Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

100 results about "Data-flow analysis" patented technology

Data-flow analysis is a technique for gathering information about the possible set of values calculated at various points in a computer program. A program's control flow graph (CFG) is used to determine those parts of a program to which a particular value assigned to a variable might propagate. The information gathered is often used by compilers when optimizing a program. A canonical example of a data-flow analysis is reaching definitions.

Unmanned aerial vehicle flight control system vulnerability detection method based on data flow analysis and LLM

The invention discloses an unmanned aerial vehicle flight control system vulnerability detection method based on data flow analysis and LLM, and belongs to the technical field of intelligent software testing. Comprising the following steps: extracting a code function module associated with user operation in an unmanned aerial vehicle flight control system through a data flow analysis method, and establishing an operation-code mapping relation library; generating a structured natural language semantic description for each function module code by adopting a large language model LLM, and forming a multi-dimensional semantic feature vector; based on correlation analysis of multi-module semantic features, a combined test scene is constructed, and a natural language test case is generated; the natural language test case is converted into an executable test code through reverse semantic mapping, and coding reconstruction of test logic is completed; and executing a test code and capturing a runtime log in an unmanned aerial vehicle simulation environment, and performing vulnerability feature extraction and root cause positioning by using a large language model. According to the method, the efficiency is improved, and meanwhile, the deep coverage test of a complex interaction scene is supported.
Owner:HUAZHONG UNIV OF SCI & TECH

Large model code security review method based on control flow analysis and retrieval enhancement

The invention relates to the technical field of code security analysis, and discloses a control flow analysis and retrieval enhancement-based large model code security review method, which comprises the following steps of: analyzing an incremental code to generate an abstract syntax tree and data flow analysis information; retrieving local knowledge base association business rules and historical vulnerabilities based on grammatical features, and generating a context enhancement prompt; calling a large language model to jointly analyze codes and contexts, identifying vulnerabilities and outputting a structured report; and combining with a historical false alarm data optimization result and then integrating to a development assembly line. Multi-source information is fused through an RAG technology to enhance semantic understanding, and control flow node tracking and cross-version semantic association are combined, so that the problems of a traditional tool business logic vulnerability detection blind area, incremental code analysis failure and high false alarm rate are solved, synchronous improvement of security examination accuracy and efficiency is realized, and the method is adaptive to an agile development scene.
Owner:HANGZHOU BAIHA YIBAI INFORMATION TECHNOLOGY CO LTD

Automatic program repairing method based on data flow driving

PendingCN120872836AError detection/correctionValidation testData stream
The invention relates to an automatic program repairing method based on data flow driving, which takes an error file and a method signature as input, and reports error information in a defect positioning tool or an integrated development environment. Secondly, handing over error information and original defect codes to a large language model, extracting an element list related to defects from the large language model, then constructing defect contexts, using a search tool to retrieve key element definitions and dependency relationships, integrating control flow and error mode information, and finally obtaining defect information; then, the retrieved information, the original defect codes and the potential defect types are integrated into cue words, and the cue words are submitted to a large language model to generate candidate patches. And then the candidate patch is verified, and if the candidate patch does not pass the verification, error reporting information during the verification is combined with the candidate patch to carry out iterative optimization until the candidate patch successfully passes all test verification or the maximum number of iterations is reached. According to the method, context semantics are enhanced by means of data flow analysis, and the repairing accuracy and efficiency are improved.
Owner:CHONGQING UNIV

