Rapid high-risk vulnerability judgment method based on reverse slicing

By adopting a fast high-risk vulnerability determination method based on reverse slicing in software development, combining forward taint analysis and reverse slicing calculation, the problem of determining memory corruption security defects in complex software systems is solved, and the analysis efficiency and accuracy are improved.

CN120180442APending Publication Date: 2025-06-20BEIJING INST OF COMP TECH & APPL
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510238952.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-03
Publication Date
2025-06-20

AI Technical Summary

Technical Problem

The problem of determining memory corruption security defects in complex software systems is inefficient in analysis or has a high false alarm rate.

Method used

A fast high-risk vulnerability determination method based on reverse slices is adopted, combined with forward stain analysis and reverse slice calculation, and the instruction execution trajectory and abnormal input information are recorded through the dynamic analysis technology monitored by the whole system, and the stain propagation and the reverse slice relationship flow diagram are established, and potential vulnerabilities are located and verified.

Benefits of technology

It improves the efficiency and accuracy of memory corruption security defects, reduces redundant code analysis, effectively filters false positives, and supports iterative analysis to deal with high-risk vulnerability judgments in complex software systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120180442A_ABST
    Figure CN120180442A_ABST
Patent Text Reader

Abstract

The invention relates to a high-risk vulnerability rapid judgment method based on reverse slicing, and belongs to the technical field of software development. According to the method, forward stain analysis and reverse data flow analysis are combined, rapid judgment is carried out on the memory destruction type security defects, the efficiency and accuracy of vulnerability analysis are improved, the judgment problem of the memory destruction type security defects in a complex software system is effectively solved, and the method has important theoretical significance and application value.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of software development, and particularly relates to a method for quickly determining high-risk vulnerabilities based on reverse slicing. Background Art

[0002] In the process of software development, vulnerability analysis is an important link to ensure software security. Traditional vulnerability analysis methods usually rely on static code analysis or dynamic taint analysis. However, when facing complex software systems, these methods often face challenges such as a large amount of redundant code and complex data flows, resulting in low analysis efficiency or a high false positive rate. Therefore, it is necessary to design a method for quickly determining high-risk vulnerabilities to effectively solve the problem of determining memory corruption security defects in complex software systems. Summary of the Invention

[0003] (1) Technical Problems to be Solved

[0004] The technical problem to be solved by the present invention is to design a method for quickly determining high-risk vulnerabilities, improve the efficiency and accuracy of vulnerability analysis, and solve the problem of determining memory corruption security defects in complex software systems.

[0005] (2) Technical Solutions

[0006] To solve the above technical problems, the present invention provides a method for quickly determining high-risk vulnerabilities based on reverse slicing, including the following steps:

[0007] Step 1, Execution Record Extraction: By using dynamic analysis technology for full-system monitoring, monitor the triggering process of software security defects in gateway devices, record the instruction execution trace information during software operation, and the input information that triggers defect exceptions. The instruction execution trace information includes instruction addresses, operands, and register states;

[0008] Step 2, Forward Taint Analysis: Mark the input information that triggers defect exceptions as taint sources, and dynamically propagate taints according to the taint sources to update the memory taint status;

[0009] Step 3, Reverse Slicing Calculation:

[0010] 1) Specify the start and end points of the reverse slice, as well as the target memory address or register address of the slice;

[0011] 2) Initialize the storage unit SliceMap to record the storage units that need to be sliced and traced;

[0012] 3) Starting from the start instruction, reverse-parsing the execution record of each instruction, and tracing the source of the target data according to the instruction semantics;

[0013] 4) During the tracing process, use SliceMap to record the storage units that need to be sliced and traced, and establish a reverse slicing relationship flow graph, where each node represents a storage unit and the edge represents the data dependency relationship;

[0014] 5) After the reverse slicing calculation is completed, a complete reverse slicing relationship flow graph is obtained;

[0015] Step 4, Vulnerability determination:

[0016] Based on the results of forward taint analysis and reverse slicing calculation, perform vulnerability determination:

[0017] 1) Analyze the taint status of the operands and registers at the abnormal position of the program to determine whether the exception is caused by taint data control;

