The application provides a binary security patch detection method and
system,
electronic equipment and storage medium, and relates to the technical field of
network security.The application can effectively reduce the differential
noise introduced by variable renaming,
compiler optimization and other factors by
processing the
pseudo code of the binary program through the iterative variable mapping and differential alignment
algorithm, generate the high-quality
pseudo code differential text after alignment, and provide clear and accurate input basis for subsequent
security analysis;Further, through the large
language model agent analysis mechanism, the program
semantic information across functions and processes can be intelligently identified and utilized, the security
impact of the patch is deeply reasoned, and finally the accurate detection and judgment of the binary security patch are realized.The application provides a security patch detection scheme which does not depend on the
source code, can effectively process the binary program difference
noise, and can comprehensively utilize the context information for accurate judgment.