Intelligent risk analysis system of financial system

The invention relates to the technical field of intelligent risk analysis, in particular to an intelligent risk analysis system of a financial system. The system comprises a data flow analysis module, a relational graph construction module, an abnormal mode detection module, a security boundary monitoring module, a staged strategy planning module, a scene simulation evaluation module, a decision support module and a comprehensive risk management module. A graph database and a graph convolutional network are utilized to deeply analyze a financial entity relationship, reveal a risk association network, improve abnormal behavior recognition through a K-mean value and an isolated forest algorithm, enhance security boundary monitoring through a random forest algorithm, enable risk threshold adjustment to be more dynamic, combine a decision tree with a genetic algorithm, optimize a risk management strategy, and improve risk management efficiency. The system dynamics and proxy model technology in scene simulation evaluation strengthens risk prediction and increases foresight, principal component analysis and risk matrix evaluation are applied in a comprehensive risk management module, a quantitative analysis tool is provided, and more systematic and comprehensive risk management is realized.
Owner:GUOXING PROJECT CONSULTING CO LTD

Research and development platform language intelligent analysis method based on multi-system fusion

The invention discloses a research and development platform language intelligent analysis method based on multi-system fusion, and relates to the technical field of language intelligent analysis. According to the method, various language data in a multi-system fusion research and development platform are efficiently processed, cleaned and coded to generate a standardized data set by customizing a data adaptation interface, deep lexical and syntactic analysis and semantic role labeling are performed on the standardized data set, related features are extracted, a semantic mapping network is constructed, and semantic feature vectors are generated; cross-modal feature fusion is realized, deep meanings of language data are comprehensively captured, rich feature input is provided for intelligent analysis, a constructed intelligent analysis model can perform accurate intelligent analysis and intention recognition on natural language instructions and technical documents, and the intelligent analysis model can be used for performing intelligent analysis and intention recognition on the technical documents by means of compiling environment simulation, debugging information semantic optimization and the like. The model training effect is improved, and the analysis accuracy and the hardware compatibility are improved through hardware behavior simulation, real-time data flow analysis, user feedback and other modes.
Owner:SOUTHERN POWER GRID DIGITAL GRID RESEARCH INSTITUTE CO LTD

Platform and method for automatically testing and generating kernel export function of operating system

The invention provides an automatic test generation platform and method for an operating system kernel derived function. The method comprises the following steps: (1) intelligent symbol extraction and analysis; (2) generating an LLM-driven test code; (3) performing automatic compiling and virtualization testing; and (4) intelligent error diagnosis and repair. According to the method, the test coverage degree is greatly improved, through the multi-level symbol context extraction technology, single function information is extracted, the dependency relationship of related functions in the same element is analyzed, a function call graph and data flow analysis are constructed, rich context information is provided for LLM, and the problem that traditional manual test case writing is incomplete in coverage is solved.
Owner:HANGZHOU SAIFUNAS TECH CO LTD

Binary translation system and method applied to X86 program

The invention provides a binary translation system applied to an X86 program, which is used for translating a source program following X86 semantics into a target program following other semantics, and comprises a data acquisition module used for acquiring the source program; the disassembling module is used for dividing a source program into a plurality of basic blocks and analyzing subsequent basic blocks corresponding to each basic block; the backward data flow analysis module is used for sequentially analyzing each instruction in each basic block from back to front so as to obtain a target definition set and a target subsequent use set corresponding to each instruction in the source program; and the translation module is used for eliminating redundant instructions of high-order zero clearing or high-order retention of the general register generated in translation. According to the technical scheme, the register state of the general register corresponding to each instruction of the source program is analyzed through the backward data flow analysis module so as to eliminate redundant instructions generated in the translation process.
Owner:INST OF COMPUTING TECH CHINESE ACAD OF SCI

Data center machine room operation and maintenance anomaly detection method based on deep learning

The invention provides a data center machine room operation and maintenance anomaly detection method based on deep learning, and the method comprises the steps: employing a long-short-term memory network to analyze a time sequence for a low-dimensional feature set, capturing a subtle mode in a low-dimensional dynamic feature, and obtaining a behavior mode sequence; extracting a data packet structure and time delay change from the abnormal candidate set, carrying out secondary screening by adopting an isolated forest algorithm, and determining a hidden abnormal behavior set; according to the abnormal mode set, analyzing the real-time data stream by adopting a sliding window mechanism, judging whether the abnormal mode continuously appears or not, and obtaining an abnormal continuity score; according to a final anomaly detection result, updating parameters of the behavior benchmark model, and optimizing the model by adopting an online learning mechanism to obtain an updated behavior benchmark model; and for the updated behavior reference model, circularly executing real-time data flow analysis, and continuously capturing a subtle mode to obtain continuous anomaly detection output.
Owner:FUJIAN GUOKE INFORMATION TECH CO LTD