[0018] 2) If so, determine it as a memory out-of-bounds or buffer overflow vulnerability; if not, extract the process of pointer dereference and data link nodes through reverse slicing, and perform the next step to further analyze whether there is a memory corruption vulnerability;

[0019] 3) Use normal input as test data, extract the attribute information of the abnormal crash position in the normal input, compare it with the abnormal input, and locate the difference points for verification and analysis;

[0020] Step 5, Iterative analysis: If no conclusion is drawn in Step 4, perform iterative analysis of reverse slicing on data link nodes or conditional control nodes until a high-risk vulnerability is determined.

[0021] Preferably, the dynamic analysis technology for full-system monitoring adopts a hybrid tracing mechanism based on hardware virtualization extension and dynamic binary instrumentation; among them, use hardware-level EPT page table monitoring to achieve non-intrusive full-system monitoring; enable fine-grained DBI instrumentation for key functions; design a caching mechanism, and use hash fingerprint compression storage for preset high-frequency repeated instruction sequences.

[0022] Preferably, Step 2 is specifically as follows:

[0023] 1) Initialize the taint status, and mark the memory area corresponding to the taint source as tainted;

[0024] 2) According to the instruction execution order, parse the machine code of each instruction, and extract the instruction opcode and operands;

[0025] 3) According to the instruction semantics, update the taint status of the target operand; among them, for the mov instruction, propagate the taint status of the source operand to the target operand;

[0026] 4) Repeat steps 1) to 3) until all instructions are executed, and obtain the complete taint status information.

[0027] Preferably, in step 3), if the starting instruction is an add instruction and the target register is traced by slicing, trace the source operand register.

[0028] If the starting instruction is a load instruction and the target register is traced by slicing, trace the memory operand address.

[0029] Preferably, this method depends on the dynamic execution record of the program. The execution record is recorded in the order of instruction execution, and this method analyzes each instruction in the recorded instruction sequence one by one from the back to the front, tracing the data sources of the memory or registers of interest. This method traces a single variable, which is a single-byte, double-byte, four-byte, or longer continuous storage unit.

[0030] Preferably, the input of this method requires the user to specify two time points as the starting point and the ending position of the slice. The starting point is the later executed one, so the instruction sequence number id of the starting point is greater than the instruction sequence number id of the ending point. At the same time, the user needs to specify the memory or register address and size of the slice as the target unit for slice backtracking. The process of this method is to parse each instruction execution record in reverse order from the starting point to the ending point. During the process of parsing the instruction, recalculate the storage unit that needs to be traced by slicing according to the instruction semantics and operand address. The storage unit traced by slicing also uses the page table method to record the storage unit SliceMap that needs to be traced by slicing in the current memory.

[0031] Preferably, in this method, by extracting the associated node information, establishing the connection edge relationship of the node information, and drawing the reverse slice relationship flow graph; when updating the slice memory state, store the corresponding instruction sequence number in the slice memory structure. When retrieving the slice state of the target byte, if the byte is the byte that needs to be sliced and backtracked, and it also records the id of the backtracking node, then establish a relationship edge between the record with the corresponding id and the id record of the currently analyzed instruction as an element for drawing the slice backtracking flow graph.

[0032] The present invention also provides a system for implementing the above method.

[0033] The present invention also provides a software development method designed based on the above method.

[0034] The present invention also provides a software development system designed based on the above method.

[0035] (III) Beneficial effects

[0036] The method proposed by the present invention combines forward taint analysis and reverse slice calculation, effectively making up for the deficiencies of dynamic taint analysis, and improving the determination efficiency and accuracy of memory corruption security defects. The specific advantages are as follows:

[0037] 1. Through reverse slicing calculation, the data source can be accurately traced, and the problem of data flow disconnection in dynamic taint analysis can be solved;

[0038] 2. Combined with forward taint analysis, the critical path of vulnerability exploitation can be quickly located, reducing redundant code analysis;

[0039] 3. By comparing the attribute information of normal and abnormal inputs, false positives can be effectively filtered, improving the judgment accuracy;

[0040] 4. Support iterative analysis, and can cope with the challenges of high-risk vulnerability judgment in complex software systems. Description of the Drawings

[0041] Figure 1 It is a comparison diagram of the taint propagation calculation and the reverse slicing calculation process. Detailed Implementation Modes

[0042] To make the objectives, contents, and advantages of the present invention clearer, the following further describes in detail the specific implementation modes of the present invention with reference to the drawings and embodiments.

