Multi-entry point extraction and call graph construction method for SpringWeb framework
Through the Tai-e-based plug-in system, multiple entry points of the SpringWeb framework are extracted and call diagrams are constructed, which solves the shortcomings of traditional tools in identifying multiple entry points and dependencies in the Spring framework, and realizes efficient static analysis and vulnerability detection of SpringWeb applications.
Patent Information
- Application Number
- CN202510358542.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-25
- Publication Date
- 2025-07-08
AI Technical Summary
Traditional static analysis tools are difficult to effectively identify and analyze multiple entry points and their dependencies in the Spring framework, which leads to shortcomings in the control flow and data flow analysis of web applications, especially when facing the dynamic characteristics of the Spring framework.
A plug-in system based on the open source static analysis tool Tai-e is developed. By collecting the annotation rules provided by Spring, multiple entry points of web applications are extracted, and call graphs are built, dependency injection objects are identified, and a complete call graph is generated for vulnerability detection.
It realizes automatic identification and extraction of multiple entry points of SpringWeb applications, builds a complete call graph, can accurately analyze control flow and data flow, and supports efficient application behavior inference and vulnerability detection.
Smart Images

Figure CN120277674A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of cyberspace security and relates to a method for extracting multiple entry points and constructing a call graph for the Spring Web framework. Background Art
[0002] In modern Java Web development, the Spring framework has become the mainstream choice. Its modularity, powerful dependency injection (DI), and aspect-oriented programming (AOP) features have greatly simplified the development process. Dependency injection can decouple the dependencies between components, and aspect-oriented programming can centrally manage cross-cutting concerns such as logging and security control. These technologies provide developers with higher flexibility and maintainability. However, this dynamic nature of the Spring framework also poses significant challenges in static application analysis.
[0003] The complex structure of Web applications further increases the difficulty of static analysis. Different from general single-entry-point programs, Web applications usually consist of multiple entries, such as controllers, service layers, and REST API interfaces. These entry points work together to handle user requests, forming a huge call network. Comprehensive analysis of these entry points is the key to accurately inferring the application behavior. However, due to the diversity and dynamic nature of Web applications, traditional static analysis tools face challenges in identifying and analyzing all entry points.
[0004] In addition, dynamic features such as dependency injection and AOP in the Spring framework make the static analysis of control flow and data flow more difficult. Dependency injection is usually resolved and dynamically bound at runtime, making it difficult to determine specific dependencies at compile time; while AOP affects the actual path of method calls, resulting in traditional static analysis techniques being difficult to capture the complete call relationship. These dynamic features make the control flow of the application appear ambiguous at compile time. Therefore, traditional static analysis tools are difficult to obtain accurate results when dealing with Spring Web applications.
[0005] Currently, there are some tools for static application security testing (SAST), such as Soot, Wala, Doop, and CodeQL, etc., which are efficient in source code analysis but still have limitations when dealing with multiple entry points of Web applications and the dynamic nature of Spring. They have deficiencies in extracting multiple entry points and accurately constructing dependency relationships, and it is difficult to comprehensively analyze complex control flow and data flow. These deficiencies reveal the defects of traditional static analysis methods in modern Web application scenarios and also lay the foundation for the research of new static analysis methods. Summary of the Invention
[0006] In view of the problem that the Spring's dependency injection cannot be directly analyzed in the field of static analysis, the present invention develops a Web application analysis system that can be "used out of the box" based on the plugin system of the open-source static analysis tool Tai-e. This system solves the dynamic characteristics of the Spring framework's "dependency injection", can extract multiple entry points of the Web application and analyze the call flow of each call point, and simultaneously generate a call graph. Then, based on the call flow of each entry, it detects the call flows with vulnerabilities in these call flows to complete vulnerability detection.
[0007] To achieve the above object, the present invention provides the following technical solutions:
[0008] A method for extracting multiple entry points and constructing a call graph for the Spring Web framework, characterized by including the following steps:
[0009] (1) Collect the annotation rules provided by Spring official, and sort out the annotation rules related to web entry and the annotation rules related to dependency injection;
[0010] (2) Load the project to be analyzed through the open-source static analysis tool, and extract the url path and the corresponding entry method according to the annotation rules related to web entry sorted out in step (1);
[0011] (3) Add the entry method corresponding to the url path obtained in step (2) as the initial entry of the call graph, and then process the objects of dependency injection according to the annotation rules related to dependency injection sorted out in step (1) to construct a complete call graph;
[0012] (4) Output the url path and the corresponding entry method in the program, and respectively output the call flow of each entry method.
