Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

343 results about "Control flow graph" patented technology

In computer science, a control-flow graph (CFG) is a representation, using graph notation, of all paths that might be traversed through a program during its execution. The control-flow graph is due to Frances E. Allen, who notes that Reese T. Prosser used boolean connectivity matrices for flow analysis before.

Variation test method and device based on intelligent automation script

The invention discloses a variation test method and device based on an intelligent automation script. The method comprises the following steps: extracting a statement execution sequence and a branch dependency relationship in an original source code by using a context-aware syntax tree, and generating a control flow diagram and a data flow diagram; performing code semantic analysis on the multi-dimensional code features by using a large language model, identifying potential defect types and variation rules, predicting the test efficiency of variants in combination with a deep Q learning model, and generating to-be-processed variants; performing grammar check and equivalence analysis on the to-be-processed variants to obtain effective variants, and testing the effective variants; variation test indexes are calculated, code weak points are positioned, and test blind areas are identified according to survival variants, so that a visual analysis report is generated; and iteratively generating a new test case according to the current survival variant and the visual analysis report, and testing the current survival variant by using the new test case. According to the invention, the variation test efficiency can be improved.
Owner:BEIJING YULORE INNOVATION TECH

Cross-chain smart contract vulnerability detection method and system based on multi-feature fusion learning

The invention discloses a cross-chain smart contract vulnerability detection method and system based on multi-feature fusion learning. The method comprises the following steps: collecting a cross-chain smart contract vulnerability data set for cleaning and labeling; feature extraction is carried out from the source code and the byte code, an abstract syntax tree (AST) is extracted from the cleaned source code, a basic control flow graph (CFG) is extracted from the byte code, and a cross-chain control flow graph (xCFG) is constructed; carrying out feature representation on AST and xCFG, generating a graph vector through a graph neural network (GNN), generating a semantic vector through CodeBert, and fusing the semantic vector into a feature fusion vector; performing model training and detection, taking the generated vectors as training data and test data, obtaining a cross-chain smart contract vulnerability detection model by adopting Transform-FC model training data, and finally evaluating model performance through accuracy, recall rate, precision rate and F1 value. According to the method, the structural features and semantic features of the codes can be effectively fused, potential vulnerability information in the codes can be fully mined, the recognition capability of the model for cross-chain vulnerabilities can be enhanced, and the accuracy and reliability of the cross-chain vulnerability detection model can be improved, so that the security of a block chain system can be more efficiently guaranteed.
Owner:HOHAI UNIV

Intelligent contract vulnerability detection method based on heterogeneous graph attention network

The invention discloses an intelligent contract vulnerability detection method based on a heterogeneous graph attention network. According to the method, firstly, the source code of the intelligent contract is preprocessed, the SCIR of the code of the intelligent contract is constructed, the complexity of the code of the contract is reduced, and vulnerability features are enriched; and constructing an intelligent contract code attribute graph SCPG based on SCIR, integrating various code graph structures such as an abstract syntax tree and a control flow graph, and comprehensively describing syntax and semantic features of the contract. And then constructing an intelligent contract code heterogeneous graph SCHG on the basis of the SCPG, optimizing code graph structure representation, and realizing high-quality modeling of node features. And finally, detecting the vulnerability of the smart contract by using a customized multi-layer heterogeneous graph attention network model MHGAN. The intelligent contract vulnerability detection method based on deep learning makes up for the defects of an existing intelligent contract vulnerability detection method based on deep learning, effectively improves the accuracy of intelligent contract vulnerability detection, and is excellent in the interpretability of the detection result.
Owner:HANGZHOU DIANZI UNIV

Source code vulnerability detection method combining static and dynamic analysis

The invention discloses a static and dynamic analysis-combined source code vulnerability detection method, which comprises the following steps of: performing static scanning on an input source code, and preliminarily positioning potential vulnerabilities according to a preset vulnerability rule base; executing program slicing based on the control flow diagram and the data flow diagram, and extracting a precise code subset related to the vulnerability; a large language model based on a Transform structure is utilized, and a dynamic verification attack case is automatically generated according to the vulnerability type and the slice code; executing the test case in a sandbox environment, monitoring program abnormal behaviors in real time, and confirming actual availability of vulnerabilities; and finally, synthesizing static and dynamic results to generate a multi-level vulnerability detection report. According to the method, the accuracy and coverage rate of vulnerability detection can be effectively improved, the false report and missing report rate is reduced, high automation and intelligence of the source code vulnerability detection process are realized, and the method has good applicability and popularization value.
Owner:GUANGDONG POWER GRID CO LTD +1

