Automatic utilization method for memory destruction type vulnerabilities based on large model

Through the automated utilization method based on large models, the problem of time-consuming and error-prone traditional exploitation methods is solved, and efficient automated utilization of memory corruption vulnerabilities is realized, which improves the success rate and efficiency of exploitation.

CN120180445APending Publication Date: 2025-06-20BEIJING INST OF COMP TECH & APPL
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510271561.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-08
Publication Date
2025-06-20

AI Technical Summary

Technical Problem

Traditional memory corruption vulnerability exploitation methods rely on manual analysis, are time-consuming and error-prone, making it difficult to achieve automation and efficient utilization.

Method used

The automated utilization method based on large models is adopted to automatically generate vulnerability utilization code through steps such as data collection and preprocessing, large model training and optimization, vulnerability analysis, utilization code generation and optimization, automated testing and verification.

Benefits of technology

It improves the efficiency and success rate of vulnerability utilization, reduces manual intervention, and reduces the difficulty and cost of vulnerability utilization.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader

Abstract

The invention relates to an automatic utilization method of memory destruction type vulnerabilities based on a large model, and belongs to the technical field of network security. Through intelligent analysis of a large model, vulnerabilities can be quickly positioned, utilization codes can be generated, and the vulnerability utilization efficiency is improved; in combination with the code generation capability of a large model, high-quality utilization codes can be generated, and the success rate of vulnerability utilization is improved; through an automatic test and verification process, manual intervention is reduced, and the difficulty and cost of vulnerability utilization are reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of network security technology, and particularly relates to an automated exploitation method for memory corruption vulnerabilities based on large models. Background Art

[0002] Memory corruption vulnerabilities (such as buffer overflows, Use-After-Free, heap overflows, etc.) are the most dangerous type of vulnerabilities in the field of network security and are often used by attackers to execute arbitrary code or escalate privileges. Traditional vulnerability exploitation methods usually rely on manual analysis, requiring security researchers to have profound reverse engineering and vulnerability exploitation techniques, which are time-consuming and error-prone. In recent years, large models (such as GPT, Codex, etc.) have demonstrated powerful capabilities in code generation and pattern recognition, and can automatically generate high-quality code. Therefore, how to use large models to automatically analyze memory corruption vulnerabilities and generate exploitation code has become an urgent problem to be solved. Summary of the Invention

[0003] (I) Technical Problems to be Solved

[0004] The technical problem to be solved by the present invention is to design an automated exploitation method for memory corruption vulnerabilities, realizing the automatic generation of vulnerability exploitation code and improving the efficiency and success rate of vulnerability exploitation.

[0005] (II) Technical Solutions

[0006] To solve the above technical problems, the present invention provides an automated exploitation method for memory corruption vulnerabilities based on large models, including the following steps:

[0007] Step 1. Vulnerability Analysis Based on Large Model

[0008] 1.1 Data Collection and Preprocessing

[0009] ● Data Sources:

[0010] ○ Target Program: Obtain the binary file (such as ELF, PE file), debugging information (such as PDB file, DWARF information), and symbol table of the target program.

[0011] ○ Crash Log: Collect the crash log (such as Core Dump, Minidump) of the target program when the vulnerability is triggered.

[0012] ○ Vulnerability Description: Obtain the detailed description and exploitation method of the vulnerability from public vulnerability libraries (such as CVE, Exploit-DB).

[0013] ○ Environment Information: Record the operating system version, library version, memory protection mechanism (such as ASLR, DEP), etc. under which the target program runs.

[0014] ● Data preprocessing:

[0015] ○ Disassembly and decompilation: Use tools (such as IDA Pro, Ghidra) to disassemble and decompile binary files, and extract assembly code, function call graphs, and control flow graphs.

[0016] ○ Feature extraction: Extract key features, such as:

[0017] ■ Function call relationships.

[0018] ■ Memory layout information (such as heap, stack, global variables).

[0019] ■ Vulnerability trigger points (such as buffer size, loop boundaries).

