Estimation device, estimation method, and estimation program
The estimation device efficiently identifies the software associated with binary data by analyzing surface layer information and referencing relevant software information, addressing inefficiencies and security constraints in existing methods.
Patent Information
- Application Number
- PCT/JP2023/041801
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-11-21
- Publication Date
- 2025-05-30
AI Technical Summary
Existing techniques for identifying the software associated with binary data are inefficient due to the large amount of data that needs to be compared, and they may not function properly when the main body of the binary file cannot be obtained for security reasons.
An estimation device and method that acquire and analyze surface layer information from binary files, such as file names, character strings, and execution logs, to estimate the software associated with the binary data by referencing source code information, package information, and command line manual information.
Enables efficient estimation of the software associated with binary data without the need for extensive data comparison, even when the main binary file cannot be accessed, thus improving processing speed and security compliance.
Smart Images

Figure JP2023041801_30052025_PF_FP_ABST
Abstract
Description
Estimation device, estimation method, and estimation program
[0001] The present invention relates to an estimation device, an estimation method, and an estimation program for estimating target software of binary data.
[0002] In conventional technology, binary files, which are the executable form of software, are written in machine code that is difficult for humans to understand, making it difficult to verify their contents. Therefore, in order to identify what software a binary file relates to, there is a technology that prepares an index and identifies what software a binary file relates to by its similarity to the index.
[0003] For example, there is a technology that extracts features from a binary whose software name and version are known, and then extracts similar features from the binary being inspected. If the extracted features match or are similar, the software name and version of the binary being inspected can be estimated as the software name and version in question.
[0004] Saed Alrabaee, Mourad Debbabi, Lingyu Wang, “A Survey of Binary Code Fingerprinting Approaches: Taxonomy, Methodologies, and Features,” 2022
[0005] However, the above techniques require a lot of processing time due to the large amount of binary data to be compared. In addition, due to software security reasons, the binary file itself may not be available.
[0006] Therefore, the present invention solves the above-mentioned problem and makes it possible to easily guess what software the binary data relates to.
[0007] In order to solve the above-mentioned problems, the present invention is characterized by comprising an information acquisition unit that acquires at least one of a file name, a character string, and an execution log contained in the readable portion of a binary file, and an estimation unit that identifies software having at least one of the file name, character string, and execution log based on source code information, package information, and command line manual information for each piece of software, and estimates and outputs the identified software as the target software of the binary file.
[0008] According to the present invention, it is possible to easily infer what software the binary data relates to.
[0009] FIG. 1 is a diagram for explaining an overview of an estimation device. FIG. 2 is a diagram showing an example of the configuration of a system including the estimation device. FIG. 3 is a diagram showing an example of the binary information DB of FIG. 2. FIG. 4 is a diagram showing an example of the binary information DB to which estimation results of target software have been added. FIG. 5 is a flowchart showing an example of a processing procedure executed by the estimation device. FIG. 6 is a diagram for explaining an example of processing executed by a first estimation unit. FIG. 7 is a diagram for explaining an example of processing executed by a second estimation unit. FIG. 8 is a diagram for explaining an example of processing executed by a third estimation unit. FIG. 9 is a diagram showing a computer that executes an estimation program.
[0010] DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS Hereinafter, a description will be given of an embodiment of the present invention with reference to the drawings, but the present invention is not limited to the embodiment.
[0011] First, an overview of an estimation device 10 according to the present embodiment will be described with reference to Fig. 1. The estimation device 10 estimates to which software the binary data in a binary file relates, based on readable information contained in the binary file (e.g., a file name, a character string, an execution log of the binary file, etc.; hereinafter, referred to as surface information, where appropriate).
[0012] For example, the estimation device 10 estimates the software name, source code information, description, etc. (see symbol 102) of the binary data of the binary file based on the surface information 101 of the binary file, by referring to source code information, package software information (package information), command line manual information, etc. (command manual information) that can be obtained via a network.
[0013] [Configuration Example] Next, a configuration example of a system 1 including an estimation device 10 will be described with reference to Fig. 2. The system 1 includes a server that stores package information, a server that stores command manual information, a server (repository) that stores source code information, a terminal device, the estimation device 10, etc. These servers and devices are connected to each other so as to be able to communicate with each other via a network such as the Internet.