Automatic test scheme generation method, equipment and medium

The invention relates to the technical field of automatic testing, and discloses an automatic testing scheme generation method and device and a medium, and the method comprises the steps: matching a demand action in a test demand with a code entry name corresponding to a code segment, and determining a code risk level of a current demand code block; analyzing the code change frequency and the code dependency degree of the current demand code block according to historical test records in the test domain knowledge base, and determining the test dynamic priority of the current demand code block; constructing a control flow diagram and a data flow diagram of the current demand code block, and detecting risk nodes in the control flow diagram and the data flow diagram; generating a test scene of the current demand code block according to the risk node, and generating a boundary value test rule according to a key constraint condition in the data flow diagram; and querying an environment simulation rule of the current demand code block, and packaging the test scene, the boundary value test rule and the environment simulation rule into an automatic test scheme. According to the invention, the code coverage when the test scheme is generated can be improved.
Owner:深圳市分期乐网络科技有限公司

Cross-language application program vulnerability mining method based on static analysis

The invention discloses a cross-language application program vulnerability mining method based on static analysis, which adopts a nested cross-programming language pointer analysis method and a micro-service cross-programming language taint tracking method to effectively solve the limitation of processing nested cross-language control flow and micro-service cross-language data flow. A nested language semantic boundary is accurately positioned by constructing a nested byte code, and a data stream is completely tracked by utilizing an interface relay technology, so that the detection precision is improved. According to the method, part of multi-end data streams and complex control streams of cross-programming language applications can be uniformly processed, and the analysis process in a cross-programming language environment is simplified; by nesting cross-programming language control flow diagram construction and double-end / multi-end data flow diagram construction, a unified analysis framework is constructed, seamless cooperation of static analysis among different languages is achieved, the analysis cost is reduced, the analysis efficiency is improved, efficient and accurate vulnerability mining is achieved in a complex cross-programming language application program, and the method is suitable for application and popularization. And the reliability of cross-language vulnerability detection is improved.
Owner:XIDIAN UNIV

Test generation and defect prediction method and system based on heterogeneous program diagram

The invention discloses a test generation and defect prediction method and system based on a heterogeneous program diagram, and the method comprises the steps: constructing a heterogeneous dynamic program dependency diagram: extracting an abstract syntax tree, a control flow diagram and a program dependency diagram of a source code through static analysis, capturing an execution track during operation in combination with dynamic instrumentation, and integrating version evolution information, forming a heterogeneous dynamic program dependency graph containing various types of nodes and edges; heterogeneous graph neural network modeling: designing a four-layer eight-header heterogeneous graph neural network model based on the heterogeneous dynamic program dependency graph, and outputting a function level defect probability and a test case sequence by adopting a type awareness attention mechanism and time coding injection; and multi-task joint training and reasoning: adopting an end-to-end training strategy, jointly optimizing defect prediction loss and test generation loss, preferentially screening high-risk functions during reasoning, and generating a coverage test case. According to the method, the defect detection accuracy is remarkably improved, the test coverage rate is increased, and the method is suitable for enterprise-level complex software systems.
Owner:NO 15 INST OF CHINA ELECTRONICS TECH GRP

Source code bug repairing method, electronic equipment and storage medium

The invention relates to the technical field of vulnerability repair, in particular to a source code vulnerability repair method, electronic equipment and a storage medium, and the method comprises the following steps: obtaining an abstract syntax tree and a control flow graph according to a source code containing a vulnerability, and generating a vulnerability context feature vector by using a graph neural network model in combination with vulnerability position information, determining a historical vulnerability repair case corresponding to the vulnerability context feature vector from a vulnerability-repair knowledge base, inputting the vulnerability context feature vector and the corresponding historical vulnerability repair case into a code generation model, outputting a candidate repair code set corresponding to the source code, evaluating each candidate repair code, and determining the vulnerability-repair knowledge base according to the candidate repair code set. Screening out an optimal repair code to automatically repair the source code vulnerability; according to the method, deep semantic analysis is performed on the vulnerability context, and intelligent reasoning is performed, so that the repair code with correct grammar and adaptive context can be generated, and the automation level and accuracy of vulnerability repair are remarkably improved.
Owner:QINGDAO WANDAO (BEIJING) INFORMATION TECH CO LTD

