Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

65 results about "Control flow diagram" patented technology

A control-flow diagram (CFD) is a diagram to describe the control flow of a business process, process or review. Control-flow diagrams were developed in the 1950s, and are widely used in multiple engineering disciplines. They are one of the classic business process modeling methodologies, along with flow charts, drakon-charts, data flow diagrams, functional flow block diagram, Gantt charts, PERT diagrams, and IDEF.

Multi-rule static detection and large-model dynamic repair method for code defects

The invention provides a multi-rule static detection and large-model dynamic repair method for code defects. The method comprises the steps that code defect types are summarized and abstracted into a unified defect mode rule set; constructing an abstract syntax tree, a control flow diagram and a data flow diagram of the source code; performing static analysis based on a multi-rule engine to identify potential defects; inputting the defect context into a large language model to generate a repair suggestion; performing semantic consistency verification and integration on the repair suggestions; and executing automatic testing and secondary static analysis to verify a repair result. According to the method, the traditional static analysis technology and the modern large language model capability are combined, accurate recognition and intelligent repair of code defects are achieved, a closed-loop defect processing flow is formed, the defect detection accuracy is improved, intelligent repair is achieved, closed-loop verification is formed, the development efficiency is improved, and man-machine cooperation is supported.
Owner:CHINA UNIV OF PETROLEUM (EAST CHINA)

A method, device, and medium for identifying software component analysis

The present invention discloses a method, device, and medium for identifying software component analysis, which relates to the technical field of software technology. Specifically, it includes: obtaining all files in the software to be identified to obtain a first data set; extracting meta-file data to obtain a second data set, and obtaining a first open-source file set through first feature matching; performing deletion processing on the first data set to obtain a third data set, calculating the minimum hash signature through the program abstract syntax tree and the corresponding sub-syntax tree to generate a second feature set, and obtaining a second open-source file set through third feature matching; performing deletion processing on the third data set to obtain a fourth data set, obtaining an updated syntax tree based on the abstract syntax tree and the fourth data set and constructing a control flow diagram, and obtaining a third open-source file set through fourth feature matching between the third feature set and a preset reference database; merging the first open-source file set, the second open-source file set, and the second open-source file set to obtain the total open-source component set in the software to be identified.
Owner:NANTONG INST OF TECH

Instruction-level code optimization method and device based on template matching, medium and equipment

The invention discloses an instruction-level code optimization method and device based on template matching, a medium and equipment. According to the method, instruction-level codes serve as input, the input instruction-level codes are firstly constructed into corresponding control flow diagrams, then value ranges of active variables and register quantities are initialized based on the control flow diagrams, then variable assignment instructions and related instructions are found out from instruction sequences of basic blocks to form instruction segments to be optimized, and the instruction segments to be optimized are optimized. The method comprises the following steps of: optimizing an instruction fragment, obtaining an optimized instruction fragment through template matching, performing SMT equivalence verification on the instruction fragment before and after optimization based on an active variable and a value range of a register quantity, and finally optimizing an input instruction-level code in a manner of replacing the instruction fragment before optimization with the optimized instruction fragment which is verified to be equivalent. And finally, the optimized instruction-level code is obtained.
Owner:NANJING UNIV

Multi-language code generation method based on self-supervised pre-training

The invention discloses a multi-language code generation method based on self-supervised pre-training, which comprises the following steps: acquiring and cleaning multi-language code data to form a training corpus; the method comprises the following steps: representing code data as an abstract syntax tree, extracting a control flow diagram and a data flow diagram of the code data, and obtaining unified semantic representation through combination of a diagram encoder and a sequence encoder; designing a self-supervised pre-training task, and pre-training the semantic representation based on the training corpus; constructing a multi-language pre-training model based on the structure-improved recurrent neural tensor network and the multi-language embedding matrix; when a user inputs a natural language, generating a target language code by using the multi-language pre-training model; and target language code correction is carried out through conventional function testing and grammar checking. According to the method, multi-channel recursive combination and a hierarchical recursive expansion mechanism are combined with self-supervised pre-training, so that accurate generation and performability improvement of cross-language codes are realized.
Owner:CLOUD HI-TECH (BEIJING) TECHNOLOGY CO LTD