[0043] The present invention proposes a method for quickly judging high-risk vulnerabilities based on reverse slicing, which combines forward taint analysis and reverse data flow analysis to quickly judge memory corruption security defects, improving the efficiency and accuracy of vulnerability analysis.

[0044] A method for quickly judging high-risk vulnerabilities based on reverse slicing provided by the present invention includes the following steps:

[0045] 1. Execution record extraction: Through dynamic analysis techniques for full-system monitoring (such as system call monitoring, dynamic binary instrumentation, etc.), monitor the triggering process of software security defects in the gateway device, record the instruction execution trace (Trace) information during software operation, as well as the input information that triggers the defect exception. The instruction execution trace (Trace) information includes instruction addresses, operands, register states, etc. These execution records provide data support for subsequent forward taint analysis and reverse slicing calculation. Focus on designing a hybrid execution tracing technology, adopting a hybrid tracing mechanism based on hardware virtualization extensions (such as Intel VT-x) and dynamic binary instrumentation (DBI) to improve the integrity and efficiency of execution records and solve the performance bottleneck of traditional DBI:

[0046] o Use hardware-level EPT page table monitoring to achieve non-intrusive full-system monitoring

[0047] o Enable fine-grained DBI instrumentation for critical functions (such as memcpy / strcpy)

[0048] o Design an intelligent caching mechanism and use hash fingerprint compression storage for high-frequency repeated instruction sequences

[0049] 2. Forward taint analysis: Mark the input information that triggers the defect exception as the taint source, dynamically propagate the taint according to the taint source, and update the memory taint status. The following methods are used to improve the analysis accuracy in complex data flow scenarios:

[0050] o Taint propagation rule learning module based on neural network

[0051] o Adaptive propagation strategy selector (distinguish control flow / data flow sensitive modes)

[0052] o Context-aware taint marking system (supporting multi-dimensional labels: source, credibility, propagation path weight)

[0053] The specific steps are as follows:

[0054] 1) Initialize the taint status and mark the memory area corresponding to the taint source as tainted;

[0055] 2) Parse the machine code of each instruction in the order of instruction execution, and extract the instruction opcode and operands;

[0056] 3) Update the taint status of the target operand according to the instruction semantics; for example, for the mov instruction, propagate the taint status of the source operand to the target operand;

[0057] 4) Repeat the above process (steps 1) to 3)) until all instructions are executed to obtain the complete taint status information.

[0058] 3. Reverse slice calculation:

[0059] 1) Specify the start and end points (instruction numbers) of the reverse slice, as well as the target memory address or register address of the slice;

[0060] 2) Initialize the SliceMap to record the storage units that need to be sliced and traced;

[0061] 3) Start from the start instruction, reverse-parsing the execution record of each instruction, and tracing the source of the target data according to the instruction semantics.

[0062] o For example, for the add instruction, if the target register is sliced and traced, the source operand register needs to be traced.

[0063] o For the load instruction, if the target register is sliced and traced, the memory operand address needs to be traced.

[0064] 4) During the tracing process, update the SliceMap (use the SliceMap to record the storage units that need to be sliced and traced), and establish a reverse slice relationship flow graph. Each node represents a storage unit, and the edge represents the data dependency relationship.

[0065] 5) After the reverse slice calculation is completed, a complete reverse slice relationship flow graph is obtained.

[0066] To solve the problem of traditional reverse slice path explosion, an adaptive slice granularity adjustment algorithm (automatically select byte / word / double-word granularity based on the vulnerability type), a path-sensitive hierarchical slicing strategy (fine-grained analysis of the core path and coarse-grained processing of the non-critical path), and probabilistic data flow analysis (probabilistic modeling of uncertain dependency relationships) are designed.

