Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

32 results about "Security analysis" patented technology

Security analysis is the analysis of tradeable financial instruments called securities. It deals with finding the proper value of individual securities (i.e., stocks and bonds). These are usually classified into debt securities, equities, or some hybrid of the two. Tradeable credit derivatives are also securities. Commodities or futures contracts are not securities. They are distinguished from securities by the fact that their performance is not dependent on the management or activities of an outside or third party. Options on these contracts are however considered securities, since performance is now dependent on the activities of a third party. The definition of what is and what is not a security comes directly from the language of a United States Supreme Court decision in the case of SEC v. W. J. Howey Co.. Security analysis is typically divided into fundamental analysis, which relies upon the examination of fundamental business factors such as financial statements, and technical analysis, which focuses upon price trends and momentum. Quantitative analysis may use indicators from both areas.

Security analysis method for post-quantum NTRU cryptographic algorithm

The invention provides a security analysis method for a post-quantum NTRU cryptographic algorithm, and the method comprises the steps: an attacker carries out the sampling of a public key, and obtains a public key sample, different private keys g with a public Hamming weight, and a fixed target private key; according to each public key sample and information disclosed by the Hamming weight of the private key, establishing a modular equation, and solving the modular equation by combining a linear technology and a preset initial value; obtaining a complete value of the second polynomial based on a linear relation between the equation set solution and other parts except the constant term in the second polynomial and a linear relation between a preset initial value and the constant term of the second polynomial; and according to the public key sample and the complete value of the second polynomial, utilizing a GS algorithm to obtain a speculative value of the target private key, and according to the relationship between the speculative value and the actual value of the target private key, carrying out security analysis on the password security system. The private key is recovered by using the relation between the solution of the modular equation and the private key, and the bottleneck of the existing technical means is broken through.
Owner:HUBEI UNIV +1

Cooperative generation method of inspection and detection report based on alliance chain

The invention discloses an alliance chain-based inspection and detection report collaborative generation method. The method comprises six algorithms: an initialization algorithm, a user registration algorithm, a report generation algorithm, a report consensus uplink algorithm, a report query algorithm and a penetrating supervision algorithm. According to the invention, efficient cooperation among multiple inspection and detection mechanisms is realized, the reliability of inspection and detection reports is ensured, penetrating supervision is realized, and hierarchical access to the inspection and detection reports is supported. Therefore, on the premise of ensuring data security and privacy protection, the availability of the report is improved, security analysis verifies that the scheme has penetrating supervision, report confidentiality and report reliability of unauthorized users and the like, and performance analysis shows that the scheme has relatively low calculation and communication overhead.
Owner:HUZHOU UNIVERSITY

Software development-oriented security processing method and device, equipment and medium

The invention relates to the technical field of data security, can be applied to business scenes of financial science and technology, medical health and the like, and discloses a security processing method, device and equipment oriented to software development and a medium. Obtaining an architecture design document to identify potential safety hazards and generate design improvement suggestions; generating a code based on the business logic description and the design improvement suggestion, and completing security detection and repair to obtain a processed code and a code repair record; performing security test on the processed code and recording a test result; collecting data of exception identification, hidden danger identification, code detection and repair and security test to update the security knowledge base; and generating a security analysis report based on the demand exception list, the design improvement suggestion, the code repair record and the test result. According to the invention, through a security identification and restoration process from demand to test, early discovery of security problems, linkage processing and knowledge self-updating are realized.
Owner:PING AN TECH (SHENZHEN) CO LTD

Security analysis method based on SelfTargetSIS problem

PendingCN121907424ACryptographic attack countermeasuresRandom oracleQuantum modeling
The invention provides a safety analysis method based on a SelfTargetSIS problem. The method comprises the following steps: modeling a solution target of the SelfTargetSIS problem into explicit search on a message set, an allowable vector set and a challenge vector set; estimating a first search complexity in the classic model under a random oracle model; estimating a second search complexity in the quantum model under a random oracle model; and determining the minimum value of the first search complexity and the known classical optimal attack complexity as the effective attack complexity under the classical model, and determining the minimum value of the second search complexity and the known quantum optimal attack complexity as the effective attack complexity under the quantum model, thereby performing security evaluation on the anti-quantum signature. According to the method, an explicit search path based on a message set, an allowable vector set and a challenge vector set is supplemented and quantified, and the attack cost in the real world can be reflected more comprehensively.
Owner:INST OF SOFTWARE - CHINESE ACAD OF SCI