Application user tracking detection method and device based on dynamic and static combination technology

The invention relates to an application user tracking detection method and device based on a dynamic and static combination technology, and the method comprises the steps: obtaining a first interprocess control flow diagram associated with a device identifier according to an application package of a target application and a configuration file containing a predefined device identifier; according to a program behavior of a target application in a running state, determining a function associated with an application programming interface of the equipment identifier and an application programming interface of network data transmission, and obtaining a second interprocess control flow diagram of data leakage according to the function; integrating the first interprocess control flow diagram and the second interprocess control flow diagram to obtain a third interprocess control flow diagram; and obtaining a leakage path of the target application to the user data according to the third interprocess control flow diagram. By adopting the method, the problems of narrow detection coverage and low detection accuracy in the aspect of tracking the user by using the device identifier through the APP can be solved.
Owner:HANGZHOU HIGH-TECH ZONE (BINJIANG) INSTITUTE OF BLOCKCHAIN & DATA SECURITY +1

Intelligent contract vulnerability detection method and system based on semantic comprehension and program path analysis

The invention discloses an intelligent contract vulnerability detection method and system based on semantic comprehension and program path analysis, and belongs to the technical field of network security. The method comprises the following steps: firstly, analyzing an intelligent contract code by using a large language model, and reasoning to generate a structured security rule for defining a taint source, a taint sink and a purifier; secondly, guiding a taint analysis engine by using a security rule, and tracking on a data flow and a control flow diagram of a program so as to efficiently screen out a high-risk taint path; then, carrying out reachability verification on the high-risk path by adopting a symbolic execution technology; and finally, performing final context review on the verified vulnerability path by using the large language model again to generate a vulnerability report. According to the method, the semantic comprehension ability of the large language model and the preciseness of traditional program analysis are subjected to multi-stage cooperation, so that the detection precision and efficiency of the intelligent contract logic vulnerability can be remarkably improved, the interpretability of a report result is greatly enhanced, and the method has important application value.
Owner:ZHEJIANG UNIV +2

Cross-architecture binary code similarity detection method based on graph neural network

The invention discloses a graph neural network-based cross-architecture binary code similarity detection method, which comprises the following steps of: respectively implementing original feature extraction operation on an open source software binary file and a firmware binary file by utilizing a reverse engineering tool to obtain basic feature data of the open source software binary file and the firmware binary file; the control flow diagram of the open source software and the firmware is converted into an embedded representation through an embedded network, the open source software generates an embedded representation table, and the firmware generates a corresponding embedded representation; and storing the open source software embedded representation into an open source software database, storing the firmware embedded representation into a firmware database, and finally, comparing the similarity of data in the database to complete the similarity detection of the cross-architecture binary codes so as to screen out code fragments possibly having potential safety hazards in the firmware. According to the method, the similarity of the cross-architecture binary codes can be effectively detected, and the third-party codes with security risks in the firmware of the Internet of Things equipment can be accurately detected.
Owner:NO 30 INST OF CHINA ELECTRONIC TECH GRP CORP +1

Static binary code taint analysis method based on propagation action range

The invention discloses a static binary code taint analysis method based on a propagation action scope, and relates to the field of static binary code taint analysis, and the static binary code taint analysis method comprises the following steps: extracting a program instruction set and a control flow structure based on a disassembling result of a target binary code; calculating a value set with a source of the binary code based on the control flow graph; on the basis of the control flow diagram and the value set with the source, executing cross-function stain propagation analysis, and identifying memory positions or registers influenced by pollution in each function and propagation action ranges of the memory positions or the registers; and extracting all instruction sets using the taint data based on the taint and the propagation action range thereof. According to the method, the false alarm rate of static binary taint analysis can be reduced and the instruction set involved in the taint analysis can be reduced without increasing the analysis overhead, so that the method has important significance in improving the instrumentation efficiency and the operation efficiency of dynamic taint analysis and improving the accuracy of protocol reversion, fuzzy testing and vulnerability mining based on the taint analysis.
Owner:EAST CHINA NORMAL UNIV