[0014] The package information is information showing various information about each package software. The command manual information is information showing the command line manual for each software. The source code information is information showing the source code for each software.
[0015] The terminal device is a device that registers binary information (details of which will be described later) of a binary file, requests reference to the estimation result of the target software of the binary file, etc. to the estimation device 10. The estimation device 10 estimates the target software of the binary file from the surface information of the binary file.
[0016] The estimation device 10 includes, for example, an input / output unit 11, a communication unit 12, a storage unit 13, and a control unit 14.
[0017] The input / output unit 11 is an interface that controls the input and output of various data. The communication unit 12 is a communication interface for performing data communication with external devices. For example, the communication unit 12 accesses a server that stores source code information, a server that stores package software information, and a server that stores command manual information via a network to acquire various types of information.
[0018] The storage unit 13 stores data, programs, etc. that are referenced when the control unit 14 executes various processes. The storage unit 13 is realized by a semiconductor memory element such as a random access memory (RAM) or a flash memory, or a storage device such as a hard disk or an optical disk.
[0019] The storage unit 13 includes, for example, a binary information database (DB) that stores binary information, which is information about binary files.
[0020] For example, as shown in Figure 3, the binary information is information that indicates, for each binary file to be estimated, the ID of the binary file, the hash value, information obtained from the readable part of the binary file (file name, string, execution log), etc.
[0021] 3, this binary information may include the registrant of the binary information, the reference conditions of the binary information, etc. This binary information is registered in the binary information DB by the control unit 14. Note that, among the binary information, the file name of the binary file, character string, execution log, etc. may be automatically obtained from the readable portion of the binary file by the control unit 14 and registered, or may be manually registered by the registrant of the binary information.
[0022] Returning to the description of Fig. 2, the control unit 14 controls the entire estimation device 10. The functions of the control unit 14 are realized, for example, by a CPU (Central Processing Unit) executing a program stored in the storage unit 13.
[0023] The control unit 14 includes a binary information registration unit (acquisition unit) 141, an estimation unit 142, and a reference unit 146. The binary information registration unit 141 registers binary information in a binary information DB based on a request from a registrant. For example, the binary information registration unit 141 acquires at least one of a file name, a character string, and an execution log contained in the readable portion of a binary file. The binary information registration unit 141 then registers binary information indicating the acquired information in the binary information DB.
[0024] The estimation unit 142 estimates the target software of a binary file based on at least one of the file name, character string, and execution log indicated in the binary information in the binary information DB (see FIG. 3). To estimate the target software of a binary file, the estimation unit 142 refers to, for example, the package information, command manual information, source code information, etc. Then, the estimation unit 142 adds information about the estimated target software (estimation result) to the binary information in the binary information DB.
[0025] 4, the estimation unit 142 adds information about the estimated target software (see reference numeral 401) to the binary information. For example, the estimation unit 142 adds information that the name of the target software for the binary file with binary file ID "1" is "aaa." The estimation result may include the repository URL of the target software, as shown by reference numeral 401.
[0026] Returning to the description of Fig. 2, the estimation unit 142 includes a first estimation unit 143, a second estimation unit 144, and a third estimation unit 145.
[0027] If the binary information (see FIG. 3) received by the binary information registration unit 141 includes a file name, the first estimation unit 143 estimates the target software of the binary file based on the file name.
[0028] If the binary information (see FIG. 3) received by the binary information registration unit 141 contains a character string, the second estimation unit 144 estimates the target software of the binary file based on the character string.
[0029] The third estimation unit 145 estimates the target software of the binary file based on the execution log when the execution log is included in the binary information (see FIG. 3 ) received by the binary information registration unit 141. Details of the first estimation unit 143, the second estimation unit 144, and the third estimation unit 145 will be described later using specific examples.
[0030] The reference unit 146 refers to the estimation result of the target software of the binary file in response to a request from the user of the estimation device 10. For example, when the reference unit 146 receives a reference request from the user's terminal device via the network, it outputs binary information including the estimation result of the target software from the binary information DB (see FIG. 4 ). This allows the user to know what software the binary file relates to.