Routing protocol security analysis method and device, equipment and storage medium

ActiveCN116017466BPathPingAttack
The application discloses a routing protocol analysis method and device, equipment and a storage medium. After obtaining a routing protocol to be analyzed, an attack point in the routing protocol to be analyzed is identified, the attack point is an attack purpose of an attacker, the path of the attack to be performed by the attacker to achieve the attack purpose is reversely searched in the routing protocol to be analyzed starting from the attack purpose of the attacker, a detection rule is generated for the attack path, and the routing protocol to be analyzed is analyzed based on the generated detection rule. The attack path is obtained by comprehensively searching in the routing protocol to be analyzed starting from the attack point. The detection rule is obtained by analyzing the attack path. The routing protocol is analyzed according to the detection rule. The possible vulnerabilities in the routing protocol can be comprehensively analyzed.
Owner:AGRICULTURAL BANK OF CHINA

Software security analysis

Systems and methods are disclosed for software security analysis. In certain embodiments, a method may comprise identifying a set of potential security vulnerabilities, comparing the potential vulnerabilities to a catalog identifying elements on a client system, and generating risk mitigation advice based on potential security vulnerabilities matching an element in the catalog. The method may include evaluating a data field of a service request to a third party to determine an expected data type for the field, determining whether the actual data included in the service request matches the expected data type, and quarantining the service request when the actual data does not match the expected data type. The method may comprise operating as a proxy for the service request, including receiving the service request from the client system, evaluating the service request for irregularities, and forwarding the service request to the third party once the irregularities have been addressed.
Owner:APILYZE INC

A blockchain-based fair commodity transaction privacy protection method

The application discloses a fair commodity transaction privacy protection method based on a blockchain, which comprises the following steps: system initialization; a buyer publishes a payment transaction; a miner verifies the transaction and executes a payment function of a contract if the transaction is passed, or ends the process; the buyer publishes a payment proof transaction; a seller verifies a verifiable encryption signature and publishes a delivery transaction if the encryption signature is passed, or ends the process; the buyer publishes a redemption proof transaction; the seller publishes a redemption transaction; and the miner verifies the transaction and executes a redemption function of the contract if the transaction is passed. The method realizes the comprehensive protection of the identities, account balances, transaction amounts and transaction contents of the two parties of the transaction by using blind signature, verifiable encryption signature, homomorphic encryption, range proof and zero-knowledge proof technology to protect the transaction privacy and ensure the fairness of the transaction while recording the transaction information through the blockchain and the smart contract. Through security analysis, the method meets the effectiveness, time limit, fairness, anonymity, confidentiality and balance.
Owner:SOUTHWEST JIAOTONG UNIV

Intelligent contract reusable component use logic compliance detection method and system

The invention provides an intelligent contract reusable component use logic compliance detection method and system, and belongs to the technical field of intelligent contract reusable component safety analysis. Inputting an intelligent contract source code and carrying out preprocessing operation; constructing a multi-dimensional smart contract feature analyzer, generating a multi-dimensional smart contract feature graph representation, and further extracting a use case of a reusable component of the smart contract and a core feature of the use case; a use logic compliance review model is generated based on large model retrieval enhancement, and potential use logic non-compliance use cases are identified; a large model illusion suppression engine based on snapshot conflicts is constructed, large model illusion is suppressed, and potential use logic non-compliance use cases after illusion suppression are obtained; constructing a verification engine based on similarity analysis, and carrying out secondary verification on the potential non-compliance use cases; and outputting a detection report of the use logic compliance of the reusable component in the current smart contract, thereby realizing automatic detection of the use logic compliance of the reusable component in the smart contract.
Owner:ZHEJIANG UNIV

Theoretical security analysis method of lattice PKE / KEM scheme based on compressed public key design

The present invention proposes a theoretical security analysis method for a lattice-based PKE / KEM scheme based on a compressed public key design, comprising the following steps: obtaining a key encapsulation scheme; utilizing the properties of a discrete Gaussian distribution to decompose e into two parts, e1 and e2, and then re-expressing the parameters as #imgabs0#; expressing #imgabs1# and #imgabs2# as #imgabs3#, wherein #imgabs4# is taken from an appropriate distribution; utilizing the properties of the discrete Gaussian distribution to decompose a secret #imgabs5# into a secret #imgabs6# and a redundant part #imgabs7# of a standard modulus LWE problem; and then rewriting the sample form as #imgabs8#; utilizing the standard modulus LWE problem corresponding to #imgabs9# to evaluate the theoretical difficulty lower bound of the corresponding problem, and then evaluating the security strength lower bound of the KEM scheme; and selecting specific parameters of the key encapsulation scheme for a required security strength λ according to the computational complexity of the standard modulus LWE problem corresponding to #imgabs10#.
Owner:SHANDONG UNIV