Software development system and software development method

The invention relates to the technical field of software development, and discloses a software development system and a software development method. The software development method comprises the following steps: constructing a multi-dimensional technical debt quantitative model, and calculating a technical debt score based on factors such as code complexity, change frequency and defect association degree; a code semantic multi-level representation model is constructed, and multi-level representation of codes is constructed through combined analysis of an abstract syntax tree, a data flow diagram and a control flow diagram; a self-supervised learning model is applied to train code representation, and development intentions and business concepts contained in codes are recognized; generating a context-dependent reconstruction suggestion; and optimizing the reconstruction path planning. Through objective quantification of the technical debt and deep understanding of code semantics, the technical problems that in the prior art, technical debt management is difficult to quantify and reconstruction decision-making lacks scientific basis are solved, code maintenance cost is remarkably reduced, and development efficiency is greatly improved.
Owner:BEIJING CAOMU TECHNOLOGY CO LTD

Code conversion method and related device

The invention discloses a code conversion method and a related device, and the method comprises the steps: obtaining an input code, carrying out the grammatical analysis of the input code, and generating an abstract syntax tree which comprises a plurality of nodes; coding a code text in the input code to generate a first semantic vector; encoding the structure in the abstract syntax tree to generate a second semantic vector; processing the first semantic vector, and converting the first semantic vector into a second semantic vector; generating a control flow diagram according to the abstract syntax tree, and constructing a data flow diagram; determining a plurality of semantic units according to the control flow diagram and the data flow diagram; obtaining a preset domain knowledge graph, wherein the preset domain knowledge graph comprises a plurality of concept nodes; according to the concept nodes and the semantic units, analyzing the second semantic vector to obtain a target semantic vector, decoding the target semantic vector into a target language, and generating a target code. By adopting the method and the device, code conversion expansibility and accuracy can be improved.
Owner:WEBANK (CHINA)

Static analysis method and device for program problems, electronic equipment, readable storage medium and program product

The embodiment of the invention provides a program problem static analysis method and device, electronic equipment, a readable storage medium and a program product, and relates to the technical field of program static analysis. The method comprises the steps that a target program is analyzed based on a rule constraint set of target syntax, and an abstract syntax tree is generated; constructing an annotation control flow graph according to the abstract syntax tree; according to the annotation control flow diagram, identifying a periodic task in the target program; and on the basis of performing loop expansion on the execution process of the periodic task, performing symbolic execution analysis on the annotation control flow diagram, and identifying the cross-period conflict problem of the periodic task. By identifying the periodic task and circularly expanding the periodic task, the analysis limitation on the program problem in the related technology is solved, the cross-period conflict problem in the program is efficiently identified, and the static guarantee capability on the program quality is improved.
Owner:SHANGHAI FORMAL TECH INFORMATION TECH CO LTD

Detecting uninitialized variables during program pre-compilation using control flow graphs

PendingUS20260044322A1Code compilationUninitialized variableTheoretical computer science
In various examples, static single assignment-based control flow graph traversal analysis for uninitialized variable detection system and methods are disclosed. A pre-compiler stage of a compiler system, may reconstruct source code into an SSA form IR and detect and identify uninitialized variables based on applying a variable analysis pass that traverses a CFG corresponding to the SSA form IR. A variable analysis pass may traverse through the CFG to build a defined variable map and a Phi variable map. The maps may be used to map undefined variables to basic blocks of the CFG where the undefined variables occur. The variable analysis pass may pass uninitialized variable data to a compiler error handling process. The compiler error handling process may produce an error report that traces the basic block with undefined variables to lines of the source code to assist in efficiently debugging the source code.
Owner:NVIDIA CORP

Code detection and protection method, system, equipment and medium

The invention provides a code detection and protection method, system and device and a medium, and belongs to the technical field of malicious code detection.The method specifically comprises the steps that WASM byte codes are obtained; converting the byte code into a WAT text and an intermediate representation, and analyzing meta-information; respectively constructing control flow diagrams and program dependency diagrams of the JS and the WASM based on the AST and the intermediate representation, and fusing the control flow diagrams and the program dependency diagrams into a unified dependency diagram through cross-language interface nodes; matching the dependency graph by using a preset malicious rule base, and marking a suspicious level; if not, WASM is injected into a Unikernel mirror image to be executed in an isolation environment, and behavior fingerprints during operation are collected; and outputting a malicious and non-malicious conclusion by combining the static analysis result with dynamic feature rating such as resource consumption and abnormal events. Through cross-language dependency graph fusion and dynamic and static combination analysis, malicious behaviors in WASM and JS interaction are captured, execution and behavior collection are isolated, the misjudgment risk is reduced, the detection accuracy is improved, and efficient and accurate WebAssembly module protection is achieved.
Owner:TAIAN POWER SUPPLY CO OF STATE GRID SHANDONG ELECTRIC POWER CO