[0067] 4. Vulnerability determination:

[0068] Based on the results of forward taint analysis and reverse slice calculation, perform vulnerability determination:

[0069] 1) Analyze the taint status of the operands and registers at the abnormal position of the program to determine whether the exception is caused by tainted data control. If so, it is determined as a vulnerability such as memory out-of-bounds or buffer overflow.

[0070] 2) If it is not tainted data control, extract the process of pointer dereference and the data link nodes through reverse slicing, and further analyze whether there are memory corruption vulnerabilities such as heap overflow or wild pointer.

[0071] 3) Use the normal input as the test data, extract the attribute information of the abnormal crash position in the normal input, compare it with the abnormal input, and locate the difference points for verification analysis. For example, compare the differences in a certain register value between the normal input and the abnormal input to determine whether it is a key parameter for vulnerability exploitation.

[0072] 5. Iterative analysis: If the above analysis still does not draw a conclusion, perform iterative analysis of reverse slicing on the data link nodes or conditional control nodes until a high-risk vulnerability is determined.

[0073] The present invention proposes a data flow analysis method based on reverse slicing, which traces and analyzes the security defect abnormal data through the data flow analysis method of reverse slicing. The data flow analysis method based on reverse slicing consists of two parts: execution record extraction and reverse slice calculation. Among them, the execution record extraction can be realized based on the dynamic analysis technology of full-system monitoring. The present invention mainly elaborates on the process method of reverse slice calculation.

[0074] The analysis of backward slicing relies on the dynamic execution record of the program. The execution record is recorded in the order of instruction execution. However, backward slicing analysis needs to be done in reverse. According to the recorded instruction sequence, each instruction is analyzed one by one from the back to the front to trace the data source of the concerned memory or register. The initially marked taint sources in taint analysis are usually whole memory blocks, while backward slicing traces more single variables according to actual needs. This variable can be a single byte, double-byte, four-byte or longer continuous storage unit.

[0075] The input of backward slicing analysis requires the user to specify two time points (the sequence numbers of executed instructions) as the start and end positions of the slice. The start point is the later executed one, so the instruction sequence number id of the start point is greater than that of the end point. At the same time, the user needs to specify the memory or register address and size of the slice as the target unit for slice backtracking. The analysis process is to parse each instruction execution record in reverse order from the start point to the end point. During the instruction parsing process, according to the instruction semantics and operand addresses, the storage units that need to be sliced and traced are recalculated. The storage units for slice backtracking also adopt the page table method, which records the storage units SliceMap that need to be sliced and traced in the current memory.

[0076] During the backward slicing analysis process, there are similarities and obvious differences between the update calculation of the slice backtracking storage unit and the dynamic taint propagation calculation. Both need to parse the instruction machine code, extract the instruction opcode to obtain the instruction meaning, and obtain the source operation bytes and destination operation bytes based on the instruction semantics. As Figure 1 shown, the taint propagation calculation updates the taint status of the destination operation bytes according to the taint status of the source operation bytes, while backward slicing analysis is the opposite. It updates the backtracking requirements of the source bytes according to the backtracking requirements of the destination operation bytes, and at the same time needs to eliminate the backtracking requirements of the destination operation bytes, while taint analysis does not eliminate the taint status of the source bytes.

[0077] During the backward slicing analysis process, by extracting the associated node information and establishing the connection edge relationship of the node information, the backward slice relationship flow graph can be drawn. When updating the slice memory status, the corresponding instruction sequence number is stored in the slice memory structure. When retrieving the slice status of the destination byte, if this byte is the byte that needs to be sliced and backtracked, the id of the backtracking node is also recorded. A relationship edge is established between the record with the corresponding id and the id record of the currently analyzed instruction as an element for drawing the slice backtracking flow graph. After the backward slicing analysis is completed, the project stores all the extracted relationship edges in a file according to the record format drawn by graph, and directly draws the backward slice data flow graph through the graphviz dot component.