[0013] Further, the step (1) specifically includes the following sub-steps:
[0014] (1.1) Collect the annotation rules related to web entry in the Spring framework, specifically including the following annotation rules: @Controller (controller annotation), @RestController (REST controller annotation, returning data instead of view), @RequestMapping (general request annotation), @GetMapping (GET request annotation), @PostMapping (POST request annotation), @PutMapping (PUT request annotation), @DeleteMapping (DELETE request annotation), @PatchMapping (PATCH request annotation);
[0015] (1.2) Collect the annotation rules related to dependency injection in the Spring framework, specifically including the following annotation rules: Bean-related rules: @Component (general component annotation), @Service (service layer annotation), @Repository (data access layer annotation), @Controller (controller annotation), @RestController (REST controller annotation), @Configuration (configuration class annotation), @Bean (Bean definition annotation);
[0016] Injection point-related rules: @Autowired (automatic injection annotation), @Inject (automatic injection annotation), @Resource (resource annotation), @Qualifier (qualifier annotation), @Value (value annotation).
[0017] Furthermore, the step (2) specifically includes the following sub-steps:
[0018] (2.1) Use an open-source static analysis tool to load the project to be analyzed, obtain all application classes in the project, and filter out the classes containing controller annotation-related according to the web entry-related annotation rules collected in step (1.1), and mark them as controller classes;
[0019] (2.2) Check each method in the controller classes collected in step (2.1) one by one, and collect all methods containing any Mapping annotation in the web entry-related annotation rules collected in step (1.1);
[0020] (2.3) For the entry methods containing the Mapping annotation collected in step (2.2), extract their URL path information, establish the mapping relationship between the path and the entry method, and store the result in the mapping table for subsequent use in call graph construction and dependency injection processing;
[0021] Furthermore, the step (3) specifically includes the following sub-steps:
[0022] (3.1) Use an open-source static analysis tool to add the entry methods collected in step (2.2) as the entry methods of the call graph;
[0023] (3.2) According to the dependency injection-related annotation rules collected in step (1.2), analyze each application class, and if it contains the relevant rules, add this class to the Bean set;
[0024] (3.3) Process dependency injection points. For the three injection cases of field injection, constructor injection, and Setter method injection, first process them according to "name injection", and then according to "type injection". For field injection, if the field has the injection point-related rules collected in step (1.2), first determine whether the name of the class to be injected is specified by an annotation. If so, find the corresponding class in the Bean set collected in step (3.2) according to the specified name. If there is no @Qualifier, find the corresponding class in the Bean set according to the field name, and add the found result to the variable pointer set.
[0025] (3.4) For constructor injection and Setter method injection, directly find the corresponding Bean in the Bean set according to the field name.
[0026] (3.5) If steps (3.3) and (3.4) fail to handle correctly, find the corresponding class and all its subclasses in the Bean set according to the type, and add the result to the variable pointer set.
[0027] Further, the specific processing algorithm of step (3.3) is as follows:
[0028] (3.3.1) Extract the variable name and the name of the field to be loaded from the LoadField statement.
[0029] (3.3.2) Determine whether the field extracted in step (3.3.1) has the annotation rules related to dependency injection collected in step (1.2).
[0030] (3.3.3) If it has the annotation rules related to dependency injection collected in step (1.2), first obtain the name specified by the annotation, and then search for the class with this name in the Bean set collected in step (3.2). If the annotation does not specify a name, use the name of the field itself to be loaded to search for the class with this name in the Bean set collected in step (3.2).
[0031] (3.3.4) If the result in step (3.3.3) is not empty, create an abstract object for the found class using the open-source static analysis framework Tai-e and add the abstract object to the pointer set of the variable extracted in step (3.3.1).
[0032] (3.3.5) If the abstract object is successfully created and added to the pointer set of the variable, mark the variable as "processed state".
