Software inspection apparatus, software inspection method, and program
The software inspection device identifies call flows across multiple binaries by tracing system call commands, addressing the limitation of existing technologies and enhancing software inspection capabilities.
Patent Information
- Application Number
- JP2023185609
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-10-30
- Publication Date
- 2025-05-14
AI Technical Summary
Existing software inspection technologies fail to identify call flows that span multiple binaries, as they do not consider sub-binaries connected to the main binary.
A software inspection device and method that identifies a binary group including a main binary and its connected sub-binaries, tracing call flows by recognizing system call commands across these binaries.
Enables the identification of call flows spanning multiple binaries, facilitating comprehensive software inspection and detection of potential security vulnerabilities.
Smart Images

Figure 2025074650000001_ABST
Abstract
Description
[Technical field]
[0001] The present disclosure relates to a software inspection device, a software inspection method, and a program. [Background technology]
[0002] Patent Document 1 discloses a technology that performs static analysis on binary code, extracts the functions, system calls, and API calls that are called, as well as the argument values and conditions at the time of the calls, compares the extracted information with the contents of specifications, etc., and detects malicious code based on the comparison results. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] JP 2009-98851 A Summary of the Invention [Problem to be solved by the invention]
[0004] The inventors have noted that the main binary, which is the software to be inspected, has at least one library (which may be called a "sub-binary") that is directly or indirectly loaded and is connected in series with the main binary side being the upstream. Patent Document 1 does not take this into consideration, so there is a possibility that it cannot identify a "call flow" that spans multiple binaries. A "call flow" means a flow that includes multiple functions that have a call relationship.
[0005] An object of the present disclosure is to provide a software inspection device, a software inspection method, and a program capable of identifying a call flow that spans multiple binaries. [Means for solving the problem]
[0006] In one aspect, a software inspection apparatus includes: a binary group identification unit that identifies a binary group including a main binary, which is software to be inspected, and at least one sub-binary that is a target to be loaded directly or indirectly by the main binary and is connected in series with the main binary side being the upstream side; a call flow identification unit that identifies a call flow in the binary group starting from a second function included in the main binary and ending at the first function by sequentially identifying a plurality of functions included in the binary group and having a call relationship, the first function being included in one of the at least one sub-binary and including a predetermined system call command, in the upstream direction; Equipped with:
[0007] In another aspect, a software testing method includes: Identifying a binary group including a main binary, which is software to be inspected, and at least one sub-binary that is a target to be loaded directly or indirectly by the main binary and is connected in series with the main binary as an upstream side; identifying a call flow in the binary group starting from a second function included in the main binary and ending at the first function by sequentially identifying a plurality of functions included in the binary group and having a call relationship therebetween, the first function including a predetermined system call command included in any one of the at least one sub-binary, in the upstream direction; Includes.
[0008] In another aspect, the program further comprises: Identifying a binary group including a main binary, which is software to be inspected, and at least one sub-binary that is a target to be loaded directly or indirectly by the main binary and is connected in series with the main binary as an upstream side; identifying a call flow in the binary group starting from a second function included in the main binary and ending at the first function by sequentially identifying a plurality of functions included in the binary group and having a call relationship therebetween, the first function including a predetermined system call command included in any one of the at least one sub-binary, in the upstream direction; The software inspection device executes a process including the steps: Effect of the Invention
[0009] The present disclosure makes it possible to provide a software inspection device, a software inspection method, and a program capable of identifying a call flow that spans multiple binaries. [Brief description of the drawings]
[0010] [Figure 1] 1 is a block diagram showing an example of a software inspection apparatus according to the present disclosure. [Diagram 2] 4 is a flowchart illustrating an example of a processing operation of the software inspection device of the present disclosure. [Diagram 3] FIG. 13 is a block diagram showing another example of a software inspection apparatus according to the present disclosure. [Figure 4] 13 is a flowchart illustrating an example of a binary group identification process of the software inspection device of the present disclosure. [Diagram 5] 11 is a diagram for explaining an example of a binary group identification process of the software inspection device of the present disclosure. FIG. [Figure 6] FIG. 2 illustrates an example of a binary tree table of the present disclosure. [Figure 7] 13 is a flowchart illustrating an example of a call flow identification process of the software inspection device of the present disclosure. [Figure 8] 10 is a diagram for explaining an example of a call flow identification process of the software inspection device of the present disclosure. FIG. [Figure 9] FIG. 13 is a diagram illustrating an example of a list of system calls to be inspected according to the present disclosure. [Figure 10]FIG. 13 is a block diagram showing another example of a software inspection apparatus according to the present disclosure. [Figure 11] FIG. 1 illustrates an example of the configuration of a software inspection device according to the present disclosure. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0011] Hereinafter, an embodiment will be described with reference to the drawings. In this disclosure, the drawings may relate to one or more embodiments. Also, each element in the drawings may apply to one or more embodiments. In the embodiments, the same or equivalent elements are given the same reference numerals, and duplicated explanations are omitted.