Large language model analysis and grouping of software requirements to generate test cases for software testing

A system includes processor(s) configured to: receive natural language text describing software requirements for software program; analyze natural language text describing software requirements to identify relationships between different software requirements at least in part by: analyzing how data flows between different software requirements; analyzing how different software requirements influence path and decision points to achieve functionality identified by software requirements; and identifying dependencies between different software requirements; establish sequence for different software requirements based on relationships identified between different software requirements; group plurality of different software requirements together into logical group(s) of software requirements based on sequence for different software requirements and relationships between different software requirements; generate test cases based on logical group(s) of software requirements; execute software program using test cases; and analyze results of execution of software program using test cases to identify any defects in software program.
Owner:HONEYWELL INTERNATIONAL INC

Method and system for detecting login request forgery vulnerability after third-party verification based on data flow analysis

The invention provides a method and a system for detecting a login request forgery vulnerability after third-party verification based on data flow analysis, and belongs to the technical field of network security vulnerability detection. And performing large-scale collection on the applets, constructing a to-be-tested applet data set, performing automatic decryption and unpacking on the wxapkg encrypted packet at the front end of the to-be-tested applet by using an applet front-end code decompilation tool, and obtaining a front-end source code file of the to-be-tested applet. The method comprises the following steps: performing data flow analysis on a front-end source code of each to-be-tested applet by adopting an AST-based data flow analysis method, identifying an API parameter used in a third-party verification login process as a data source, analyzing data flow, modeling client-server interaction to obtain an applet client-server interaction process diagram, and performing data flow analysis on the applet client-server interaction process diagram. And finally, after third-party verification, the login request forgery vulnerability is carried out. According to the method, the login request counterfeiting vulnerability after third-party verification in the applet ecology can be effectively detected.
Owner:NAT UNIV OF DEFENSE TECH

Redundant code identification method and system based on data flow diagram

The invention provides a redundant code identification method and system based on a data flow diagram. The problem that multiple types of redundant codes cannot be comprehensively identified in the prior art is solved. Identifying a waste interface set through set operation processing of an interface access log, a total station scanning result and code warehouse information; performing dynamic call detection and data flow analysis based on a static analysis tool and the abstract syntax tree, and identifying an internal useless code set; identifying and combining a waste script set and a waste consumer set to form a waste component set through state check and log analysis of consumer operation states, script execution records and task scheduling configuration; constructing a whole system call graph to perform reverse reachability analysis, and identifying a cascade waste code set; and finally, generating a complete redundant code report containing statistical data, a detailed list and risk assessment based on the various sets.
Owner:BEIJING YULORE INNOVATION TECH

Multi-language program and data flow analysis using LLM

A computer-implemented system analyzes program and data flows in a software system comprising code written in multiple programming languages using a generative large language model (LLM) directed by programming-language-specific prompts. The LLM identifies functional components within the code, generating labeled graph nodes that include a node type, a node name, and dependency information. A graph construction computer system processes the labeled graph nodes to generate a directed graph, where nodes represent functional components and directed edges represent dependencies. The system stores the graph in a database and provides a web-based interface for visualization, allowing users to explore, query, and analyze program and data flows across the software system. The system enables automated, language-agnostic dependency mapping, facilitating software analysis, debugging, and modernization.
Owner:MORGAN STANLEY SERVICES GROUP INC

Bluetooth low-power-consumption communication optimization method and system of smart watch