[0031] If the binary information includes a reference condition, the reference unit 146 allows the binary information to be referenced in accordance with the reference condition of the binary information. For example, the reference unit 146 allows only the terminal device of the registrant of the binary information or a user approved by the registrant to reference the binary information.
[0032] [Example of Processing Procedure] Next, an example of processing procedure executed by the estimation device 10 will be described with reference to Fig. 5. First, the binary information registration unit 141 registers binary information in the binary information DB (S1).
[0033] Next, the estimation unit 142 estimates the target software of the binary file based on the binary information in the binary information DB. For example, if the binary information in the binary information DB includes a file name (for example, the file name "aaa" of the binary information shown in FIG. 3), the first estimation unit 143 estimates the target software based on the file name (S2).
[0034] Furthermore, if the binary information contains character string information (character string), the second estimation unit 144 estimates the target software based on the character string (S3). For example, if the binary information in the binary information DB contains a character string (for example, the character string "Usage: aaa[option]" in the binary information shown in FIG. 3), the second estimation unit 144 estimates the target software based on the character string.
[0035] Furthermore, if the binary information includes execution log information (execution log), the third estimation unit 145 estimates the target software based on the execution log (S4). For example, if the binary information in the binary information DB includes an execution log (for example, the execution log of the binary information shown in FIG. 3 is "error no. 1234: command not found"), the third estimation unit 145 estimates the target software based on the execution log.
[0036] Then, the estimation unit 142 stores the estimation result of the target software in the binary information DB (S5).
[0037] Next, the first estimating unit 143, the second estimating unit 144, and the third estimating unit 145 will be described in detail using a specific example.
[0038] [First Estimation Unit] The first estimation unit 143 estimates the target software based on the file name (e.g., "aaa") indicated in the binary information, for example, according to the procedure shown in Fig. 6. The first estimation unit 143 then stores the estimation result of the target software in the binary information DB (see Fig. 4). Note that, hereinafter, the file name indicated in the binary information will be referred to as the binary file name, where appropriate.
[0039] First, if there is a file name that matches the binary file name ("aaa") in the file list of the package information obtained from the server that stores the package information, the first estimation unit 143 estimates that the software is the target software (S11).
[0040] For example, as indicated by the reference numeral 601, the first estimation unit 143 estimates that "AAA (package name)" is the target software from the package information " / usr / bin / aaa".
[0041] Furthermore, if the command manual information obtained from the server that stores the command manual information contains a command name that matches the binary file name ("aaa"), the first estimation unit 143 estimates that the software that uses that command name is the target software (S12).
[0042] For example, as shown by the symbol 602, when the first estimation unit 143 finds a command name in the command manual information ("aaa", "bbb") that matches the binary file name ("aaa"), it estimates that the software that uses that command is the target software.
[0043] In addition, the first estimation unit 143 accesses a server that stores source code information, searches for build information (e.g., Makefile, etc.) from the source code information using a code search engine, and if a generated file name in the build information matches the binary file name ("aaa"), it estimates that the software that generates the file with that file name is the target software (S13).
[0044] For example, the first estimation unit 143 searches for build information from source code information using the search query indicated by the symbol 603, and if there is a file name in the generated file name in the build information that matches the binary file name ("aaa"), it estimates that the software that generates the file with that file name is the target software.
[0045] The first estimation unit 143 also searches for binary file names and extensions from the source code information using a code search engine, and estimates the most famous software hit as the target software (S14).
[0046] For example, the first estimation unit 143 searches for the binary file name ("aaa") + extension ("lang:C" or ".c") from the source code information using the search query shown by the reference symbol 604, and estimates that the most famous software hit is the target software.
[0047] If there are multiple candidates that match in S13 and S14 above, the first estimation unit 143 selects, for example, the candidate that is most famous in the source code information, the candidate that is most frequently used, or the candidate related to the oldest project.
[0048] [Second Estimation Unit] The second estimation unit 144 estimates the target software based on a character string (e.g., "Usage: aaa[option]") indicated in the binary information, for example, according to the procedure shown in Fig. 7. Then, the second estimation unit 144 stores the estimation result of the target software in the binary information DB.