[0020] ○ Data formatting: Convert the extracted features into a format suitable for input to the large model (such as text sequences, JSON, or graph structures).

[0021] 1.2 Large model training and optimization

[0022] ● Model selection:

[0023] ○ Use pre-trained large models (such as GPT-4, Codex) as the base model, which perform excellently in code generation and pattern recognition.

[0024] ○ Fine-tune the model according to the characteristics of vulnerability analysis to enable it to understand the semantics of binary code and vulnerability patterns.

[0025] ● Multi-task learning:

[0026] ○ Task design:

[0027] ■ Vulnerability location: Identify potential vulnerability locations in binary code (such as buffer overflow points, Use-After-Free points).

[0028] ■ Vulnerability type identification: Classify vulnerability types (such as stack overflow, heap overflow, format string vulnerability).

[0029] ■ Exploitability assessment: Evaluate the exploitability of vulnerabilities (such as whether the memory protection mechanism can be bypassed).

[0030] ○ Loss function: Design independent loss functions for each task and perform joint optimization by combining weighted summation.

[0031] ● Reinforcement learning optimization:

[0032] ○ Dynamically adjust the model parameters through reinforcement learning to enable it to adapt to the environments of different target programs.

[0033] ○Design the reward function, for example:

[0034] ■Reward +1 for correctly identifying the vulnerability location.

[0035] ■Penalty -1 for incorrectly identifying the vulnerability location.

[0036] ■Reward +2 for successfully generating an exploit code.

[0037] 1.3 Vulnerability Analysis

[0038] ●Input data: Binary file of the target program, debugging information, crash logs, and vulnerability descriptions.

[0039] ●Model inference:

[0040] ○Utilize the sequence modeling ability of the large model to analyze the control flow and data flow of the binary code.

[0041] ○Combine the crash logs and vulnerability descriptions to infer the trigger conditions and exploitability of the vulnerability.

[0042] ●Output results:

[0043] ○Vulnerability location (such as function name, offset address).

[0044] ○Vulnerability type (such as stack overflow, Use-After-Free).

[0045] ○Exploitability assessment (such as high, medium, low).

[0046] Step 2. Automated Exploit Code Generation

[0047] 2.1 Exploitation Strategy Generation

[0048] ●Input data: Vulnerability analysis results (such as vulnerability location, type, exploitability).

[0049] ●Strategy generation:

[0050] ○Generate exploitation strategies according to the vulnerability type. For example:

[0051] ■For stack overflow vulnerabilities: Overwrite the return address or function pointer and construct a ROP chain.

[0052] ■For heap overflow vulnerabilities: Utilize heap spray or adjust the heap layout.

[0053] ■For Use-After-Free vulnerabilities: Replace the freed object and construct a malicious object.

[0054] ○Optimize the exploitation strategy by combining the environment of the target program (such as operating system, memory protection mechanism).

[0055] ● Output result: Use strategies (such as overwriting addresses, ROP chain construction, heap spray layout).

[0056] 2.2 Code generation for exploitation

[0057] ● Input data: Use strategies and environmental information of the target program.

[0058] ● Code generation:

[0059] ○ Utilize the code generation ability of the large model to automatically generate exploit code. For example:

[0060] ■ Stack overflow vulnerability: Generate a payload to overwrite the return address.

[0061] ■ Heap overflow vulnerability: Generate heap spray code and ROP chain.

[0062] ■ Use-After-Free vulnerability: Generate object replacement code.

[0063] ○ The generated code includes:

[0064] ■ Vulnerability trigger code (such as constructing malformed input).

[0065] ■ Memory layout adjustment code (such as heap spray, ROP chain construction).

[0066] ■ Privilege escalation code (such as Shellcode, system calls).

[0067] ● Output result: Exploit code.

[0068] 2.3 Code optimization for exploitation

[0069] ● Input data: The generated exploit code. Specifically, the ASLR entropy value, memory page attributes, and instruction set characteristics of the target system are obtained in real time through the dynamic protection status monitoring module, and architecture-adaptive exploit code is generated accordingly. The NSGA-II multi-objective optimization algorithm is applied in the ROP chain construction stage to minimize the payload length and maximize the address guessing success rate at the same time.