[0012] First Embodiment <Example of software inspection device configuration> Fig. 1 is a block diagram showing an example of a software inspection device according to the present disclosure. In Fig. 1, the software inspection device 10 includes a binary group identification unit 11 and a call flow identification unit 12. The software inspection device 10 receives a "main binary" which is software to be inspected. The software inspection device 10 also receives a "sub-binary group."
[0013] The binary group identification unit 11 executes a "binary group identification process" that identifies one or more "binary groups." Each binary group includes a main binary and at least one "sub-binary" that is a target that the main binary loads directly or indirectly and is connected in series with the main binary on the upstream side. The sub-binary is sometimes called a "library." The main binary is sometimes simply called a "binary." The main binary and the sub-binary individually, or the main binary and the sub-binary collectively, are sometimes called "binaries." "Binary" is data that is expressed in binary numbers so that a computer can process it directly.
[0014] The call flow identification unit 12 executes a "call flow identification process" for identifying a "call flow." For example, the call flow identification unit 12 sequentially identifies a plurality of functions included in a binary group and having a call relationship, starting from a function (hereinafter sometimes referred to as a "first function") including a predetermined system call command included in one of the at least one sub-binary, toward the upstream. This allows the call flow identification unit 12 to identify a call flow in a binary group that starts from a function (hereinafter sometimes referred to as a "second function") included in a main binary and ends at the first function. Here, a system call command is a command for making a system call (i.e., a command for invoking a system call).
[0015] <Example of software inspection device operation> FIG. 2 is a flowchart showing an example of the processing operation of the software checking device of the present disclosure.
[0016] The binary group identification unit 11 executes a "binary group identification process" (step S11).
[0017] The call flow determination unit 12 executes a "call flow determination process" (step S12).
[0018] As described above, according to the first embodiment, the binary group identification unit 11 in the software inspection device 10 identifies a binary group. The binary group includes a main binary and at least one sub-binary that is a target to be loaded directly or indirectly by the main binary and is connected in series with the main binary side being the upstream side. The call flow identification unit 12 sequentially identifies a plurality of functions included in the binary group and having a call relationship, starting from a first function including a predetermined system call command included in any of the at least one sub-binary, toward the upstream side. In this way, the call flow identification unit 12 identifies a call flow in the binary group that starts from a second function included in the main binary and ends at the first function.
[0019] This configuration of the software checking device 10 enables the software checking device 10 to identify a call flow that spans multiple binaries.
[0020] <Second embodiment> <Example of software inspection device configuration> 3 is a block diagram showing another example of the software inspection device of the present disclosure. In FIG. 3, the software inspection device 20 includes a binary group identification unit 21 and a call flow identification unit 22.
[0021] The binary group identification unit 21 executes a binary group identification process in the same manner as the binary group identification unit 11. For example, the binary group identification unit 21 identifies at least one sub-binary by sequentially identifying multiple binaries having a call relationship starting from a main binary. For example, the binary group identification unit 21 may identify a sub-binary called by a main binary based on a "binary name" included in the main binary.