Instruction-level code optimization method and device based on template matching, medium and equipment

The invention discloses an instruction-level code optimization method and device based on template matching, a medium and equipment. According to the method, instruction-level codes serve as input, the input instruction-level codes are firstly constructed into corresponding control flow diagrams, then value ranges of active variables and register quantities are initialized based on the control flow diagrams, then variable assignment instructions and related instructions are found out from instruction sequences of basic blocks to form instruction segments to be optimized, and the instruction segments to be optimized are optimized. The method comprises the following steps of: optimizing an instruction fragment, obtaining an optimized instruction fragment through template matching, performing SMT equivalence verification on the instruction fragment before and after optimization based on an active variable and a value range of a register quantity, and finally optimizing an input instruction-level code in a manner of replacing the instruction fragment before optimization with the optimized instruction fragment which is verified to be equivalent. And finally, the optimized instruction-level code is obtained.
Owner:NANJING UNIV

Multi-language code generation method based on self-supervised pre-training

The invention discloses a multi-language code generation method based on self-supervised pre-training, which comprises the following steps: acquiring and cleaning multi-language code data to form a training corpus; the method comprises the following steps: representing code data as an abstract syntax tree, extracting a control flow diagram and a data flow diagram of the code data, and obtaining unified semantic representation through combination of a diagram encoder and a sequence encoder; designing a self-supervised pre-training task, and pre-training the semantic representation based on the training corpus; constructing a multi-language pre-training model based on the structure-improved recurrent neural tensor network and the multi-language embedding matrix; when a user inputs a natural language, generating a target language code by using the multi-language pre-training model; and target language code correction is carried out through conventional function testing and grammar checking. According to the method, multi-channel recursive combination and a hierarchical recursive expansion mechanism are combined with self-supervised pre-training, so that accurate generation and performability improvement of cross-language codes are realized.
Owner:CLOUD HI-TECH (BEIJING) TECHNOLOGY CO LTD

LLVM-based Program Static Analysis Method and System

The present invention discloses a program static analysis method and system based on LLVM, belonging to the technical field of computer program analysis. The technical problem to be solved is that the existing program analysis technologies have low accuracy, low efficiency and limited application scope in estimating program performance characteristics and memory reuse distance distribution. The method includes: converting a source file into an LLVM IR file with source-level debugging information; traversing modules, functions, basic blocks and instructions in the LLVM IR file to obtain static trace information of a target function; constructing a basic block-level control flow graph of the LLVM IR file and annotating relevant information; identifying and annotating loop information when traversing paths to obtain an execution path with loop annotations, replacing basic blocks in the execution path with corresponding memory access information, and generating a static memory trace with loop annotations; calculating the memory access reuse distance distribution through a recursive algorithm based on the static memory trace with loop annotations.
Owner:SHANDONG INSPUR SCI RES INST CO LTD

Application user tracking detection method and device based on dynamic and static combination technology

The invention relates to an application user tracking detection method and device based on a dynamic and static combination technology, and the method comprises the steps: obtaining a first interprocess control flow diagram associated with a device identifier according to an application package of a target application and a configuration file containing a predefined device identifier; according to a program behavior of a target application in a running state, determining a function associated with an application programming interface of the equipment identifier and an application programming interface of network data transmission, and obtaining a second interprocess control flow diagram of data leakage according to the function; integrating the first interprocess control flow diagram and the second interprocess control flow diagram to obtain a third interprocess control flow diagram; and obtaining a leakage path of the target application to the user data according to the third interprocess control flow diagram. By adopting the method, the problems of narrow detection coverage and low detection accuracy in the aspect of tracking the user by using the device identifier through the APP can be solved.
Owner:HANGZHOU HIGH-TECH ZONE (BINJIANG) INSTITUTE OF BLOCKCHAIN & DATA SECURITY +1

Cross-modal adaptation fine tuning method and system based on double-branch network architecture