[0078] Combining the data flow analysis method of forward taint propagation and backward slicing, the present invention intends to implement the vulnerability analysis and determination for gateway device software through the following process:

[0079] 1) Use dynamic analysis technology with full-system monitoring to monitor the triggering process of software security defects in the gateway device, record the instruction Trace information executed, and the input information that triggers the defect exception.

[0080] 2) Mark the input information that triggers the defect exception as the taint source. According to the marked taint source, parse each instruction executed by the process, and perform taint propagation analysis according to the instruction semantics, dynamically updating and maintaining the memory taint status during the analysis process.

[0081] 3) Analyze the taint status of the instruction operands and registers at the abnormal position of the program, as well as the taint status of the valid memory pointed to by each register. If the crash is caused by the taint data controlling the addressing pointer register, it is an exception caused by un-detected array out-of-bounds. The calculation process of the abnormal data can be drawn through taint backtracking.

[0082] 4) If the operands and related addressing registers at the abnormal position are not controlled by taint data, extract the process of pointer dereference and the data link nodes through reverse data flow analysis.

[0083] 5) Monitor the heap allocation and release during the program running process, record the address and size of the heap allocation, mark the space storing the heap address as taint, perform taint propagation analysis on the pointer dereference process, and detect whether there is a heap overflow in the link nodes extracted in step 4); at the same time, mark the released heap and detect whether the extracted link nodes reference the released heap pointer. If neither occurs, proceed to step 6.

[0084] 6) Use the normal input as the test data, extract the attribute information of the abnormal crash position in the normal input. If the normal input does not execute to this position, change to another normal input. If the condition is still not met after changing multiple inputs, extract the attributes of the link node positions in step 4) during the execution of the normal sample. These attribute information include the values of the operands and registers, and the calculation process of these values. Compare the differences between the crash input and the normal input at these nodes, and locate the difference points for verification and analysis.

[0085] 7) If no conclusion is reached after the above analysis, iterative analysis of reverse slicing can be performed on the data link nodes extracted in step 4, or their conditional control nodes, that is, use the output of step 4 as the input of step 4 for iterative analysis.

[0086] Embodiment

[0087] Suppose there is a buffer overflow vulnerability in the software of a certain gateway device. An attacker can trigger this vulnerability by constructing specific input data, resulting in the program crashing.

[0088] Use the method of the present invention for vulnerability determination:

[0089] 1. Record the instruction execution trace information during the software running process through the whole-system monitoring technology.

[0090] 2. Mark the input data that triggers the crash as the taint source, perform forward taint analysis, and obtain the memory taint status.

[0091] 3. Specify the starting point of the backward slice as the crash instruction, the ending point as the buffer read instruction, and the target memory address as the buffer address, perform backward slice calculation, and obtain the backward slice relationship flow graph.

[0092] 4. Analyze the backward slice relationship flow graph and find that the buffer data is overwritten by malicious input data, resulting in program crash.

[0093] 5. Determine that the vulnerability is a buffer overflow vulnerability and provide the critical path and parameters for exploiting the vulnerability.

[0094] It can be seen that the present invention proposes a fast determination method for high-risk vulnerabilities based on backward slicing, combines forward taint analysis and backward data flow analysis, effectively solves the problem of determining memory corruption security defects in complex software systems, and has important theoretical significance and application value.

[0095] The above are only the preferred embodiments of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the technical principle of the present invention, several improvements and deformations can still be made, and these improvements and deformations should also be regarded as the protection scope of the present invention.