[0070] ● Code optimization:

[0071] ○ Utilize the code optimization ability of the large model to optimize the generated exploitation code. For example:

[0072] ■ Reduce the code length and improve the execution efficiency.

[0073] ■ Bypass memory protection mechanisms (such as ASLR, DEP).

[0074] ■ Improve the stability and reliability of the code.

[0075] ● Output result: Optimized exploit code.

[0076] Step 3. Automated testing and verification

[0077] 3.1 Test environment setup

[0078] ● Environment configuration:

[0079] ○ Set up an environment consistent with the target program (such as operating system version, library version).

[0080] ○ Configure debugging tools (such as GDB, WinDbg) and monitoring tools (such as Process Monitor).

[0081] ● Input data: Target program, generated exploit code.

[0082] 3.2 Test execution and monitoring

[0083] ● Test execution:

[0084] ○ Inject the generated exploit code into the target program and monitor its execution process.

[0085] ○ Record program crash information, memory status, and execution results.

[0086] ● Input data: Exploit code, target program.

[0087] 3.3 Result verification and feedback

[0088] ● Result verification:

[0089] ○ Use a GAN network to construct an attack - defense confrontation verification environment, where the generator module generates Exploit variants that bypass the current protection mechanism, and the discriminator module simulates the EDR / XDR protection system in a real environment.

[0090] ○ Generate 1000 groups of protection variants through the GAN, and the Exploit maintains an 85% success rate.

[0091] ○ Analyze the test results and identify the deficiencies of the exploit code (such as poor stability, low compatibility).

[0092] ● Feedback for optimization:

[0093] ○ Feed the test results back to the large - model to further optimize vulnerability analysis and exploit code generation.

[0094] Output result: Exploit report (such as success / failure, optimization suggestions).

[0095] (III) Beneficial effects

[0096] Through the intelligent analysis of the large model, the present invention can quickly locate vulnerabilities and generate exploitation code, improving the efficiency of vulnerability exploitation; combining the code generation ability of the large model, it can generate high-quality exploitation code, increasing the success rate of vulnerability exploitation; through the automated testing and verification process, it reduces manual intervention and lowers the difficulty and cost of vulnerability exploitation. Detailed implementation manners

[0097] To make the objectives, content and advantages of the present invention clearer, the following further describes in detail the specific implementation manners of the present invention in conjunction with embodiments.

[0098] The present invention provides an automated exploitation method for memory corruption vulnerabilities based on a large model, including steps such as data collection and preprocessing, large model training and optimization, vulnerability analysis, exploitation code generation and optimization, automated testing and verification, etc. The large model is used to analyze the binary file of the target program to locate vulnerabilities and generate exploitation code; through the code generation ability of the large model, high-quality vulnerability exploitation code is automatically generated. Specifically, it includes steps: deploying a large model training environment, collecting and preprocessing the binary file and debugging information of the target program; training and optimizing the large model so that it can accurately analyze memory corruption vulnerabilities; developing an automated vulnerability exploitation tool, integrating the vulnerability analysis and code generation capabilities of the large model; conducting automated vulnerability exploitation tests on the target program, recording and analyzing the test results; optimizing the exploitation code according to the test results and generating a detailed vulnerability exploitation report. This method automatically generates exploitation code (Exploit) through the intelligent analysis ability of the large model, improving the efficiency and success rate of vulnerability exploitation.

[0099] The following details the implementation process of the "automated exploitation method for memory corruption vulnerabilities based on a large model" of the present invention through a specific embodiment. This embodiment takes a stack overflow vulnerability as an example to show how to use the large model to automatically analyze vulnerabilities and generate exploitation code.

[0100] 1. Scenario description

[0101] ● Target program: A Linux application program (ELF format) with a stack overflow vulnerability.