[0033] Further, the specific processing algorithm of step (3.4) is as follows:
[0034] (3.4.1) First, extract the variable name and the name of the field to be loaded from the LoadField statement and create a mapping;
[0035] (3.4.2) Directly use the name of the field itself to be loaded to search for the class with this name in the Bean set collected in step (3.2);
[0036] (3.4.3) If the result in step (3.4.2) is not empty, use the open-source static analysis framework Tai-e to create an abstract object for the found class and add the abstract object to the pointer set of the variable extracted in step (3.4.1);
[0037] (3.4.4) If the abstract object is successfully created and added to the variable's pointer set, mark the variable as "processed state"
[0038] (3.4.5) For variables not marked as "processed state", search for the corresponding class in the Bean set collected in step (3.2) according to the type of the variable, and add the found class and all its subclasses to the variable pointer set;
[0039] (3.4.6) For the "this" variable, search for the corresponding class in the Bean set collected in step (3.2) according to the type of the "this" variable, and add the found class to the variable pointer set.
[0040] Furthermore, step (4) specifically includes the following sub-steps:
[0041] (4.1) Output the mapping table of the URL path and the corresponding entry method in the program, clearly recording the association relationship between each URL path and its entry method;
[0042] (4.2) Generate call flow output for the call graph of each entry method, including the direct and indirect call methods of the entry method, and save the call graph structure for subsequent analysis.
[0043] Compared with the prior art, the present invention has the following advantages and beneficial effects:
[0044] (1) The present invention can automatically identify and extract all URL entry paths and their associated methods, and output and display this information;
[0045] (2) The present invention can handle the objects implicitly created by the Spring framework during dynamic operation. By identifying these dependency injection objects and adding them to the pointer set of relevant variables, the system can effectively construct a complete call graph, thus providing a solid foundation for subsequent analysis. Description of the Drawings
[0046] Figure 1This is the implementation framework diagram of the method of the present invention.
[0047] Figure 2 This is the flow chart for extracting Beans in the sub-step of processing dependency injection in the present invention. Detailed implementation manners
[0048] The following will detail the technical solutions provided by the present invention in combination with specific embodiments. It should be understood that the following specific implementation manners are only used to illustrate the present invention and not to limit the scope of the present invention.
[0049] The present invention proposes a method for extracting multiple entry points and constructing a call graph for the Spring Web framework. It is developed based on the open-source static analysis tool Tai-e plug-in system. By statically analyzing and extracting the control flow and data flow information of Web applications, a call graph is generated to support efficient application behavior inference. The implementation steps are as Figure 1 shown. The specific implementation is divided into three steps: First, the system identifies multiple entry points in the Web application, such as controllers, service classes, and REST interfaces, to ensure that the analysis tool can comprehensively cover all entry points of the application; Second, through static analysis technology, the dynamic characteristics of dependency injection in the Spring framework are processed, the dependency relationships are parsed and accurately constructed to optimize the accuracy of the control flow and data flow; Finally, a complete call graph is generated to show the call relationships of each call point, enabling the system to accurately statically infer the dynamic behavior of Spring Web applications.
[0050] Specifically, the method of the present invention has the following steps:
[0051] (1) Collect the annotation rules provided by Spring official, and sort out the annotation rules related to web entry and the annotation rules related to dependency injection;
[0052] The specific process of this step is as follows:
[0053] (1.1) Collect the annotation rules related to web entry in the Spring framework, specifically including the following annotation rules: @Controller, @RestController, @RequestMapping, @GetMapping, @PostMapping, @PutMapping, @DeleteMapping, @PatchMapping;
[0054] (1.2) Collect the annotation rules related to dependency injection in the Spring framework, specifically including the following annotation rules:
[0055] Bean-related rules: @Component, @Service, @Repository, @Controller, @RestController, @Configuration, @Bean;
[0056] Rules related to injection points: @Autowired, @Inject, @Resource, @Qualifier, @Value;
[0057] (2) Load the project to be analyzed through an open-source static analysis tool, and extract the URL paths and the corresponding entry methods according to the annotation rules related to the web entry sorted out in step (1).
[0058] The specific process of this step is as follows:
[0059] (2.1) Use an open-source static analysis tool to load the project to be analyzed, obtain all the application classes in the project, and filter out the classes containing controller annotations according to the annotation rules related to the web entry collected in step (1.1), and mark them as controller classes.
[0060] (2.2) Check each method in the controller classes collected in step (2.1) one by one, and collect all the methods containing any Mapping annotation in the annotation rules related to the web entry collected in step (1.1).
[0061] (2.3) For the entry methods containing Mapping annotations collected in step (2.2), extract their URL path information, establish a mapping relationship between the path and the entry method, and store the result in a mapping table for subsequent use in call graph construction and dependency injection processing.