The invention provides a Bluetooth low-power-consumption communication optimization method and system for a smart watch, and is applied to the field of communication data processing. The stability of wireless connection between the smart watch and other equipment can be remarkably improved, the problems of interruption and data loss caused by frequent switching of wireless signals are reduced through intelligent signal frequency band switching, data synchronization adjustment and adaptive optimization of application scenes, and in addition, the stability of wireless connection between the smart watch and other equipment is improved. In combination with real-time data flow analysis and signal strength evaluation, the smart watch can more efficiently manage wireless connection and data transmission, and more stable and reliable user experience is provided.
Owner:JIANGXI TIANJI ELECTRONIC TECH CO LTD

Compiler method and apparatus for identifying dynamic single-use producing definitions in programs

A method, apparatus, and system are disclosed. The method includes constructing a static single assignment (SSA) form and a static single use (SSU) form for a program; setting a single-use disqualifying property locally for each SSU version, and propagating the single-use disqualifying property both forward and backward on an SSU graph uniquely formed from the constructed SSU form so it becomes a global property; transferring results from the SSU form to the SSA form to set a single-use property locally for each SSA version based on an occurrence of any use being associated with a disqualifying SSU version; performing data flow analysis on an SSA graph uniquely formed from the constructed SSA form so the single-use property becomes a global property to identify one or more definitions as dynamic single-use for variables in the program; and generating computer-readable instructions for executing the program based on the one or more definitions identified as dynamic single use for the variables in the program, wherein the one or more definitions identified as dynamic single-use has a defined value used exactly one time during execution of the program.
Owner:SAMSUNG ELECTRONICS CO LTD

Financial risk identification system driven by big data

The invention relates to the technical field of risk identification, in particular to a big data driven financial risk identification system, which comprises a time data synchronization module, a multi-dimensional feature mapping module, a financial behavior analysis module and a risk dynamic identification module. According to the method, the financial data flow is synchronized in real time, multi-dimensional scale transformation is applied, and capturing and processing of financial data are optimized, so that more efficient data flow analysis is realized, subtle changes and key forms of time sequence data can be accurately captured in a complex financial environment, and the sensitivity and accuracy of risk identification are greatly improved; refined similarity calculation and behavior recognition help the system to find potential risks earlier and ensure that financial institutions can respond quickly, so that risk events are effectively prevented and reduced, the market with dynamic changes is dealt with, and the rationality of risk management strategy formulation and resource allocation can be remarkably improved.
Owner:LINYI DAIMA BLOCKCHAIN NETWORK TECHNOLOGY CO LTD +1

Java null pointer dereference detection method based on static analysis

The invention discloses a Java null pointer de-reference detection method based on static analysis, which realizes more accurate null pointer anomaly detection through combination of a hierarchical analysis framework and reachability verification. A to-be-detected target program is processed, and an intermediate representation IR and an intra-process control flow graph CFG are obtained; null value data flow analysis and alias analysis in the process are carried out based on the IR and the CFG, and a corresponding data flow result is generated; executing flow insensitive pointer analysis according to a data flow result, dynamically constructing a pointer flow graph of a Java program, spreading null values on the graph, and synchronously generating an interprocess control flow graph; potential null variables are extracted from the PFG, dereferencing statements related to the variables are collected, and a statement sequence which conforms to null value propagation of a control flow is searched on an ICFG graph in combination with a CFL-Reach algorithm; and for different code modes, for different types of statement sequences, performing reachability verification by adopting a rule-driven solver, and outputting a defect detection report.
Owner:NANJING UNIV