Method, device, equipment and medium for multi-thread undefined behavior detection

The invention relates to the technical field of computers, and discloses a method, a device, equipment and a medium for multi-thread undefined behavior detection, and the method comprises the following steps: constructing a control flow diagram and a data flow diagram based on a multi-thread program code, and creating a multi-thread execution path model based on the control flow diagram and the data flow diagram; distributing a thread fragment data set in the multi-thread execution path model to a plurality of computing nodes, and extracting an operation sequence in the distributed thread fragment data set in each computing node; performing iteration and layering processing on the operation sequence, and constructing a causal relationship graph; based on the causal relationship graph, generating an operation dependency track, mapping the operation dependency track to different memory models, performing execution sequence simulation to obtain a plurality of execution paths, and performing behavior analysis based on the execution paths to obtain a behavior analysis result. According to the method, the undefined behaviors in the multi-thread program can be systematically detected, and the stability and the safety of the system can be improved.
Owner:镁佳(北京)科技有限公司

Lightweight program control flow obfuscation method, system, equipment and medium

The invention discloses a lightweight program control flow obfuscation method, system and device and a medium, and the method comprises the steps: carrying out the static analysis of a program based on a program source code, recognizing all basic blocks, analyzing the execution sequence and jump relation of the basic blocks, and obtaining a control flow diagram of the program; a unique runtime state is distributed for the basic blocks by analyzing the dependency relationship among the basic blocks, and a conversion rule among the states is defined, so that a state transition model is obtained; the method comprises the following steps: dynamically generating an encryption key by using a state conversion relationship, and encrypting sensitive information in a control flow to obtain an encryption program code subjected to obfuscation protection; a current runtime state is read in a program execution process, a corresponding decryption key is generated, a plaintext address of sensitive information is restored, and executable implicit jump and variable access operation is obtained. Static analysis, especially control flow analysis, can be effectively resisted, so that source codes and algorithms of software are protected from being easily acquired or tampered.
Owner:YUNNAN POWER GRID CO LTD KUNMING POWER SUPPLY BUREAU

Function name prediction method and system based on bidirectional semantic transfer

The invention relates to the technical field of function name prediction, in particular to a function name prediction method and system based on bidirectional semantic transfer. The method comprises the following steps of: 1, acquiring a target function of a binary file, and extracting a function body and an interprocess control flow diagram of the target function; wherein the target function is a function with a function name to be predicted; step 2, inputting the function body of the target function into a preset bidirectional semantic transfer framework, and obtaining global information of the target function; wherein the bidirectional semantic transfer framework obtains a corresponding sub-function and a parent function according to the target function, obtains an internal semantic database, a sub-function semantic database and a parent function semantic database of the target function by utilizing a large language model, and performs semantic fusion as global information; and 3, taking the global information of the target function as input of the large language model, and generating a function name of the target function in combination with the cue word. According to the method, the function name prediction reasoning capability can be improved.
Owner:Chinese People's Liberation Army Cyberspace Force Information Engineering University

Repeated vulnerability detection method based on multi-object type state analysis

The invention provides a repeated vulnerability detection method based on multi-object type state analysis, and the method comprises the steps: employing a preset vulnerability mode description language, constructing a corresponding vulnerability mode description rule for each vulnerability, and the rule comprises a plurality of variable objects and program statements causing the vulnerabilities; translating the vulnerability mode description rule into a corresponding linear sequential logic formula; converting the formula into an automaton, wherein the automaton comprises an accepting state of the automaton and binding constraints of a plurality of variable objects of the environment in the accepting state; constructing an interprocess control flow diagram for the target program to be detected, wherein the interprocess control flow diagram comprises a plurality of program points; performing multivariable object analysis on the target program based on the graph to obtain an automaton state set of each program point and a data dependency relationship of a plurality of variable objects under each automaton state, and when an automaton state in an accepting state exists and the data dependency relationship of the plurality of variable objects meets the binding constraint, performing the multivariable object analysis on the target program; and detecting that a corresponding vulnerability exists in the target program.
Owner:INST OF COMPUTING TECH CHINESE ACAD OF SCI