[0062] (3) Add the entry methods corresponding to the URLs obtained in step (2) as the initial entries of the call graph, and then process the objects for dependency injection according to the annotation rules related to dependency injection sorted out in step (1) to construct a complete call graph.
[0063] The specific process of this step is as follows:
[0064] (3.1) Use an open-source static analysis tool to add the entry methods collected in step (2.2) as the entry methods of the call graph.
[0065] (3.2) According to the annotation rules related to dependency injection collected in step (1.2), analyze each application class. If it contains the relevant rules, add this class to the Bean set.
[0066] (3.3) Process dependency injection points. For the three injection cases of field injection, constructor injection, and Setter method injection, first process according to "name injection", and then process according to "type injection"; for field injection, if the injection point related rules collected in step (1.2) are available on the field, first determine whether the name of the class to be injected is specified by an annotation. If so, find the corresponding class in the Bean set collected in step (3.2) according to the specified name. If there is no @Qualifier, find the corresponding class in the Bean set according to the field name, and add the found result to the variable pointer set;
[0067] The algorithm for processing field injection is shown as follows:
[0068]
[0069] (3.4) For constructor injection and Setter method injection, directly find the corresponding Bean in the Bean set according to the field name;
[0070] The algorithm for processing constructor injection and Setter method injection is shown as follows:
[0071]
[0072]
[0073] (3.5) If steps (3.3) and (3.4) fail to process correctly, find the corresponding class and all its subclasses in the Bean set according to the type, and add the result to the variable pointer set;
[0074] (4) Output the url path and the corresponding entry method in the program, and output the call flow of each entry method respectively.
[0075] The specific process of this step is as follows:
[0076] (4.1) Output the mapping table of the URL path and the corresponding entry method in the program, and clearly record the association relationship between each URL path and its entry method;
[0077] (4.2) Generate a call flow output for the call graph of each entry method, including the direct and indirect call methods of the entry method, and save the call graph structure for subsequent analysis.
[0078] In the evaluation experiment, the open-source WebGoat network security target range open-sourced by Owasp was used for testing, and the call graph obtained by this invention was compared with the call graph obtained by the open-source static analysis tool. There was a significant improvement in the pointing of variables, reachable methods, and call edges statically analyzed. The results are shown in Table 1.
[0079] Table 1 Comparison of WebGoat analysis results without using this system and using this system
[0080]
[0081] The technical means disclosed in the solution of the present invention are not limited to the technical means disclosed in the above embodiments, but also include technical solutions composed of any combination of the above technical features. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present invention, several improvements and refinements can be made, and these improvements and refinements are also regarded as the protection scope of the present invention.
Claims
1. A method for extracting multiple entry points and constructing a call graph for the SpringWeb framework, characterized in that First, identify multiple entry points in the Web application to ensure that the analysis tool comprehensively covers all entry points of the application; second, process the dynamic characteristics of dependency injection in the Spring framework through static analysis techniques, parse and precisely construct the dependency relationships to optimize the accuracy of control flow and data flow; finally, generate a complete call graph to show the call relationships of each call point, enabling the system to accurately perform static inference on the dynamic behavior of the Spring Web application, specifically including the following steps: (1) Collect the annotation rules provided by Spring official, and sort out the annotation rules related to web entry and the annotation rules related to dependency injection; (2) Load the project to be analyzed through an open-source static analysis tool, and extract the url paths and the corresponding entry methods according to the web entry-related annotation rules sorted out in step (1); (3) Add the entry methods corresponding to the url paths obtained in step (2) as the initial entry of the call graph, and then process the dependency injection objects according to the dependency injection-related annotation rules sorted out in step (1) to construct a complete call graph; (4) Output the url paths and the corresponding entry methods in the program, and respectively output the call flows of each entry method.
2. The method for multi-entry point extraction and call graph construction for the SpringWeb framework according to claim 1, characterized in that The specific steps of step (1) include the following sub-steps: (1.1) Collect the annotation rules related to web entry in the Spring framework, specifically including: @Controller, @RestController, @RequestMapping, @GetMapping, @PostMapping, @PutMapping, @DeleteMapping, @PatchMapping; (1.2) Collect the annotation rules related to dependency injection in the Spring framework, specifically including: Bean-related rules: @Component, @Service, @Repository, @Controller, @RestController, @Configuration, @Bean; Injection point-related rules: @Autowired, @Inject, @Resource, @Qualifier, @Value.
