The invention provides a code detection and protection method,
system and device and a medium, and belongs to the technical field of malicious code detection.The method specifically comprises the steps that WASM
byte codes are obtained; converting the
byte code into a WAT text and an intermediate representation, and analyzing meta-information; respectively constructing
control flow diagrams and program dependency diagrams of the JS and the WASM based on the AST and the intermediate representation, and fusing the
control flow diagrams and the program dependency diagrams into a unified dependency diagram through cross-language interface nodes; matching the
dependency graph by using a preset malicious rule base, and marking a suspicious level; if not, WASM is injected into a Unikernel
mirror image to be executed in an isolation environment, and behavior fingerprints during operation are collected; and outputting a malicious and non-malicious conclusion by combining the
static analysis result with
dynamic feature rating such as
resource consumption and abnormal events. Through cross-language
dependency graph fusion and dynamic and static combination analysis, malicious behaviors in WASM and JS interaction are captured, execution and behavior collection are isolated, the misjudgment risk is reduced, the detection accuracy is improved, and efficient and accurate WebAssembly module protection is achieved.