[0022] The call flow identification unit 22 executes a call flow identification process, similar to the call flow identification unit 12. For example, the call flow identification unit 22 includes an identification processing unit (first identification processing unit) 22A and an identification processing unit (second identification processing unit) 22B.
[0023] The identification processing unit 22A identifies a first function including a predetermined system call instruction in the binary group identified by the binary group identification unit 21. For example, the identification processing unit 22A sequentially selects each binary group identified by the binary group identification unit 21 as a "binary group to be identified for processing." Then, the identification processing unit 22A identifies a first function including a predetermined system call instruction in the binary group to be identified for processing.
[0024] The identification processing unit 22B sequentially identifies a plurality of functions having a call relationship in the binary group to be identified, starting from the first function, toward the upstream side. This allows the identification processing unit 22B to identify a call flow in the binary group to be identified, starting from the second function included in the main binary and ending at the first function.
[0025] <Example of software inspection device operation> Another example of the processing operation of the software inspection device of the present disclosure will be described.
[0026] (Binary group specific processing) Fig. 4 is a flowchart illustrating an example of a binary group identification process of the software inspection device of the present disclosure. Fig. 5 is a diagram for explaining an example of a binary group identification process of the software inspection device of the present disclosure.
[0027] The binary group identification unit 21 sets the main binary as a binary to be extracted from the import sub-binary (step S21).
[0028] The binary group identification unit 21 acquires all names of the sub-binaries to be loaded (i.e., library names) from the import information included in the binary from which the import sub-binary names are to be extracted (step S22). For example, in the example shown in Fig. 5, three sub-binary names (i.e., import sub-binary names), "libA (library A)", "libB (library B)", and "libC (library C)", are extracted from the main binary.
[0029] The binary group identification unit 21 associates the name of the binary set in the binary to be extracted (here, "main binary") with the acquired import sub-binary name (i.e., "libA", "libB", "libC") and stores them in a binary tree table (step S23). FIG. 6 is a diagram showing an example of a binary tree table of the present disclosure. Note that, when a sub-binary corresponding to the acquired import sub-binary name is included in the "sub-binary group", the binary group identification unit 21 may store the import sub-binary name in the binary tree table.
[0030] The binary group identification unit 21 sets the sub-binary corresponding to the acquired import sub-binary name as a candidate binary to be extracted for the import sub-binary name (step S24).
[0031] The binary group identification unit 21 sets one of the candidates for the binary to be extracted as the binary to be extracted for the import sub-binary name (step S25).
[0032] The binary group identification unit 21 searches for the name of the sub-binary to be loaded based on the import information in the binary from which the import sub-binary name is to be extracted (step S26).
[0033] If the name of the sub-binary to be loaded is found (YES in step S27), the processing returns to step S22. For example, the binary group identification unit 21 first sets the sub-binary A corresponding to libA as the binary to be extracted. Then, the binary group identification unit 21 extracts the name of the sub-binary to be loaded from the import information included in the sub-binary A. Here, the sub-binary name "libC (library C)" is extracted from the sub-binary A.
[0034] If the name of the sub-binary to be loaded is not found (step S27 NO), the binary group identification unit 21 associates the name of the binary set in the binary to be extracted with "None" as the value of the item "Import sub-binary name" and stores this in the binary tree table (step S28).
[0035] The binary group identification unit 21 determines whether there is an extraction target binary candidate that has not yet been set as an extraction target binary (step S29).
[0036] If there is an extraction target binary candidate that has not yet been set in the extraction target binary (step S29 YES), the processing returns to step S25. If there is no extraction target binary candidate that has not yet been set in the extraction target binary (step S29 NO), the flow in Fig. 4 ends. In this way, the binary group identification unit 21 can identify binary groups by creating a binary tree table.
[0037] 5 and 6, four binary groups are identified: binary groups 1 to 4. For example, binary group #1 is "main binary-libA-libC-libF", binary group #2 is "main binary-libB-libD-libE", binary group #3 is "main binary-libB-libE", and binary group #4 is "main binary-libC-libF".