Claims

1. A method for rapid determination of high-risk vulnerabilities based on reverse slicing, characterized in that: The following steps are involved: Step 1: Execution record extraction: Through the dynamic analysis technology of full system monitoring, the triggering process of gateway device software security defects is monitored, and the instruction execution trajectory information during the software operation and the input information that triggers the defect exception are recorded. The instruction execution trajectory information includes the instruction address, operand, and register status; Step 2: Forward taint analysis: Mark the input information that triggers the defect exception as the taint source, dynamically propagate the taint according to the taint source, and update the memory taint status; Step 3: Reverse slice calculation: 1) Specify the starting and ending points of the reverse slice, as well as the target memory address or register address of the slice; 2) Initialize the storage unit SliceMap and record the storage units that need to be sliced ​​and traced; 3) Starting from the starting instruction, reverse parse the execution record of each instruction and trace the source of the target data according to the instruction semantics; 4) During the tracing process, SliceMap is used to record the storage units that need to be sliced ​​and traced, and a reverse slice relationship flow graph is established, where each node represents a storage unit and the edge represents the data dependency relationship; 5) After the reverse slicing calculation is completed, a complete reverse slicing relationship flow graph is obtained; Step 4: Vulnerability determination: Based on the results of forward stain analysis and reverse slice calculation, vulnerability determination is performed: 1) Analyze the tainted status of the operands and registers at the program exception location to determine whether the exception is caused by tainted data control; 2) If yes, it is determined to be a memory out-of-bounds or buffer overflow vulnerability; if not, the pointer dereference process and data link node are extracted through reverse slicing, and the next step is to further analyze whether there is a memory corruption vulnerability; 3) Use normal input as test data, extract attribute information of abnormal crash location in normal input, compare with abnormal input, locate difference points for verification analysis; Step 5, iterative analysis: If step 4 does not reach a conclusion, perform iterative analysis of reverse slicing on the data link node or conditional control node until a high-risk vulnerability is determined.

2. The method according to claim 1, characterized in that The dynamic analysis technology for full-system monitoring adopts a hybrid tracking mechanism based on hardware virtualization extension and dynamic binary instrumentation; among them, hardware-level EPT page table monitoring is used to achieve non-intrusive full-system monitoring; fine-grained DBI instrumentation is enabled for key functions; a cache mechanism is designed, and hash fingerprint compression storage is used for preset high-frequency repeated instruction sequences.

3. The method according to claim 1, characterized in that Step 2 is as follows: 1) Initialize the taint state and mark the memory area corresponding to the taint source as tainted; 2) According to the instruction execution order, parse the machine code of each instruction and extract the instruction opcode and operand; 3) Update the taint state of the target operand according to the instruction semantics; for the mov instruction, propagate the taint state of the source operand to the target operand; 4) Repeat steps 1) to 3) until all instructions are executed and complete taint status information is obtained.

4. The method according to claim 1, characterized in that In step 3 of 3), if the starting instruction is an add instruction, if the target register is sliced ​​and traced, then the source operand register is traced; If the starting instruction is a load instruction, if the target register is sliced ​​and traced, the memory operand address is traced.

5. The method according to claim 1, characterized in that This method relies on the dynamic execution record of the program. The execution record is recorded in the order of instruction execution. This method analyzes the recorded instruction sequence one by one from back to front to trace the data source of the memory or register of interest. This method traces a single variable, which is a single-byte, double-byte, four-byte or longer continuous storage unit.

6. The method according to claim 1, characterized in that The input of this method requires the user to specify two time points as the starting point and end point of the slice. The starting point is executed later, so the instruction number id of the starting point is greater than the instruction number id of the end point. At the same time, the user needs to specify the memory or register address and size of the slice as the target unit for slice backtracking. The process of this method is to parse each instruction execution record in reverse from the starting point to the end point. During the instruction parsing process, the storage unit that needs to be sliced ​​is recalculated according to the instruction semantics and operand address. The storage unit for slice tracing also uses a page table to record the storage unit SliceMap that needs to be sliced ​​and traced in the current memory.

7. The method according to claim 1, characterized in that In this method, by extracting the associated node information and establishing the connection edge relationship of the node information, a reverse slice relationship flow graph is drawn; when updating the slice memory state, the corresponding instruction sequence number is stored in the slice memory structure. When retrieving the target byte slice state, if the byte is the byte that needs slice backtracking and the id of the backtracking node is also recorded, a relationship edge is established between the record of the corresponding id and the id record of the current analysis instruction as a drawing element of the slice backtracking flow graph.

8. A system for implementing the method according to any one of claims 1 to 7.

9. A software development method based on the method design according to any one of claims 1 to 7.

10. A software development system designed based on the method according to any one of claims 1 to 7.