Waste code cleaning method and device based on accessibility analysis

The invention relates to the technical field of code classification processing, and discloses a waste code cleaning method and device based on reachability analysis, equipment and a medium, and the method comprises the steps: scanning static codes in a preset program, and collecting and analyzing a dependency relationship and a reference relationship between the static codes; analyzing the reachability of the dependency relationship and the reference relationship between the codes, and determining static codes without the reference relationship; marking the static code without the reference relationship as a waste code according to the reachability analysis result; according to the marked abandoned codes, clearing suggestions and clearing operation steps of the abandoned codes are made, output and displayed. The method can be applied to development of business systems such as financial science and technology, medical treatment, health and pension and the like, waste codes in projects are accurately recognized and cleared through combination of control flow analysis and data flow analysis, and code quality and maintenance efficiency are improved.
Owner:CHINA PING AN LIFE INSURANCE CO LTD

Multi-language program and data flow analysis using LLM

A computer-implemented system analyzes program and data flows in a software system comprising code written in multiple programming languages using a generative large language model (LLM) directed by programming-language-specific prompts. The LLM identifies functional components within the code, generating labeled graph nodes that include a node type, a node name, and dependency information. A graph construction computer system processes the labeled graph nodes to generate a directed graph, where nodes represent functional components and directed edges represent dependencies. The system stores the graph in a database and provides a web-based interface for visualization, allowing users to explore, query, and analyze program and data flows across the software system. The system enables automated, language-agnostic dependency mapping, facilitating software analysis, debugging, and modernization.
Owner:MORGAN STANLEY SERVICES GROUP INC

Application packaging processing method, storage medium and electronic equipment

The invention provides an application packaging processing method, a storage medium and electronic equipment, and is applied to the technical field of software application. According to the method, a full-process closed-loop mechanism of the front stage, the middle stage and the rear stage of packaging is constructed; before packaging, application codes and key parameters are subjected to security detection; in the packaging process, grammar and semantic errors are deeply recognized through a regular engine, an abstract syntax tree and data flow analysis, and a diagnosis report is generated; and after packaging, executing an automatic test by utilizing the matched test case to obtain an application test result. Based on the diagnosis report and the test result, whether repackaging is needed or not is intelligently analyzed, packaging parameters and test cases are adjusted according to the error types and fed back to a safety detection link in a circulating mode, automatic error recognition and self-adaptive optimization are achieved, and therefore the safety and reliability of application packaging are effectively improved, and the development risk is reduced.
Owner:HUNAN HAPPLY SUNSHINE INTERACTIVE ENTERTAINMENT MEDIA CO LTD

Control method and control system of integrated data intelligent platform

The invention relates to the technical field of data intelligence, in particular to a control method and a control system of an integrated data intelligent platform. According to the method, the data link tracking parameter is generated by configuring the data dependency analysis mode and the target parameter, the data node information is acquired, and the personalized dependency parameter is established for each node; the system can perform bidirectional data flow analysis, upward traces a data source and a generation process, and downward identifies a data flow and a use condition; calculating and comparing the target parameters through integrity detection to obtain an integrity difference value; when the difference value exceeds a preset threshold value, a quality monitoring mechanism is triggered, and abnormity is found and positioned in time; according to the abnormal information, node dependency relationship parameters are updated, and the influence range and degree of problem data are evaluated; the accuracy and timeliness of data dependency relationship management are improved, accurate positioning and influence range evaluation of anomalies are achieved, and it is ensured that a dependency relationship analysis result reflects the actual situation of data circulation in time.
Owner:GUANGZHOU ZHONGZHI SOFTWARE DEV CO LTD

Inferring type definitions of user-defined types of variables in application program code

Type definitions of user-defined types in application program code for which definitions are absent (“unknown types”) are inferred. A static analyzer implements two passes of a fixed-point type inference algorithm. Each pass encompasses a plurality of traversals of the application's control flow to build inferred definitions of unknown types until the inferred definitions are maximally built. To build an inferred definition, based on inferring a variable is an unknown type, the static analyzer infers member variables / functions of the unknown type based on contextual information associated with the variable. Type information of unknown types is propagated along control flow paths. After the first pass terminates, unknown types can be assigned known types based on matching of inferred definitions. Inferred definitions of remaining unknown types are incorporated into the application program code. A second pass of type inferencing and data flow analysis are then performed with the inferred definitions incorporated therein.
Owner:VERACODE INC