[0038] (Call flow specific processing) Fig. 7 is a flowchart illustrating an example of a call flow specification process of the software inspection device of the present disclosure. Fig. 8 is a diagram for explaining an example of a call flow specification process of the software inspection device of the present disclosure.
[0039] The call flow identification unit 22 sequentially sets each binary group identified in the binary group identification process as a "target binary group for the call flow identification process" and executes the process flow shown in Fig. 7. Here, an example will be described in which binary group #2 is set as the target binary group.
[0040] The call flow identification unit 22 identifies a function including a predetermined system call instruction in a target binary group of the call flow identification process (step S41). Here, the "predetermined system call instruction" is a system call instruction in which the value of the first argument of the system call instruction is the same as the value of the system call number included in the inspection target system call list. FIG. 9 is a diagram showing an example of the inspection target system call list. For example, when binary group #2 is set as the target binary group, the call flow identification unit 22 identifies a function including a predetermined system call instruction (syscall 1) in the sub-binary libE as shown in FIG. 8.
[0041] Here, in order to realize a security-sensitive processing operation, it is necessary to finally execute a system call. Therefore, by identifying a function that includes a predetermined system call instruction, it is possible to identify a function that may be involved in a security-sensitive processing operation. It is also possible to identify such functions by listing functions that may be involved in a security-sensitive processing operation. However, there are fewer system call instructions compared to library functions, and the frequency with which their operations are changed or added is low, and they are also low in frequency with which they are deleted. Therefore, system call instructions can be listed more easily than functions.
[0042] Returning to the explanation of FIG. 7, the call flow identification unit 22 sets the binary including the function identified in step S41 (here, the sub-binary libE) as the "target binary for the call flow identification process" (step S42).
[0043] The call flow identification unit 22 associates one or more functions identified in step S41 with the addresses of each function and stores them in a "called function list" (step S43). The "called function list" is a list of functions that call a system call in the "target binary of the call flow identification process (here, the sub-binary libE)".
[0044] The call flow identification unit 22 identifies "partial call flows" including functions having a call relationship with each function held in the called function list as a starting point in the target binary of the call flow identification process (step S44). Here, the last function identified in each partial call flow is called the "function of interest." In the example of FIG. 8, the function "lib_func_1" is the function of interest.
[0045] The call flow identification unit 22 determines whether or not there is a binary located upstream of the current "target binary of call flow identification process" in the "target binary group of call flow identification process" (step S45). If the sub-binary libE is set as the "target binary of call flow identification process", then since the sub-binary libD exists upstream of the sub-binary libE, it is determined in step S45 that there is a binary located upstream.
[0046] If it is determined that an upstream binary exists (YES in step S45), the call flow identification unit 22 identifies a partial call flow including a function of interest called by a function included in the upstream binary (step S46).
[0047] The call flow identification unit 22 stores the partial call flow identified in step S46 in a "call flow function list" (step S47). That is, the call flow identification unit 22 stores each function included in the partial call flow in association with the address of the function in the call flow function list.
[0048] The call flow identification unit 22 sets the binary determined to exist upstream in step S45 as a new "target binary for call flow identification processing" (step S48). Here, the sub-binary libD is set as the new "target binary for call flow identification processing".
[0049] The call flow identification unit 22 identifies a "partial call flow" that includes functions having a call relationship with the function that reads the function of interest in the partial call flow identified in step S46 (function "lib_func_D" in the example of FIG. 8) as the starting point in the "target binary for call flow identification processing" (step S49). Here, the last function identified in the partial call flow is called the "function of interest." Then, the processing flow returns to step S45.
[0050] If it is determined that there is no binary located upstream (step S45 NO), the call flow identification unit 22 stores the partial call flow identified in step S44 or step S49 in the "call flow function list" (step S50). Then, the processing flow of FIG. 7 ends. In this manner, the call flow identification unit 22 can identify a call flow by creating a call flow function list. Also, by executing the processing shown in FIG. 7 for each binary group, it is possible to identify a call flow corresponding to each binary group.
[0051] <Third embodiment> The third embodiment relates to a process flow analysis, which is applied to the call flow described above.