The invention discloses a cross-modal adaptive fine tuning method and system based on a double-branch network architecture, and realizes cross-modal knowledge fusion and migration by combining the modeling capability of a graph neural network on code graph structures such as an abstract syntax tree, a control flow graph and the like and the powerful semantic understanding and generation capability of a large language model. A double-branch architecture is adopted, a graph structure and text input are coded respectively, and feature interaction is achieved through heterogeneous adaptation, structural decoupling and a mask attention mechanism. In a fine tuning stage, three-stage strategies are provided: basic fine tuning of structure perception, efficient parameter migration by combining Adapter, Prefix Tuning and LoRA, and language generation quality and robustness are optimized based on an unsupervised text reconstruction task. The training stage relates to structure sensing tasks such as node prediction, edge reconstruction and subgraph comparison, and the stability and generalization ability are improved in combination with course learning. The method is widely applicable to tasks such as code completion, question and answer and vulnerability detection, and has the advantages of strong structure perception, efficient cross-modal fusion, low training cost and the like.
Owner:PEKING UNIV +1

Computer network security software debugging method and system

The invention provides a computer network security software debugging method and system, and the method comprises the steps: setting a plurality of test nodes of a source program in target network security software, and positioning a key test node based on the execution state of each test node; constructing a target search domain when the source program is tested through the program context information of the key test node; determining a plurality of abnormal program slices in the source program based on the static control flow diagram and the dynamic control flow diagram of the program code in the target search domain; determining the test overhead of each program slice according to the test coverage information of each program slice and the path complexity when the source program executes the test data; determining the constraint level of each program slice according to all the test overhead and the membership relationship among the program slices; and debugging each program slice through the constraint level of each program slice. According to the scheme, on the basis of the constraint level of each program slice, the problem code line can be accurately pointed in the network security software debugging process.
Owner:CHENZHOU VOCATIONAL & TECH COLLEGE

Code attribute graph and large model-based code defect automatic repair method

The invention discloses an automatic code defect repairing method based on a code attribute graph and a large model, which comprises the following steps: collecting a code sample, analyzing a source code, generating the code attribute graph fusing an abstract syntax tree, a control flow graph and a data flow graph, and then carrying out dynamic pruning according to node importance calculated based on node degrees, PageRank and data propagation dependency, so as to obtain a large model; key nodes are reserved to improve the graph learning efficiency; extracting features of the optimized graph through GAT, introducing multi-scale coding, and generating a graph embedding vector; in combination with node importance, high-value Tokens are screened, semantic embedding of structure perception is carried out, and more accurate text representation is obtained; generating a comprehensive feature by fusing the image and the text vector, and then inserting a mask at a position with weak dependence or high risk; performing fine tuning optimization on the mask position; and inputting the comprehensive features and the mask source codes into a pre-training language model to generate patches, performing multi-task evaluation and reordering, and selecting an optimal patch to complete repair.
Owner:SOUTHWEST UNIVERSITY FOR NATIONALITIES

Flow chart image analysis and structured reconstruction method and device, and storage medium

The invention discloses a flow chart image analysis and structured reconstruction method and device and a storage medium, and relates to the technical field of image processing, and the method comprises the steps: carrying out the element background separation of an input image through a pre-trained convolutional neural network, and obtaining a flow chart image, the elements including text elements and graphic elements; extracting rectangular frame information, arrow information, text information and position coordinates thereof in the preprocessed flow chart image; determining the node type of each node in the flow chart image based on the rectangular frame information and the text information, and determining the connection relationship of each node based on the arrow information in combination with the position coordinates; analyzing the node type and the connection relationship of each node, modeling the logic relationship of each node, and generating a control flow diagram of the flow diagram image; and converting the control flow diagram into structured data, and rendering to generate an interactively editable flow diagram visual interface. According to the method and the device, the technical effect of reconstructing the structured flow chart by identifying the control logic structure of the flow chart is realized.
Owner:JIANTU CHUANGZHI (SHENZHEN) TECH CO LTD

Path coverage test data generation method based on SA-BKA hybrid optimization mechanism

The invention relates to the technical field of software engineering, and discloses a path coverage test data generation method based on an SA-BKA hybrid optimization mechanism, and the method comprises the steps: generating a control flow diagram through a program, recognizing each decision node through the control flow diagram, and deducing a set of all possible execution path sets as a target path set according to the decision nodes; the paths are grouped through path similarity, different optimization strategies are selected for the paths with different similarities, a simulated annealing algorithm is adopted for the groups with high path similarity, and an adaptive disturbance strategy is introduced, so that the algorithm diversity is enhanced; for low-similarity groups, a BKA algorithm is adopted, Levy flight and a dynamic step length adjustment strategy are fused, and meanwhile balance of the search process is achieved through dynamic step length adjustment. Compared with the prior art, the method has higher search efficiency under the condition of different population scales, and verifies the validity in path coverage test data generation.
Owner:SUQIAN COLLEGE