Vulnerability assessment method based on code and text multi-modal feature fusion and cross-task attention

The invention discloses a method for evaluating vulnerabilities by combining vulnerability codes and vulnerability description texts and using a cross-task attention mechanism. The method comprises the following steps: firstly, for a vulnerability code part, converting the vulnerability code part into a control flow diagram, and generating a plurality of execution paths from the control flow diagram; for the vulnerability description text part, some key vulnerability elements are extracted from the vulnerability description text part; then, considering that seven evaluation tasks have certain relevance, when feature representation of codes and texts is learned, a cross-task attention mechanism is introduced to capture relevance features among the tasks; and finally, carrying out weighted summation on the probability predicted by the classifiers at the code level and the text level to obtain a prediction result of final vulnerability assessment.
Owner:HANGZHOU DIANZI UNIV

Intelligent contract security vulnerability automatic detection and protection early warning method and system

The invention provides an intelligent contract security vulnerability automatic detection and protection early warning method and system, and relates to the technical field of vulnerability detection, and the method comprises the steps: converting an intelligent contract code into an abstract syntax tree to construct a control flow diagram and a data flow diagram, extracting a function call chain and the like to construct a moving trajectory diagram, and employing a dual verification analysis technology to detect vulnerabilities. And generating a risk assessment report, and constructing a vulnerability verification network based on zero-knowledge proof. According to the invention, the vulnerability detection accuracy of the smart contract can be remarkably improved, early warning of security risks of the smart contract is realized, and safe and stable operation of a block chain system is ensured.
Owner:JIANGSU YAOER LINGJIU TECHNOLOGY SERVICE CO LTD

An integrated circuit supply chain site security analysis method and device

The present invention provides a method and apparatus for analyzing the security of an integrated circuit supply chain site. The method includes obtaining evaluation factors, where the evaluation factors include: service type factors, site entity factors, process factors, and process flow factors; extracting, from a control flow chart database based on a preset mapping relationship, a control flow chart of an integrated circuit supply chain site service that is adapted to the evaluation factors, where the preset mapping relationship stores the mapping relationship between the evaluation factors and the control flow chart of the integrated circuit supply chain site service; extracting asset elements included in the control flow chart of the integrated circuit supply chain site service; and retrieving preset threat analysis data corresponding to the asset elements from a preset database.
Owner:CHINA INFORMATION TECH SECURITY EVALUATION CENT

Flowchart creation method, model training method, device, equipment and medium

The present application provides a method for creating a flowchart, a method for training a model, an apparatus, a device, and a medium, which relate to the field of computer technology. The method for creating a flowchart includes: obtaining an industrial control flowchart picture of a first industrial control system; performing text recognition on the industrial control flowchart picture based on a pre-trained flowchart text recognition model to obtain the text content in the industrial control flowchart picture and the coordinate information of the text content; and generating an industrial control flowchart of a second industrial control system by using a flowchart editing software in the second industrial control system according to the text content and the coordinate information of the text content. The present application can save the drawing time of engineering personnel and improve work efficiency.
Owner:SUPCON TECH CO LTD

Metamorphic relation identification method and device based on node and path characteristics

The invention provides a metamorphic relation identification method and device based on node and path characteristics, and the method comprises the steps: obtaining a plurality of objective functions which comprise a plurality of first functions with a target metamorphic relation and a plurality of second functions without the target metamorphic relation; analyzing the source code of each objective function to generate a corresponding control flow chart; feature extraction is conducted on the control flow chart to determine node features and path features, and the node features and the path features corresponding to the multiple target functions are combined to serve as training data; performing model training on the initial support vector machine model based on the training data to obtain a target support vector machine model; and based on the target support vector machine model, obtaining a target metamorphic relation identification result of the to-be-tested function. Therefore, the automation degree of the metamorphic test can be effectively improved, the dependence of testers on professional knowledge is greatly reduced, and meanwhile, the identification efficiency of the metamorphic relationship is improved.
Owner:HUANENG NUCLEAR ENERGY TECH RES INST CO LTD +1