[0052] Fig. 10 is a block diagram showing another example of the software inspection device of the present disclosure. In Fig. 10, the software inspection device 30 has a binary group identification unit 31, a call flow identification unit 32, and a process flow analysis unit 33. The binary group identification unit 31 and the call flow identification unit 32 may have the same functions as the binary group identification unit 11 and the call flow identification unit 12, or the binary group identification unit 21 and the call flow identification unit 22.
[0053] The process flow analysis unit 33 executes a "process flow analysis" for each call flow identified by the call flow identification unit 32. For example, the process flow analysis unit 33 receives a "call flow function list" corresponding to each call flow from the call flow identification unit 32. Then, the process flow analysis unit 33 uses the call flow function list to perform data flow analysis and control flow analysis to identify conditional branches in the call flow that are likely to trigger a backdoor. Then, the process flow analysis unit 33 outputs an inspection result including information on the identified conditional branches, etc.
[0054] <Other embodiments> <1> The software inspection devices 10, 20, and 30 described in the first to third embodiments can also be realized by hardware (circuits). That is, any combination of one or more functional units among the multiple functional units of the software inspection devices 10, 20, and 30 described in the first to third embodiments may be realized by one or more circuits.
[0055] <2> The software inspection devices 10, 20, and 30 described in the first to third embodiments can be realized by causing a processor to execute a program. That is, the software inspection devices 10, 20, and 30 described in the first to third embodiments can be realized by software.
[0056] FIG. 11 is a diagram showing a configuration example of a software inspection device according to the present disclosure. In FIG. 11, the software inspection device 100 has a processor 101 and a memory 102. The processor 101 may be, for example, a microprocessor, a micro processing unit (MPU), or a central processing unit (CPU). The processor 101 may include a plurality of processors. The memory 102 is configured by a combination of a volatile memory and a non-volatile memory. The memory 102 may include a storage device located away from the processor 101. In this case, the processor 101 may access the memory 102 via an I (Input) / O (Output) interface not shown.
[0057] The software inspection devices 10, 20, and 30 described in the first to third embodiments may each have the configuration shown in FIG. 11. The binary group identification units 11, 21, and 31, the call flow identification units 12, 22, and 32, and the process flow analysis unit 33 of the software inspection devices 10, 20, and 30 described in the first to third embodiments may be realized by the processor 101 reading and executing a program stored in the memory 102. The program can be stored using various types of non-transitory computer readable media and supplied to the software inspection devices 10, 20, and 30. Examples of the non-transitory computer readable media include magnetic recording media (e.g., flexible disks, magnetic tapes, and hard disk drives) and magneto-optical recording media (e.g., magneto-optical disks). Further, examples of the non-transitory computer readable media include CD-ROMs (Read Only Memory), CD-Rs, and CD-R / Ws. Further, examples of the non-transitory computer readable media include semiconductor memories. The semiconductor memory includes, for example, a mask ROM, a programmable ROM (PROM), an erasable PROM (EPROM), a flash ROM, and a random access memory (RAM). The program may also be provided to the software inspection apparatuses 10, 20, and 30 by various types of transitory computer readable media. Examples of the transitory computer readable media include an electric signal, an optical signal, and an electromagnetic wave. The transitory computer readable medium can provide the program to the software inspection apparatuses 10, 20, and 30 via a wired communication path such as an electric wire and an optical fiber, or a wireless communication path.
[0058] Although the present disclosure has been described above with reference to the embodiments, the present disclosure is not limited to the above-described embodiments. The present disclosure is not intended to be limiting. Various modifications that can be understood by a person skilled in the art may be made to the configuration and details of the present disclosure within the scope of the present disclosure. Furthermore, each embodiment may be appropriately combined with other embodiments.