[0102] ● Vulnerability type: Stack overflow vulnerability. Due to the lack of boundary checking on user input, the return address is overwritten.

[0103] ● Target environment: Ubuntu 20.04, with ASLR and DEP protection mechanisms enabled.

[0104] ● Target effect: Achieve arbitrary code execution through the exploitation code (Exploit).

[0105] 2. Implementation steps

[0106] 2.1 Data Collection and Preprocessing

[0107] 1. Obtain the target program:

[0108] ○ Download the binary file (vulnerable_program) and debugging information (such as DWARF information) of the target program.

[0109] 2. Collect crash logs:

[0110] ○ Run the target program and trigger the vulnerability to generate a crash log (Core Dump).

[0111] ○ Use GDB to analyze the crash log and obtain the register status and stack information at the time of the crash.

[0112] 3. Extract features:

[0113] ○ Use IDA Pro to disassemble the target program and extract the following features:

[0114] ■ Function call relationships (such as the main function calling the vulnerable_function).

[0115] ■ Stack frame layout (such as the location of local variables and return addresses).

[0116] ■ Vulnerability trigger points (such as the call location of the strcpy function).

[0117] ○ Convert the extracted features into structured data (such as JSON format).

[0118] 2.2 Large Model Training and Optimization

[0119] 1. Model selection:

[0120] ○ Use the pre-trained GPT-4 model as the base model.

[0121] 2. Fine-tune the model:

[0122] ○ Prepare the training data:

[0123] ■ Collect public stack overflow vulnerability samples (such as CVE vulnerability descriptions, Exploit code).

[0124] ■ Label the vulnerability location, type, and exploitation method.

[0125] ○ Design a multi-task learning framework:

[0126] ■ Task 1: Vulnerability location (identifying the call location of the strcpy function).

[0127] ■ Task 2: Vulnerability type identification (classifying as a stack overflow vulnerability).

[0128] ■ Task 3: Exploitability Assessment (assess whether ASLR and DEP can be bypassed).

[0129] ○ Optimize the model using reinforcement learning:

[0130] ■ Design a reward function, for example:

[0131] ■ Reward +1 for correctly identifying the vulnerability location.

[0132] ■ Penalty -1 for incorrectly identifying the vulnerability location.

[0133] ■ Reward +2 for successfully generating an exploit code.

[0134] 2.3 Vulnerability Analysis

[0135] 1. Input data:

[0136] ○ Binary file, debug information, and crash log of the target program.

[0137] 2. Model inference:

[0138] ○ Analyze the binary code using a large model to identify the following information:

[0139] ■ Vulnerability location: strcpy call in vulnerable_function.

[0140] ■ Vulnerability type: Stack overflow vulnerability.

[0141] ■ Exploitability: High (DEP can be bypassed through ROP chain).

[0142] 3. Output result:

[0143] ○ Vulnerability analysis report:

[0144] ■ Vulnerability location: vulnerable_function + 0x45.

[0145] ■ Vulnerability type: Stack overflow.

[0146] ■ Exploitability: High.

[0147] 2.4 Automated Exploit Code Generation

[0148] 1. Exploitation strategy generation:

[0149] ○ Generate the following exploitation strategies based on the vulnerability analysis results:

[0150] ■ Overwrite the return address and jump to the ROP chain.

[0151] ■ Use the ROP chain to call system(" / bin / sh").

[0152] 2. Code generation:

[0153] ○ Use the code generation ability of the large model to generate the following code:

[0154] ■ Payload construction:

[0155] python

[0156] payload = b"A" * 128 # Fill the buffer

[0157] payload += p32(0x0804856b) # Overwrite the return address and jump to the ROP chain

[0158] ■ ROP chain construction:

[0159] python

[0160] rop_chain = p32(0x080483e0) # Call the system function

[0161] rop_chain += p32(0x0804856b) # Return address

[0162] rop_chain += p32(0x0804a008) # Address of the " / bin / sh" string

[0163] ■ Complete Exploit code:

[0164] python

[0165] from pwn import *

[0166] # Target program

[0167] elf = ELF("vulnerable_program")

[0168] p = process(elf.path)

[0169] # Payload construction

[0170] payload = b"A" * 128

[0171] payload += p32(0x0804856b) # Overwrite the return address

[0172] # Send the Payload

[0173] p.sendline(payload)

[0174] p.interactive()

[0175] 3. Code optimization:

[0176] ○ Optimize the generated Exploit code to ensure its compatibility and stability:

[0177] ■ Adjust the Payload length to avoid triggering other exceptions.