[0049] First, the second estimation unit 144 accesses a server that stores source code information, searches the source code information using a search engine for a string ("aaa") indicated in the binary information, and if it matches the function name in the software's source code (for example, if it finds "func_aaa"), it estimates that the software is the target software (S21).
[0050] For example, when the second estimation unit 144 finds source code including "func_aaa" from the source code information using the search query for reference numeral 701, it estimates that the software of the source code is the target software.
[0051] If there are multiple matched candidates in S21, the second estimation unit 144 selects, for example, the most famous candidate in the source code information, the candidate with the most usages, or the candidate related to the oldest project. In this case, if a candidate includes a common function name, the second estimation unit 144 excludes that candidate.
[0052] In addition, the second estimation unit 144 accesses a server that stores source code information, searches for a string ("Usage: aaa [option]") in the source code information using a search engine, and if the string matches an expression that is recognized as a string in the source code of the software, it estimates that the software is the target software (S22).
[0053] For example, if the second estimation unit 144 finds source code from the source code information using the search query indicated by the reference numeral 702 that includes an expression that recognizes "Usage: aaa[option]" as a string (e.g., "printf("Usage: aaa[option]...")"), it estimates that the software of the source code is the target software.
[0054] If there are multiple hit candidates in S22, the second estimation unit 144 may select the most famous candidate in the source code information, the candidate with the most usages, or the candidate related to the oldest project. In this case, if a candidate includes a common character string, the second estimation unit 144 excludes that candidate.
[0055] [Third Estimation Unit] The third estimation unit 145 estimates the target software based on the execution log (e.g., “error no. 1234: command not found”) indicated in the binary information, for example, by the procedure shown in Fig. 8. Then, the third estimation unit 145 stores the estimation result of the target software in the binary information DB.
[0056] For example, the third estimation unit 145 first accesses a server that stores source code information, normalizes the execution log ("error no. 1234: command not found") shown in the binary information (converting numbers to *), and searches the source code information using a search engine. If the search results in a match with the output string of the software's source code, the third estimation unit 145 estimates that the software is the target software (S31).
[0057] For example, as shown in symbol 801, the third estimation unit 145 searches for source code information using a search query "error no *: command not found", which is obtained by converting the numeric part of the execution log "error no 1234: command not found" shown in the binary information to *.
[0058] As a result of the search, if the third estimation unit 145 finds a string that matches "'error no *: command not found'" in the output string of the software's source code from the source code information, it estimates that the software is the target software. For example, if the third estimation unit 145 finds the source code "printf('error no %s: command not found', errno)" from the source code information, it estimates that the software is the target software.
[0059] In addition, if there are multiple candidates that match in S31, the third estimation unit 145 may select the candidate that is most famous in the source code information, the candidate that is most frequently used, or the candidate related to the oldest project. In this case, if the candidate includes a common function name, the third estimation unit 145 excludes that candidate.
[0060] According to the estimation device 10 described above, it is possible to estimate what software the binary data of a binary file relates to, based on the information contained in the readable portion of the binary file.
[0061] [System Configuration, etc.] The components of each unit shown in the figure are conceptual functional units and do not necessarily have to be physically configured as shown. In other words, the specific form of distribution and integration of each device is not limited to that shown, and all or part of them can be functionally or physically distributed and integrated in any unit depending on various loads, usage conditions, etc. Furthermore, all or any part of the processing functions performed by each device can be realized by a CPU and a program executed by the CPU, or can be realized as hardware using wired logic.
[0062] Furthermore, among the processes described in the above embodiments, all or part of the processes described as being performed automatically can be performed manually, or all or part of the processes described as being performed manually can be performed automatically using a known method.In addition, the information including the processing procedures, control procedures, specific names, various data and parameters shown in the above documents and drawings can be changed as desired unless otherwise specified.
[0063] [Program] The above-described estimation device 10 can be implemented by installing a program (estimation program) as package software or online software on a desired computer. For example, by executing the above-described program on an information processing device, the information processing device can function as the estimation device 10. The information processing device referred to here includes mobile communication terminals such as smartphones, mobile phones, and PHS (Personal Handyphone Systems), as well as terminals such as PDAs (Personal Digital Assistants).
