provides a C or C++ smart contract vulnerability detection system at the function body level based on deep learning, including: a vulnerability function body acquisition module, a labeling module, an encoding module, and a detection module;

[0072] The vulnerability function body acquisition module is used to acquire vulnerability function bodies;

[0073] The labeling module is used to initialize the vulnerability function body and modify the vulnerability function body tag to obtain the vulnerability function body tag;

[0074] The encoding module is used to encode the vulnerability function body to obtain a function body vector;

[0075] The detection module is used to train a detection model using the function body vector and the corresponding vulnerability function body tag,

[0076] and use the detection model to detect a given function body.

[0077] The following elaborates on this embodiment in conjunction with the attached Figures 2 - 7 illustrations:

[0078] As Figure 2 shown, the main workflow of the C / C++ smart contract vulnerability detection tool at the function body level based on deep learning specifically includes:

[0079] Step1: Function body construction. Traverse all C / C++ smart contract source code files in the dataset. For each piece of code, use a regular matching algorithm to quickly locate the function name position, and then obtain the complete function body information based on the function name position.

[0080] Step 2: Initialize and modify the vulnerability function body tags. The initial vulnerability markers for all function bodies are "1", indicating vulnerability. Then, based on the modified files generated from the vulnerable code and the corresponding non-vulnerable code, each line of the function body is matched with the lines in the modified file. If a match is found, the marker is changed to "0", indicating no vulnerability; otherwise, the tag remains unchanged.

[0081] Step 3: Encode the vulnerability function body as a vector. This process needs to be carried out in three steps: First, slice the generated function body and split it into corpus files; second, use the generated corpus files to train a word2vec model; third, put the generated corpus data into the word2vec model for vector conversion, so as to encode the vulnerability slices as vectors.

[0082] Step 4: Generate vector markers and train. To learn the deep neural network, in this embodiment, the generated vectors are combined with the tags of their corresponding function bodies, that is, the marked vectors are "1" for vulnerable and "0" for non-vulnerable. The learned deep neural network encodes the vulnerability patterns and can detect whether a given function body has vulnerabilities.

[0083] Step 5: Conduct instance tests on the generated tool, output an experimental result test report, and the model performance.

[0084] The above is only a preferred specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any changes or substitutions that can be easily thought of by those skilled in the art within the technical scope disclosed in the present application should be covered by the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

Claims

1. A method for detecting C or C++ smart contract vulnerabilities at the function body level based on deep learning, characterized in that: include: Obtain a data set, and obtain all function body slices in the data set; Initializing the function body and modifying the function body label, identifying the function body label with vulnerabilities and the function body label without vulnerabilities; Encode the identified vulnerable function body labels and non-vulnerable function body labels to obtain a function body vector; Using the function body vector and the corresponding vulnerability function body label to train a detection model to obtain a detection module; The detection model is used to detect a given function body.

2. According to claim 1, a method for detecting C or C++ smart contract vulnerabilities at the function body level based on deep learning, characterized in that: Initializing the function body includes: All slices in the function body that do not have a specific vulnerability tag have their labels initialized to have a vulnerability tag.

3. According to claim 2, a method for detecting C or C++ smart contract vulnerabilities at the function body level based on deep learning is characterized in that: Modify the function body tag. Get the function body tag including: Compare the vulnerable code with the non-vulnerable code to obtain the modified file; The code in the function body is matched with the code in the modification file, and the function body label is modified according to the matching result.

4. According to claim 3, a method for detecting C or C++ smart contract vulnerabilities at the function body level based on deep learning is characterized in that: Match the code in the function body with the code in the modified file, and modify the function body label according to the matching result to include: If the code in the function body matches the code in the modified file, the corresponding label is modified to a non-vulnerability label; Otherwise, no modification is made.

5. According to a method for detecting C or C++ smart contract vulnerabilities at the function body level based on deep learning in claim 1, it is characterized in that: Encoding the function body label with a vulnerability and the function body label without a vulnerability to obtain a function body vector includes: Obtain the function body label with vulnerability and the function body label without vulnerability to be encoded; The function body labels with vulnerabilities and the function body labels without vulnerabilities to be encoded are input into a vector conversion model to obtain function body vectors, wherein the vector conversion model is obtained by training with a training set, the training set is corpus data, and the vector conversion model is a deep learning model for generating word vectors.

6. According to claim 5, a method for detecting C or C++ smart contract vulnerabilities at the function body level based on deep learning is characterized in that: Acquiring the training set includes: The function body slices are split into corpus files to obtain the training set, wherein the function body includes a vulnerable function body and a non-vulnerable function body.

7. A C or C++ smart contract vulnerability detection system at the function body level based on deep learning, characterized in that: include: Vulnerability function body acquisition module, annotation module, encoding module and detection module; The vulnerability function body acquisition module is used to obtain the vulnerability function body; The marking module is used to initialize the vulnerable function body and modify the vulnerable function body label to obtain the vulnerable function body label; The encoding module is used to encode the vulnerable function body to obtain a function body vector; The detection module is used to train a detection model using the function body vector and the corresponding vulnerability function body label, and use the detection model to detect a given function body.