Intelligent contract vulnerability detection method and system based on multi-modal large language model

The invention relates to the technical field of block chains, in particular to a smart contract vulnerability detection method and system based on a multi-modal large language model.The detection method comprises the steps that S1, the system receives source code input of a smart contract; s2, executing semantic branches and graph structure branches in parallel; executing semantic branch processing, calling an annotation agent, and generating an annotation from the source code of the smart contract; calling a vectorization agent, coding the annotation and the source code, and converting the annotation and the source code into a high-dimensional vector; executing graph structure branch processing, compiling a source code into a byte code by the system, and generating a control flow graph; the vectorization agent generates high-dimensional embedded representation of the nodes based on the control flow graph; and S3, integrating features extracted from the semantic branches and the graph structure branches through a multi-modal feature fusion strategy, and inputting the integrated features into a classifier to detect vulnerabilities. The method is based on a multi-modal large language model agent, and potential vulnerabilities in the smart contract are comprehensively analyzed by integrating high-level semantic information and low-level structured data.
Owner:BEIHANG UNIV

Code embedding method based on semantic embedding vector generation model and related device

The invention discloses a code embedding method based on a semantic embedding vector generation model, which belongs to the technical field of computers, and comprises the following steps of: obtaining a binary code block, and performing disassembling processing and code structure analysis based on different granularities to obtain a basic block corresponding to the binary code block and a control flow diagram structure feature; performing assembly instruction linear conversion and cross-instruction-set semantic embedding conversion on the basis of the basic blocks corresponding to the binary code blocks and the structural features of the control flow graph to generate a unified binary code semantic embedding vector space corresponding to a cross-instruction-set architecture; obtaining a known vulnerability sample, and performing semantic vulnerability characterization analysis and candidate vulnerability retrieval positioning to generate a candidate vulnerability code block set; and carrying out dynamic analysis verification on the candidate vulnerability code block set and identifying a corresponding vulnerability repair state so as to output a corresponding binary vulnerability code block detection report. According to the method, high-precision semantic embedding of binary codes can be realized.
Owner:HUANENG POWER INT INC +1

Memory allocation method and device, electronic equipment, storage medium and chip

The invention provides a memory allocation method and device, electronic equipment, a storage medium and a chip. The method comprises the following steps: extracting tensor data of each tensor in a kernel program; constructing a control flow diagram according to the kernel program; allocating first address information in a static random access memory for each piece of tensor data; determining an active path of each tensor according to the control flow graph, the active path comprising a first node involving the tensor; an interferogram of the tensors is constructed according to the active path, each second node in the interferogram represents a different tensor, and edges between the second nodes represent an interference relation between the tensors; the first address information of each piece of tensor data is adjusted according to the interferogram, the second address information of each piece of tensor data is obtained, and in different steps of the kernel program, if no interference relation exists between the two tensors, the storage areas of the two pieces of tensor data are reused. According to the invention, the memory reuse rate can be improved.
Owner:SHANGHAI ORIENTAL COMPUTER TECHNOLOGY CO LTD

Micropatch repair path adaptive optimization method, system and device based on variational inference and medium

The invention relates to the technical field of software security, and discloses a variational inference-based micropatch repair path adaptive optimization method, system, device and medium, and the method comprises the steps: constructing a joint control flow diagram and a data flow diagram of a to-be-analyzed program, and forming a program structure diagram; based on the program structure diagram, modeling and sampling potential variables of the repair paths through variational inference, and generating a plurality of candidate repair paths; for each candidate repair path, generating a micropatch statement according to context semantics of each node in the path, and inserting the micropatch statement into a corresponding instrumentation position in the source code; and performing multi-dimensional scoring and sorting on the candidate repair paths, and selecting an optimal repair path for deployment according to a scoring result. According to the method, the structural breakthrough of the whole process is realized in the aspects of path identification, patch generation, strategy optimization, engineering deployment and the like, and a technical support is provided for constructing a software vulnerability repair system with autonomous generation, semantic understanding and controllable deployment capabilities.
Owner:GUIZHOU POWER GRID CO LTD

Intelligent contract vulnerability detection method and system based on semantic comprehension and program path analysis