Memory access security check method for GPU compiler

The invention provides a memory access security checking method for a GPU compiler. The memory access security checking method comprises the following steps: converting a GPU code into a high-level IR instruction; according to metadata information in the high-level IR instruction, extracting a boundary allocated by each memory, and converting the high-level IR instruction into a low-level IR instruction; and based on a range analysis method of a transfer function, in the rear end of the compiler, performing data stream analysis on the low-level IR instruction, calculating a symbolized address range of each memory access, and checking the security of each memory access based on the symbolized range of each memory access and the boundary of each memory allocation. The method for performing memory access security check on the low-level IR language level in the GPU compiler is used for checking the problems of memory cross-border access or buffer overflow and the like which possibly occur after the rear end of the compiler is subjected to multiple optimizations, does not depend on a specific hardware architecture or a specific IR language, and has certain universality.
Owner:WUHAN LINGJIU MICROELECTRONICS CO LTD

Operating system kernel export function automated test generation platform and method

The application provides an operating system kernel export function automatic test generation platform and method, comprising the following steps: (1) intelligent symbol extraction and analysis; (2) LLM driven test code generation; (3) automatic compilation and virtualization test; (4) intelligent error diagnosis and repair. The application greatly improves test coverage. Through multi-level symbol context extraction technology, not only single function information is extracted, but also the dependency relationship of related functions in the same element is analyzed and a function call graph and data flow analysis are constructed, rich context information is provided for LLM, and the problem of incomplete coverage of traditional manual test case writing is solved.
Owner:HANGZHOU SAIFUNAS TECH CO LTD

Static analysis tool test case generation method based on program slicing technology

The invention discloses a static analysis tool test case generation method based on a program slicing technology, which comprises the following steps: step 1) according to a defect report of a static analysis tool, collecting and extracting variable information related to generation of a specific defect in a program as a slicing criterion; 2) through control flow analysis and data flow analysis, recording data and a control dependency relationship between statements, constructing a program dependency graph, and calculating a statement set having a dependency relationship with a slicing criterion; 3) positioning nodes corresponding to the statement set in the abstract syntax tree of the source code through a depth-first search algorithm, and deleting other nodes; the method comprises the following steps of (1) collecting a user-defined type or an external function declaration which is used through static program analysis, and outputting the type definition and the function declaration to an independent header file, and (5) writing edited codes into a file, and clearing redundant information to serve as a test case, the method adopts two-section analysis, and the test case can be generated efficiently and precisely.
Owner:NANJING UNIV

Aviation safety-oriented evidence-driven large language model MISRA C rule review method and system

The invention provides an evidence-driven large language model MISRA C rule review method and system for aviation safety. According to the method, formalized feature extraction is carried out from four aspects of grammar structure features, semantic structure features, logic analysis features and preprocessing behavior features for target codes according to various rules of MISRA C forcing class rules, and diagnosis information is diagnosed in combination with an industrial-grade compiler; generating a structured evidence set comprising abstract syntax tree node statistical features, code context structure features, control flow graph features, function internal data flow analysis features, symbol and type table features and macro definition analysis features; and based on the structured evidence set and the large language model, executing evidence tracing, rule matching and logical reasoning according to a preset thinking chain process, and outputting a structured judgment result containing illegal rule numbers, evidence description and code positions. According to the method, the false alarm rate can be remarkably reduced while the high rule coverage rate and the detection accuracy are kept.
Owner:NANJING UNIV OF AERONAUTICS & ASTRONAUTICS

A C / C++ post-release reference dynamic detection method based on pointer dereference instrumentation

The application discloses a C / C++ post-release re-reference dynamic detection method based on pointer dereference insertion, and when software testing is performed, a traditional Address Sanitizer cannot detect logical errors of address legality; the application realizes dynamic detection of pointer reuse memory errors through data flow analysis and insertion of GetElementPtr instructions.
Owner:ZHEJIANG UNIV