Binary program static analysis method based on comprehensive control flow diagram

The invention provides a binary program static analysis method based on a comprehensive control flow diagram. According to the scheme, the method comprises preprocessing, a control flow diagram generation module, a reverse control flow diagram generation module, target address ambiguity instruction recognition and a specific basic block path. The control flow diagram generation module obtains binary program information through preprocessing and generates a control flow diagram by using a breadth-first search algorithm. The reverse control flow diagram generation module initializes a reverse control flow diagram and generates a reverse edge by traversing the control flow diagram. A target address ambiguity instruction analysis module identifies a target address ambiguity jump or call instruction in the basic block. The specific basic block path analysis module uses a path search algorithm to obtain all paths of a specific basic block, and analyzes execution conditions of the paths through a symbolic execution technology. According to the method, the binary program can be comprehensively analyzed, the analysis efficiency and accuracy are improved, and powerful support is provided for software security and quality improvement.
Owner:NORTHWESTERN POLYTECHNICAL UNIV

Intelligent contract vulnerability detection and positioning method based on anchor point multi-spatial scale

The invention discloses a smart contract vulnerability detection and positioning method based on anchor point multi-spatial scale, and belongs to the technical field of security detection of a block chain network. The problems that an existing method is poor in vulnerability positioning accuracy and cannot explain vulnerability generation reasons are solved. The method comprises the following steps: firstly, disassembling byte codes, outputting operation codes obtained by disassembling as a control flow chart, segmenting the control flow chart into a plurality of instances, generating a plurality of anchor chains with fixed lengths on each instance, and constructing anchor chain characteristics for each anchor chain; secondly, splicing features of all anchor chains on a spatial scale, processing the features of the anchor chains on a contract scale and a Block scale, and identifying potential vulnerabilities in the contract; when a single anchor chain in each instance is analyzed, splicing with global features on a contract scale is carried out, and a vulnerability position is positioned through a multi-layer perceptron; and finally, realizing vulnerability positioning on an instruction scale. The method can be applied to contract vulnerability detection and positioning.
Owner:HARBIN ENG UNIV

Solidiity smart contract standard repair method

The invention discloses a method for repairing a Solidiity smart contract specification, which comprises the following steps of: inputting a Solidiity smart contract program with a developer-defined specification, performing consistency verification on the smart contract program and a Hall logic compiled specification, and repairing a smart contract which is verified to be inconsistent, so that the consistency of the Solidiity smart contract program and the Hall logic compiled specification is improved. And finally obtaining a smart contract consistent and correct with the program. In the verification process, an intelligent contract program is converted into a grammar abstract tree and a control flow chart, and a z3 solver is adopted to solve whether the program is consistent with a specification or not based on a satisfiability model theory (SMT). And repairing the inconsistent specification by means of backtracking reasoning, quantifier elimination, graph editing distance and the like to obtain a specification consistent with the program. Experiments prove that the method can be well applied to a real smart contract scene added with specifications, and developers can be effectively helped to verify and write more accurate smart contract specifications, so that use and development of the smart contract specifications are promoted.
Owner:TIANJIN UNIV

Code similarity detection method based on execution semantics

The invention discloses a code similarity detection method based on execution semantics, which adopts an end-to-end simulation execution mechanism to guide a model to model an instruction through a dynamic execution behavior of the instruction so as to deeply understand and analyze semantic connotation of codes and extract representation with execution semantic features; carrying out disassembling and control flow diagram construction on the binary program by utilizing a reverse analysis tool, and carrying out statistics and standardization processing on assembly instructions in the basic blocks so as to screen out key instructions with semantic representativeness; simulating an execution process of the instruction by adopting a Transform model, analyzing and capturing a semantic behavior of the instruction in a specific context, and further generating an instruction embedding representation with execution semantic information; and finally, modeling structure information of nodes in the control flow graph by means of a graph matching neural network, fusing execution semantics among basic blocks, constructing a function-level representation, and realizing accurate similarity measurement through a cosine distance.
Owner:GUIZHOU NORMAL UNIVERSITY