The invention discloses an intelligent contract vulnerability detection method and system based on semantic comprehension and program path analysis, and belongs to the technical field of network security. The method comprises the following steps: firstly, analyzing an intelligent contract code by using a large language model, and reasoning to generate a structured security rule for defining a taint source, a taint sink and a purifier; secondly, guiding a taint analysis engine by using a security rule, and tracking on a data flow and a control flow diagram of a program so as to efficiently screen out a high-risk taint path; then, carrying out reachability verification on the high-risk path by adopting a symbolic execution technology; and finally, performing final context review on the verified vulnerability path by using the large language model again to generate a vulnerability report. According to the method, the semantic comprehension ability of the large language model and the preciseness of traditional program analysis are subjected to multi-stage cooperation, so that the detection precision and efficiency of the intelligent contract logic vulnerability can be remarkably improved, the interpretability of a report result is greatly enhanced, and the method has important application value.
Owner:ZHEJIANG UNIV +2

Cross-architecture binary code similarity detection method based on graph neural network

The invention discloses a graph neural network-based cross-architecture binary code similarity detection method, which comprises the following steps of: respectively implementing original feature extraction operation on an open source software binary file and a firmware binary file by utilizing a reverse engineering tool to obtain basic feature data of the open source software binary file and the firmware binary file; the control flow diagram of the open source software and the firmware is converted into an embedded representation through an embedded network, the open source software generates an embedded representation table, and the firmware generates a corresponding embedded representation; and storing the open source software embedded representation into an open source software database, storing the firmware embedded representation into a firmware database, and finally, comparing the similarity of data in the database to complete the similarity detection of the cross-architecture binary codes so as to screen out code fragments possibly having potential safety hazards in the firmware. According to the method, the similarity of the cross-architecture binary codes can be effectively detected, and the third-party codes with security risks in the firmware of the Internet of Things equipment can be accurately detected.
Owner:NO 30 INST OF CHINA ELECTRONIC TECH GRP CORP +1

Cross-language software vulnerability detection method and device

The invention relates to a cross-language software vulnerability detection method and device, and the method comprises the steps: carrying out the analysis of a Joern static analysis pair, carrying out the integration and semantic enhancement of an abstract syntax tree, a control flow graph and a data dependence graph, and obtaining a cross-warehouse heterogeneous code graph; obtaining cross-language intermediate representation based on a compiler framework; after the cross-language intermediate representation and the cross-warehouse heterogeneous code graph are modeled, weighted fusion is carried out through a gated cross attention mechanism, and a multi-modal data set is obtained; carrying out migration training on the multi-modal cross-language vulnerability detection model, and carrying out vulnerability detection on cross-language software to obtain a detection result; through multi-modal data fusion and modeling, in combination with cross-language intermediate representation and a cross-warehouse heterogeneous code graph, the defects of a traditional method in the aspects of cross-language generalization ability and context reasoning ability are effectively overcome; the method has the advantages that the generalization ability of cross-language vulnerability detection is improved, the false alarm rate and the missing report rate are reduced, and the comprehensive utilization effect of global structure information is enhanced.
Owner:WSGRI SMART CITY(WUHAN) ENGINEERING TECHNOLOGY CO LTD

Intelligent detection method for network security vulnerabilities

The invention discloses an intelligent detection method for network security vulnerabilities, and relates to the technical field of network security vulnerability detection, and the method comprises the following steps: analyzing source codes to construct an abstract syntax tree, a control flow graph and a call graph, identifying sensitive operation points based on a rule base, and screening hotspot functions in combination with code indexes and the call graph; extracting a candidate path from a program entry to a sensitive operation point, encoding to generate a path context snapshot, and scoring through a pre-training model; selecting a high-risk path to execute sparse symbolic execution, simplifying constraints by using variable interval information, and dynamically feeding back and adjusting scores; poC input verification is generated for the path triggering the vulnerability constraint, a report containing the path constraint, the triggering condition and the PoC is output, program analysis and machine learning are combined, the vulnerability detection efficiency and precision are improved, and the method is suitable for code security analysis of scenes such as an embedded system.
Owner:GUANGDONG CABLE RADIO & TELEVISION NETWORK CO LTD