[0178] ■ Bypass the ASLR and DEP protection mechanisms.

[0179] 2.5 Automated testing and verification

[0180] 1. Test environment setup:

[0181] ○ Run the target program in the Ubuntu 20.04 environment.

[0182] ○ Configure GDB and Process Monitor to monitor the program execution process.

[0183] 2. Test execution:

[0184] ○ Run the generated Exploit code and observe the response of the target program.

[0185] ○ Record the program crash information, memory status, and execution results.

[0186] 3. Result verification:

[0187] ○ Verify whether the Exploit code successfully triggers the vulnerability and executes / bin / sh.

[0188] ○ Analyze the test results and identify the deficiencies of the Exploit code (such as poor stability and low compatibility).

[0189] 4. Feedback for optimization:

[0190] ○ Feed back the test results to the large model to further optimize the vulnerability analysis and Exploit code generation.

[0191] 3. Implementation results

[0192] ● Vulnerability analysis: Successfully identify the location and type of the stack overflow vulnerability.

[0193] ● Exploit generation: Automatically generate high-quality Exploit code.

[0194] ● Test verification: The Exploit code successfully triggers the vulnerability and achieves arbitrary code execution.

[0195] 4. Technical advantages

[0196] 1. Intelligent Vulnerability Analysis: Leveraging the intelligent analysis capabilities of large models to quickly locate vulnerabilities and generate exploitation code.

[0197] 2. Automated Code Generation: Utilizing the code generation capabilities of large models to automatically generate high-quality Exploit code.

[0198] 3. Efficient Testing and Verification: Through automated testing and verification processes, reduce manual intervention and improve the success rate of vulnerability exploitation.

[0199] Through the above embodiments, the present invention demonstrates how to use large models to automatically analyze memory corruption vulnerabilities and generate exploitation code, significantly improving the efficiency and success rate of vulnerability exploitation.

[0200] The present invention has broad application prospects and is applicable to fields such as vulnerability mining, penetration testing, and security protection.

[0201] The above are only the preferred embodiments of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the technical principles of the present invention, several improvements and modifications can be made, and these improvements and modifications should also be regarded as the protection scope of the present invention.