[0064] 9 is a diagram showing an example of a computer that executes an estimation program. The computer 1000 includes, for example, a memory 1010 and a CPU 1020. The computer 1000 also includes a hard disk drive interface 1030, a disk drive interface 1040, a serial port interface 1050, a video adapter 1060, and a network interface 1070. These components are connected by a bus 1080.
[0065] The memory 1010 includes a read-only memory (ROM) 1011 and a random access memory (RAM) 1012. The ROM 1011 stores a boot program such as a basic input / output system (BIOS). The hard disk drive interface 1030 is connected to a hard disk drive 1090. The disk drive interface 1040 is connected to a disk drive 1100. A removable storage medium such as a magnetic disk or optical disk is inserted into the disk drive 1100. The serial port interface 1050 is connected to a mouse 1110 and a keyboard 1120, for example. The video adapter 1060 is connected to a display 1130, for example.
[0066] The hard disk drive 1090 stores, for example, an OS 1091, an application program 1092, a program module 1093, and program data 1094. That is, the programs that define the processes executed by the above-described estimation device 10 are implemented as program modules 1093 in which computer-executable code is written. The program modules 1093 are stored, for example, in the hard disk drive 1090. For example, the program modules 1093 for executing processes similar to those of the functional configuration of the estimation device 10 are stored in the hard disk drive 1090. Note that the hard disk drive 1090 may be replaced with an SSD (Solid State Drive).
[0067] Data used in the processing of the above-described embodiment is stored as program data 1094, for example, in the memory 1010 or the hard disk drive 1090. The CPU 1020 then reads the program module 1093 or the program data 1094 stored in the memory 1010 or the hard disk drive 1090 into the RAM 1012 as necessary and executes them.
[0068] The program module 1093 and program data 1094 may not necessarily be stored in the hard disk drive 1090, but may also be stored in a removable storage medium and read by the CPU 1020 via the disk drive 1100 or the like. Alternatively, the program module 1093 and program data 1094 may be stored in another computer connected via a network (such as a local area network (LAN) or a wide area network (WAN)). The program module 1093 and program data 1094 may then be read by the CPU 1020 from the other computer via the network interface 1070.
[0069] REFERENCE SIGNS LIST 10 Estimation device 11 Input / output unit 12 Communication unit 13 Storage unit 14 Control unit 141 Binary information registration unit 142 Estimation unit 143 First estimation unit 144 Second estimation unit 145 Third estimation unit 146 Reference unit
Claims
1. An estimation device comprising: an information acquisition unit that acquires at least any one of a file name, a character string, and an execution log included in a readable part of a binary file; and an estimation unit that identifies software having at least any one of the file name, the character string, and the execution log based on source code information, package information, and command line manual information of each software, estimates the identified software as the target software of the binary file, and outputs the estimated software.
2. The estimation device according to claim 1, wherein when the estimation unit finds a file name identical to the file name included in the readable part of the binary file in a file list in the package information of the software, when it finds software using a command having the same name as the file name in the command line manual information, and when it finds a file name identical to the file name in a generated file name of software in build information retrieved from the source code information, the estimation unit estimates the software as the target software of the binary file and outputs the estimated software.
3. An estimation method executed by an estimation device, the method including: a step of acquiring at least any one of a file name, a character string, and an execution log included in a readable part of a binary file; and a step of identifying software having at least any one of the file name, the character string, and the execution log based on source code information, package information, and command line manual information of each software, estimating the identified software as the target software of the binary file, and outputting the estimated software.
4. An estimation program for causing a computer to execute: a step of acquiring at least any one of a file name, a character string, and an execution log included in a readable part of a binary file; and a step of identifying software having at least any one of the file name, the character string, and the execution log based on source code information, package information, and command line manual information of each software, estimating the identified software as the target software of the binary file, and outputting the estimated software.
Citation Information
Patent Citations
Binary software analysis
JP2012525648A
Determination apparatus, determination method, and determination program
JP2017004123A