Method and system to perform interval analysis in source code using functional approach

This disclosure relates generally to method and system to perform interval analysis in source code using functional approach. The method performs data-flow analysis using functional approach to solve infinite-height analyses and properties are validated such as array index within bounds, non-zero division, and preventing arithmetic overflow or underflow on real-life applications. The method receives source code comprising one or more functions to perform a whole program interval analysis over each function using a functional approach to identify range interval of each variable at every program point in the source code. Further, summary for each function is computed which is stored in the form of variable and its corresponding range interval at every exit point of each function. Finally, an incremental interval analysis is performed over each function having edited version change and summary is recomputed for each function impacted by change to optimize overall interval analysis.
Owner:TATA CONSULTANCY SERVICES LTD

Power software vulnerability automatic repairing method and device based on semantic enhancement and storage medium

The application discloses a kind of based on semantic enhancement's electric power software vulnerability automatic repair method, device and storage medium, the method includes: obtaining the historical source code of target software;According to the abstract syntax tree of preprocessed source code;Based on abstract syntax tree, data flow analysis is carried out to preprocessed source code to construct data propagation chain;The weight score of key symbol is calculated to each function level code segment in preprocessed source code and it is injected as semantic enhancement information into the attention mechanism of model;Additional multilayer perception machine classifier is introduced in the output end of the encoder of model;Preprocessed source code and data propagation chain are input into encoder, and the output of encoder is respectively input into multilayer perception machine classifier and decoder;The decoder generates repair patch according to the output of encoder and multilayer perception machine classifier.The application reduces the computing overhead while ensuring the repair effect, realizes the efficient, accurate and automatic repair of electric power software system vulnerability.
Owner:SOUTH CHINA UNIV OF TECH

Binary program dynamic analysis method based on process hollowing-out technology

The invention discloses a binary program dynamic analysis method based on a process hollowing-out technology, which further expands the fine-grained analysis capability of a traditional binary dynamic instrumentation tool by utilizing a system kernel module, constructs a brand new fine-grained analysis environment in a new hollowing-out process by combining with a code decoupling analysis thought, and improves the fine-grained analysis efficiency. The influence on target program execution can be reduced, the binary analysis application range and the analysis reliability are improved, and the function of an application layer dynamic instrumentation tool can be reused. According to the method, a more flexible and efficient analysis function is realized by utilizing the characteristics of an operating system, a hollow process environment and an analysis task construction method are provided, and fine-grained data flow analysis of special binary programs such as vulnerability utilization programs and antagonistic rogue programs can be realized. According to the method, the application range of automatic analysis of the binary program can be effectively expanded, the complexity of memory management analysis is simplified, and the performance and stability of dynamic analysis for binary codes are improved.
Owner:NANJING UNIV OF POSTS & TELECOMM

Automated Security Vulnerability Detection Method, System, Electronic Device and Readable Storage Medium for Multiple Types of Scripts in Embedded Systems

The present invention provides an automated security vulnerability detection method, system, electronic device and readable storage medium for multiple types of scripts in an embedded system. The method includes: unpacking and analyzing the firmware of the embedded system to be detected to identify script files and template files; identifying the dependency relationships between the script files and the template files, as well as the interactions and dependency relationships between different types of the script files, marking sensitive input source points and potential vulnerability sink points, and generating a control flow graph and an abstract syntax tree by using a context-sensitive control flow analysis algorithm; constructing a power set lattice according to the assignment statements in the control flow graph and performing data flow analysis by using a fixed-point algorithm to obtain data flow constraint relationships; and performing taint analysis to identify all dangerous execution paths. The present invention can automatically identify script security vulnerabilities, improve the security of the embedded system during script execution, and effectively prevent potential security threats.
Owner:SHANGHAI JIAOTONG UNIV