Claims

1. An automated exploitation method for memory corruption vulnerabilities based on a large model, characterized in that: The following steps are involved: Step 1. Vulnerability analysis based on large models 1.1 Data collection and preprocessing Data Collection: Get the target program's binary file, debugging information, and symbol table; Collect the crash log of the target program when the vulnerability is triggered; Obtain vulnerability descriptions and exploits from public vulnerability repositories; Record the operating system version, library version, and memory protection mechanism of the target program; Data preprocessing: Disassembly and decompilation: Use tools to disassemble and decompile binary files to extract assembly code, function call graphs, and control flow graphs; Feature extraction: Extract key features, including function call relationships, memory layout information, and vulnerability trigger points; Data formatting: converting the extracted features into a format suitable for large model input; 1.2 Large Model Training and Optimization Model selection: Use a pre-trained large model as the base model; Based on the characteristics of vulnerability analysis, the large model is fine-tuned to enable it to understand the semantics and vulnerability patterns of binary codes; Multi-task learning: The following tasks are designed: Vulnerability location: Identify potential vulnerability locations in binary code; Identify vulnerability types; Evaluate the exploitability of vulnerabilities; Design loss function: Design an independent loss function for each task and perform joint optimization by combining weighted summation; Reinforcement Learning Optimization: Dynamically adjust model parameters through reinforcement learning to enable it to adapt to the environment of different target programs; The reward function is designed according to the following principles: +1 reward for correctly identifying the vulnerability location; -1 penalty for incorrectly identifying the vulnerability location; +2 reward for successfully generating the exploit code; 1.3 Vulnerability Analysis Input data, including the target program's binary file, debugging information, crash logs, and vulnerability descriptions; Model Inference: Analyze the control flow and data flow of binary code by using the sequence modeling capability of the large model; Combine crash logs and vulnerability descriptions to infer the triggering conditions and exploitability of the vulnerability; Output results, including vulnerability location, vulnerability type, and exploitability assessment results; Step 2. Automated exploit code generation 2.1 Exploitation Strategy Generation Input data: Input vulnerability analysis results, including vulnerability location, vulnerability type, and exploitability; Strategy Generation: Generate exploit strategies based on vulnerability types, including: Stack overflow vulnerability: overwrite the return address or function pointer to construct a ROP chain; Heap overflow vulnerability: using heap spray or heap layout adjustment; Use-After-Free vulnerability: replace the released object and construct a malicious object; Output utilization strategy; 2.2 Utilizing code generation Input data: including exploitation strategies and environment information of target programs; Code Generation: Using the code generation capability of the large model, we can automatically generate the exploit code for the heap overflow vulnerability, including: Stack overflow vulnerability: Generate a payload that overwrites the return address; Heap overflow vulnerability: Generate heap spray code and ROP chain; Use-After-Free vulnerability: Generate object replacement code; The generated code includes: vulnerability triggering code; memory layout adjustment code; privilege escalation code; Output the exploit code; 2.3 Utilizing Code Optimization Input data: including the generated vulnerability exploit code, which is generated by obtaining the ASLR entropy value, memory page attributes and instruction set characteristics of the target system in real time, and generating adaptive vulnerability exploit code; Code optimization: Use the code optimization capabilities of the large model to optimize the generated exploit code, including: Reduce code length; Bypass memory protection mechanisms; Output optimized vulnerability exploit code; Step 3. Automated testing and verification 3.1 Test environment construction Environment configuration: Build an environment consistent with the target program; Configure debugging tools and monitoring tools; Input data: including target program and generated exploit code; 3.2 Test Execution and Monitoring Test execution: Inject the generated exploit code into the target program and monitor its execution process; Record program crash information, memory status and execution results; Enter the vulnerability exploit code and target program; 3.3 Result verification and feedback Verification results: The GAN network is used to build an attack and defense confrontation verification environment, in which the generator is used to generate exploit variants that bypass the current protection mechanism, and the discriminator is used to simulate the EDR / XDR protection system in the real environment; Verify whether the Exploit code successfully triggers the vulnerability; Analyze test results and identify deficiencies in the exploit code; Feedback optimization: Feed the test results back to the big model to further optimize vulnerability analysis and exploit code generation; Outputs an exploit report.

2. The method according to claim 1, characterized in that The binary files of the target program include ELF and PE files, and the debugging information includes PDB files and DWARF information.

3. The method according to claim 1, characterized in that Memory layout information includes heap, stack, and global variables.

4. The method according to claim 1, characterized in that In step 1.1, when formatting data, the extracted features are converted into text sequences, JSON, or graph structures.

5. The method according to claim 1, characterized in that In step 1.2, potential vulnerability locations in the binary code identified during vulnerability location include buffer overflow points and Use-After-Free points.

6. The method according to claim 1, characterized in that In step 1.2, the identified vulnerability types include stack overflow, heap overflow, and format string vulnerability.

7. The method according to claim 1, characterized in that When generating the exploit strategy in step 2.1, the exploit strategy is optimized in combination with the environment of the target program.

8. The method according to claim 7, characterized in that The target program's environment includes the operating system and memory protection mechanism.

9. The method according to claim 1, characterized in that The exploit strategy output in step 2.1 includes the overwrite address, heap spray layout, and ROP chain construction.

10. A system for implementing the method according to any one of claims 1 to 9.