Cross-architecture container mirror image compatibility verification method

The invention discloses a cross-architecture container mirror image compatibility verification method, which comprises the following steps of: receiving a container mirror image, analyzing an executable entity in the container mirror image, and constructing program representation data containing a control flow diagram and a symbol table; according to the method, by tracking the life cycle of a resource handle carrying state information in a program calling graph, a source architecture RSTG capable of describing program and kernel interaction logic is analyzed and constructed, an abstract resource state is used as a node, and system calling causing state change is used as an edge; performing mapping comparison on the source architecture RSTG and a preset target architecture RSTG rule set so as to identify an illegal state migration sequence in the target architecture and form an incompatible point set; and tracing the incompatible points, associating the incompatible points to specific code positions, and generating a report. According to the method, the compatibility verification is improved from stateless instruction comparison to stateful logic examination height, hidden compatibility defects can be found, and the verification depth and accuracy are remarkably improved.
Owner:GUIZHOU QIANYUAN POWER CO LTD

Intelligent contract vulnerability detection method based on pre-training technology

The invention provides an intelligent contract vulnerability detection method based on a pre-training technology. The method comprises the following steps: extracting multi-modal information of an intelligent contract source code according to the intelligent contract source code; inputting the smart contract source code into a first pre-training language model to extract semantic features of the smart contract source code; inputting the control flow chart of the source code of the smart contract into a GAT model based on multi-head attention to extract graph structure features of the source code of the smart contract; inputting the intermediate representation IR of the smart contract source code into a second pre-training language model to extract execution behavior characteristics of the smart contract source code; respectively inputting the semantic features of the smart contract source code, the execution behavior features of the smart contract source code and the graph structure features of the smart contract source code into three classifiers to obtain corresponding prediction results; and performing decision fusion on prediction results obtained by the three classifiers to obtain a final decision. Potential risks can be found in advance, potential safety hazards are reduced, and the method has wide application prospects and commercial value.
Owner:CHONGQING UNIV OF POSTS & TELECOMM

Automatic protocol vulnerability mining method and device based on enhanced data flow diagram

The invention provides a protocol vulnerability automatic mining method and device based on an enhanced data flow diagram, and the method comprises the steps: determining an analysis range of a source code, and compiling the source code into an intermediate language file based on the analysis range; performing control flow analysis on the intermediate language file to obtain a total control flow diagram; based on the total control flow diagram, performing data flow analysis and improvement on the intermediate language to generate an enhanced data flow diagram; determining an analysis target, and obtaining a calling path of the analysis target based on the enhanced data flow diagram; and performing potential risk judgment on the calling path of the analysis target, printing a path with a potential vulnerability risk, and warning a user. The protocol interaction semantic information in the source code is extracted through the static analysis technology, potential risk judgment is performed on the interaction information, vulnerabilities brought by protocol interaction can be effectively recognized, dependence on manual analysis or test cases in the protocol vulnerability mining process is reduced, the analysis range of the protocol vulnerabilities is expanded, and the protocol vulnerability mining efficiency is improved. And the protocol vulnerability mining capability and efficiency are improved.
Owner:TSINGHUA UNIVERSITY +1

Static binary code control flow diagram reconstruction method based on value set analysis

The invention discloses a static binary code control flow diagram reconstruction method based on value set analysis, which relates to the field of static binary code analysis, and comprises the following steps: extracting a program instruction set and related data segment information based on a disassembling result of a target binary executable file; obtaining an original control flow diagram, and calculating a virtual function information set based on virtual table information; and constructing a function inner value set by using a work list algorithm, analyzing an indirect jump target address according to the value set, and reconstructing a control flow diagram. According to the method, the binary code can be comprehensively analyzed under reasonable overhead, the accuracy of indirect jump target address analysis is improved, the accuracy of the control flow diagram is ensured, and the method has important significance in improving the quality of a binary code analysis task.
Owner:EAST CHINA NORMAL UNIV