[0059] A part or all of the above-described embodiments can be described as, but is not limited to, the following supplementary notes. (Appendix 1) a binary group identification unit that identifies a binary group including a main binary, which is software to be inspected, and at least one sub-binary that is a target to be loaded directly or indirectly by the main binary and is connected in series with the main binary side being the upstream side; a call flow identification unit that identifies a call flow in the binary group starting from a second function included in the main binary and ending at the first function by sequentially identifying a plurality of functions included in the binary group and having a call relationship, starting from a first function including a predetermined system call command included in any one of the at least one sub-binary, in the upstream direction; A software inspection device comprising: (Appendix 2) the binary group identification unit identifies the at least one sub-binary by sequentially identifying a plurality of binaries having a call relationship starting from the main binary; 2. The software inspection apparatus of claim 1. (Appendix 3) the binary group identification unit identifies a sub-binary called by the main binary based on a binary name included in the main binary; 3. The software inspection apparatus according to claim 2. (Appendix 4) The call flow identification unit, a first identification processing unit that identifies a first function including the predetermined system call instruction in the binary group; a second identification processing unit that identifies a call flow in the binary group, the call flow starting from a second function included in the main binary and ending at the first function, by sequentially identifying a plurality of functions having the call relationship from the first function toward the upstream side; Equipped with 2. The software inspection apparatus according to claim 1. (Appendix 5) a flow analysis unit that performs data flow analysis and control flow analysis on the identified call flow; 5. The software inspection apparatus according to claim 1 , (Appendix 6) Identifying a binary group including a main binary, which is software to be inspected, and at least one sub-binary that is a target to be loaded directly or indirectly by the main binary and is connected in series with the main binary as an upstream side; identifying a call flow in the binary group starting from a second function included in the main binary and ending at the first function by sequentially identifying a plurality of functions included in the binary group and having a call relationship therebetween, the first function including a predetermined system call command included in any one of the at least one sub-binary, in the upstream direction; A software inspection method including: (Appendix 7) The identifying the binary group includes identifying the at least one sub-binary by sequentially identifying a plurality of binaries having a call relationship starting from the main binary. 6. The software inspection method according to claim 6. (Appendix 8) identifying the binary group includes identifying a sub-binary called by the main binary based on a binary name included in the main binary; 7. The software inspection method according to claim 7. (Appendix 9) Identifying the call flow includes: identifying a first function in the binary group that includes the predetermined system call instruction; identifying a call flow in the binary group starting from a second function included in the main binary and ending at the first function by sequentially identifying a plurality of functions having the call relationship in the upstream direction starting from the first function; Including, 6. A software inspection method as described in appendix 6. (Appendix 10) performing a data flow analysis process and a control flow analysis process on the identified call flows. 10. The software inspection method according to any one of claims 6 to 9. (Appendix 11) Identifying a binary group including a main binary, which is software to be inspected, and at least one sub-binary that is a target to be loaded directly or indirectly by the main binary and is connected in series with the main binary as an upstream side; identifying a call flow in the binary group starting from a second function included in the main binary and ending at the first function by sequentially identifying a plurality of functions included in the binary group and having a call relationship therebetween, the first function including a predetermined system call command included in any one of the at least one sub-binary, in the upstream direction; A program for causing a software inspection device to execute a process including the steps of: (Appendix 12) The identifying the binary group includes identifying the at least one sub-binary by sequentially identifying a plurality of binaries having a call relationship starting from the main binary. 12. The program according to claim 11. (Appendix 13) identifying the binary group includes identifying a sub-binary called by the main binary based on a binary name included in the main binary; 13. The program according to claim 12. (Appendix 14) Identifying the call flow includes: identifying a first function in the binary group that includes the predetermined system call instruction; identifying a call flow in the binary group starting from a second function included in the main binary and ending at the first function by sequentially identifying a plurality of functions having the call relationship in the upstream direction starting from the first function; Including, 12. The program according to claim 11. (Appendix 15) the process further includes performing a data flow analysis process and a control flow analysis process on the identified call flows. 15. The program according to any one of appendices 11 to 14. [Explanation of symbols]
[0060] 10 Software testing equipment 11 Binary group identification part 12 Call flow specification 20 Software Inspection Equipment 21 Binary group identification part 22 Call flow specification part 22A Specific Processing Unit (First Specific Processing Unit) 22B Specific Processing Unit (Second Specific Processing Unit) 30 Software Inspection Equipment 31 Binary Group Identifier 32 Call flow specification part 33 Processing flow analysis unit
Claims
1. a binary group identification unit that identifies a binary group including a main binary that is software to be inspected and at least one sub-binary that is a target to be loaded directly or indirectly by the main binary and is connected in series with the main binary side being the upstream side; a call flow identification unit that identifies a call flow in the binary group starting from a second function included in the main binary and ending at the first function by sequentially identifying a plurality of functions included in the binary group and having a call relationship, starting from a first function including a predetermined system call command included in any one of the at least one sub-binary, in the upstream direction; A software inspection device comprising:
2. the binary group identification unit identifies the at least one sub-binary by sequentially identifying a plurality of binaries having a call relationship starting from the main binary; 2. The software inspection apparatus according to claim 1.