3. The method for multi-entry point extraction and call graph construction for the Spring Web framework according to claim 2, characterized in that, The specific steps of step (2) include the following sub-steps: (2.1) Use an open-source static analysis tool to load the project to be analyzed, obtain all application classes in the project, and filter out the classes containing controller annotations according to the web entry-related annotation rules collected in step (1.1), and mark them as controller classes; (2.2) Check each method in the controller classes collected in step (2.1) one by one, and collect all entry methods containing any Mapping annotation in the web entry-related annotation rules collected in step (1.1); (2.3) For the entry methods containing Mapping annotations collected in step (2.2), extract their URL path information, establish a mapping relationship between the path and the entry method, and store the result in a mapping table for subsequent use in call graph construction and dependency injection processing.
4. The method for multi-entry point extraction and call graph construction for the Spring Web framework according to claim 3, wherein (3) The said step (3) includes the following sub-steps: (3.1) Use an open-source static analysis tool to add the entry methods collected in step (2.2) as the entry methods of the call graph; (3.2) According to the annotation rules related to dependency injection collected in step (1.2), analyze each application class. If it contains relevant rules, add this class to the Bean set; (3.3) Process the dependency injection points. For the three injection cases of field injection, constructor injection, and Setter method injection, first process according to "name injection", and then according to "type injection"; for field injection, if the field has the annotation rules related to the injection points collected in step (1.2), first determine whether the name of the class to be injected is specified by the annotation. If so, find the corresponding class in the Bean set collected in step (3.2) according to the specified name. If there is no @Qualifier, find the corresponding class in the Bean set according to the field name, and add the found result to the variable pointer set; (3.4) For constructor injection and Setter method injection, directly find the corresponding Bean in the Bean set according to the field name; (3.5) If steps (3.3) and (3.4) fail to handle correctly, find the corresponding class and all its subclasses in the Bean set according to the type, and add the result to the variable pointer set.
5. The method for multi-entry point extraction and call graph construction for the SpringWeb framework according to claim 4, wherein (3.3) The algorithm steps of the said step (3.3) are as follows: (3.3.1) Extract the variable name and the name of the loaded field from the LoadField statement; (3.3.2) Determine whether the field extracted in step (3.3.1) has the annotation rules related to dependency injection collected in step (1.2); (3.3.3) If it has the annotation rules related to dependency injection collected in step (1.2), first obtain the name specified by the annotation, and then search for the class with this name in the Bean set collected in step (3.2); if the annotation does not specify a name, use the name of the loaded field itself to search for the class with this name in the Bean set collected in step (3.2); (3.3.4) If the result in step (3.3.3) is not empty, use the open-source static analysis framework Tai-e to create an abstract object for this found class and add the abstract object to the pointer set of the variable extracted in step (3.3.1); (3.3.5) If the abstract object is successfully created and added to the pointer set of the variable, mark the variable as "processed state".
6. The method for multi-entry point extraction and call graph construction for Spring Web framework according to claim 4, characterized in that, (3.4) The algorithm steps of the said step (3.4) are as follows: (3.4.1) First extract the variable name and the name of the loaded field from the LoadField statement and make a mapping; (3.4.2) Search for the class with this name in the Bean set collected in step (3.2) directly using the name of the loaded field itself; (3.4.3) If the result in step (3.4.2) is not empty, create an abstract object for the found class using the open-source static analysis framework Tai-e and add the abstract object to the pointer set of the variable extracted in step (3.4.1); (3.4.4) If the abstract object is successfully created and added to the variable pointer set, mark the variable as "processed state"; (3.4.5) For variables not marked as "processed state", search for the corresponding class in the Bean set collected in step (3.2) according to the type of the variable, and add the found class and all its subclasses to the variable pointer set; (3.4.6) For the "this" variable, search for the corresponding class in the Bean set collected in step (3.2) according to the type of the "this" variable, and add the found class to the variable pointer set.
7. The method for multi-entry point extraction and call graph construction for Spring Web framework according to claim 4, characterized in that, (4) The above step specifically includes the following sub-steps: (4.1) Output the mapping table of the URL path and the corresponding entry method in the program, clearly recording the association relationship between each URL path and its entry method; (4.2) Generate call flow output for the call graph of each entry method, including the direct and indirect call methods of the entry method, and save the call graph structure for subsequent analysis.