Smart contract vulnerability detection method and system based on taint analysis

ActiveCN120197178APlatform integrity maintainanceControl flow analysisSecurity analysis
The invention relates to the field of vulnerability detection, in particular to an intelligent contract vulnerability detection method and system based on taint analysis, and the method comprises the steps: carrying out the control flow analysis of an EVM byte code of an intelligent contract, and extracting key operation instructions in a control flow diagram and key parameters of each key operation instruction; performing access right control identification on the EVM byte code based on a defined access right control condition, and identifying access right control check and access right control state variables; setting a taint sink based on a key operation instruction and an access authority control state variable, performing taint analysis, generating a constraint condition of a taint flow path through symbolic execution, efficiently and accurately distinguishing expected normal operation in the smart contract from a real security vulnerability, negating the constraint condition to obtain a negative constraint condition, and finally obtaining an access authority control state variable. And negative constraint conditions are further solved, so that the accuracy and reliability of security analysis of the smart contract are remarkably improved, and powerful support is provided for security assurance of the smart contract.
Owner:YANTAI UNIV

Static binary code taint analysis method based on propagation action range

The invention discloses a static binary code taint analysis method based on a propagation action scope, and relates to the field of static binary code taint analysis, and the static binary code taint analysis method comprises the following steps: extracting a program instruction set and a control flow structure based on a disassembling result of a target binary code; calculating a value set with a source of the binary code based on the control flow graph; on the basis of the control flow diagram and the value set with the source, executing cross-function stain propagation analysis, and identifying memory positions or registers influenced by pollution in each function and propagation action ranges of the memory positions or the registers; and extracting all instruction sets using the taint data based on the taint and the propagation action range thereof. According to the method, the false alarm rate of static binary taint analysis can be reduced and the instruction set involved in the taint analysis can be reduced without increasing the analysis overhead, so that the method has important significance in improving the instrumentation efficiency and the operation efficiency of dynamic taint analysis and improving the accuracy of protocol reversion, fuzzy testing and vulnerability mining based on the taint analysis.
Owner:EAST CHINA NORMAL UNIV

Software development system and software development method

The invention relates to the technical field of software development, and discloses a software development system and a software development method. The software development method comprises the following steps: constructing a multi-dimensional technical debt quantitative model, and calculating a technical debt score based on factors such as code complexity, change frequency and defect association degree; a code semantic multi-level representation model is constructed, and multi-level representation of codes is constructed through combined analysis of an abstract syntax tree, a data flow diagram and a control flow diagram; a self-supervised learning model is applied to train code representation, and development intentions and business concepts contained in codes are recognized; generating a context-dependent reconstruction suggestion; and optimizing the reconstruction path planning. Through objective quantification of the technical debt and deep understanding of code semantics, the technical problems that in the prior art, technical debt management is difficult to quantify and reconstruction decision-making lacks scientific basis are solved, code maintenance cost is remarkably reduced, and development efficiency is greatly improved.
Owner:BEIJING CAOMU TECHNOLOGY CO LTD

Binary code similarity detection method and system based on multi-modal feature fusion

The invention provides a binary code similarity detection method and system based on multi-modal feature fusion, and belongs to the technical field of network security. According to the method, a program analysis method is utilized, disassembling codes are extracted from a binary file to serve as text sequence features, and a control flow graph is extracted to serve as topological graph structure features; aiming at two different modes of text sequence features and topological graph structure features, respectively using different representation models to carry out embedding representation; carrying out fusion processing on the embedded representation vectors of different modals by using a multi-modal fusion representation model, and generating a fused embedded representation vector; and based on the fused embedded representation vector, detecting the similarity degree in combination with a vector distance calculation formula, and completing similarity detection according to a preset threshold. According to the invention, the problems of low detection accuracy and weak detection scene generalization ability caused by incomplete use of the feature level of the binary code similarity detection method are solved.
Owner:NAT UNIV OF DEFENSE TECH

Machine learning data security processing and remote proof model protection system and method

The invention discloses a machine learning data security processing and remote proof model protection system and method, and belongs to the field of computer program analysis technology, information security and data service, and the method comprises the steps: combining a Pearson correlation coefficient, an FP-Growth algorithm and cosine similarity to act on discrete data to fill missing values, carrying out the minority group oversampling based on SMOTE, and carrying out the data security processing and remote proof model protection based on SMOTE. And a measurement engine is constructed, and instrumentation is carried out in machine learning model program codes to complete measurement of the modeling process and the modeling result integrity. According to the data security processing and remote proof model protection system and method based on machine learning, a control flow diagram of a static model program code is traversed in a breadth-first search mode to calculate a credible execution process metric value of each sub-process; and comparing each measurement value with the credibility measurement value to verify the measurement result so as to ensure that the code and the result are not tampered in the modeling process.
Owner:BEIJING INFORMATION SCI & TECH UNIV