3. the binary group identification unit identifies a sub-binary called by the main binary based on a binary name included in the main binary; 3. The software inspection apparatus according to claim 2.
4. The call flow identification unit, a first identification processing unit that identifies a first function including the predetermined system call instruction in the binary group; a second identification processing unit that identifies a call flow in the binary group, the call flow starting from a second function included in the main binary and ending at the first function, by sequentially identifying a plurality of functions having the call relationship from the first function toward the upstream side; Equipped with 2. The software inspection apparatus according to claim 1.
5. a flow analysis unit that performs data flow analysis and control flow analysis on the identified call flow; 5. The software inspection device according to claim 1.
6. Identifying a binary group including a main binary, which is software to be inspected, and at least one sub-binary that is a target to be loaded directly or indirectly by the main binary and is connected in series with the main binary as an upstream side; Identifying a call flow in the binary group starting from a second function included in the main binary and ending at the first function by sequentially identifying a plurality of functions included in the binary group and having a call relationship therebetween, starting from a first function including a predetermined system call instruction included in any one of the at least one sub-binary, toward the upstream side; A software inspection method including:
7. and identifying the binary group includes identifying the at least one sub-binary by sequentially identifying a plurality of binaries having a call relationship starting from the main binary.
7. The method of claim 6.
8. and identifying the binary group includes identifying a sub-binary called by the main binary based on a binary name included in the main binary.
8. The method of claim 7.
9. Identifying the call flow includes: identifying a first function in the binary group that includes the predetermined system call instruction; identifying a call flow in the binary group starting from a second function included in the main binary and ending at the first function by sequentially identifying a plurality of functions having the call relationship in the upstream direction starting from the first function; Including, 7. The method of claim 6.
10. performing a data flow analysis process and a control flow analysis process on the identified call flows. The software inspection method according to any one of claims 6 to 9.
11. Identifying a binary group including a main binary, which is software to be inspected, and at least one sub-binary that is a target to be loaded directly or indirectly by the main binary and is connected in series with the main binary as an upstream side; Identifying a call flow in the binary group starting from a second function included in the main binary and ending at the first function by sequentially identifying a plurality of functions included in the binary group and having a call relationship therebetween, starting from a first function including a predetermined system call instruction included in any one of the at least one sub-binary, toward the upstream side; A program for causing a software inspection device to execute a process including the steps of:
12. and identifying the binary group includes identifying the at least one sub-binary by sequentially identifying a plurality of binaries having a call relationship starting from the main binary. The program according to claim 11.
13. and identifying the binary group includes identifying a sub-binary called by the main binary based on a binary name included in the main binary. The program according to claim 12.
14. Identifying the call flow includes: identifying a first function in the binary group that includes the predetermined system call instruction; identifying a call flow in the binary group starting from a second function included in the main binary and ending at the first function by sequentially identifying a plurality of functions having the call relationship in the upstream direction starting from the first function; Including, The program according to claim 11.
15. the process further includes performing a data flow analysis process and a control flow analysis process on the identified call flows. The program according to any one of claims 11 to 14.
Citation Information
Patent Citations
System for detecting invalid code
JP2009098851A