The invention discloses a cross-language application program
vulnerability mining method based on
static analysis, which adopts a nested cross-
programming language
pointer analysis method and a micro-service cross-
programming language taint tracking method to effectively solve the limitation of
processing nested cross-language
control flow and micro-service cross-language data flow. A nested language semantic boundary is accurately positioned by constructing a nested
byte code, and a
data stream is completely tracked by utilizing an interface
relay technology, so that the detection precision is improved. According to the method, part of multi-end data streams and complex control streams of cross-
programming language applications can be uniformly processed, and the analysis process in a cross-
programming language environment is simplified; by nesting cross-
programming language control flow diagram construction and double-end / multi-end
data flow diagram construction, a unified analysis framework is constructed, seamless cooperation of
static analysis among different languages is achieved, the analysis cost is reduced, the analysis efficiency is improved, efficient and accurate
vulnerability mining is achieved in a complex cross-
programming language application program, and the method is suitable for application and popularization. And the reliability of cross-language
vulnerability detection is improved.