Machine learning-based virtual currency transmission and sale identification method based on complex network

The invention discloses a virtual transmitted currency identification method based on machine learning based on a complex network, and belongs to the technical field of block chain security analysis and financial anti-fraud. Comprising the steps of task creation and data preparation, primary data search and key address mining, graph network construction and feature engineering, deep data search and transaction detail analysis, involved feature monitoring, contract address feature monitoring, model training and optimization, and result display and decision support. According to the method, multi-level fund flow and transaction relations are deeply analyzed, key nodes and abnormal transactions in virtual currency sales activities are automatically identified, the discovery and early warning efficiency of illegal sales activities is remarkably improved, and the problem that information sources are insufficient in traditional monitoring is solved.
Owner:GUIZHOU SHENGCHI DIGITAL IND TECHNOLOGY CO LTD

A system security analysis method, system, and device

The application discloses a kind of system security analysis method, system and equipment, method includes: system task is decomposed, each subtask is determined as the functional unit of the system;The performance of each functional unit is evaluated using time and precision, the output variability score of each functional unit is obtained by introducing expert score, then the potential coupling of each functional unit performance change is analyzed, and the functional coupling variability score of each functional unit is obtained in combination with the output variability score;Threshold value of functional coupling variability score is set, when exceeding the threshold value of functional coupling variability score, system will occur functional resonance, so as to identify the key functional unit in system, and set barrier for the key functional unit to prevent potential accidents from happening.The application fuses subjective and objective factors to analyze the safety of system, solves the technical problems that cannot give quantitative analysis results due to excessive dependence on expert subjective evaluation, and lacks theory or process to construct functional resonance.
Owner:CHINA STATE SHIPBUILDING CORP LTD RESEARCH INSTITUTE 719

Security analysis method and system for virtual shuffling aiming at misuse of bit slices

The invention relates to the technical field of security evaluation of encryption algorithms, and provides a virtual shuffling security analysis method and system for bit slice misuse, and the method comprises the steps: creating a counter array which comprises a plurality of elements, and the index of each element corresponds to the value of a candidate key; for virtual shuffling, collecting a plurality of groups of tracks, screening out effective tracks for each track group, and if the number of the effective tracks is smaller than a threshold value, discarding the track group; performing LDA operation on the reserved track group to obtain a recommended key set, and for each candidate key in the recommended key set, adding one to the value of the index position of the corresponding counter array; and after all the track groups are processed, traversing the counter array, finding out the key with the highest count as a correct key, counting the count of the correct key, and obtaining the actual recommendation frequency of the correct key. And the risk of misuse of bit slice virtual shuffling in IF-ELSE implementation can be efficiently identified.
Owner:SHANDONG UNIV

Automatic detection method, system and computing device for malicious code in smart contracts

The present invention discloses a method, system and computing device for automatic detection of malicious code for smart contracts, relates to the field of security analysis technology, and solves the technical problem that the prior art has the risk of omitting key execution states, thereby causing underreporting of malicious code detection; the present invention generates an abstract syntax tree by parsing source code; traverses and identifies all types of address variables in the abstract syntax tree, marks them as address variable sets and classifies them; calls the initial state and builds a symbolic execution engine with a buffer pool, and uses the initial state as input to output a matrix through the symbolic execution engine; builds and initializes a result deviation table based on the output matrix; updates the result deviation table according to a symbol replacer and generates a deviation function queue; iteratively analyzes the result deviation based on the deviation function queue to obtain a final deviation variable set; and judges whether the corresponding smart contract is malicious based on the final deviation variable set; the present invention covers a wider range of malicious contract codes.
Owner:ANHUI UNIV

Automatic reasoning method and system for use specifications of reusable components of smart contracts

The invention provides an automatic reasoning method and system for use specifications of a reusable component of a smart contract, and belongs to the technical field of security analysis of the reusable component of the smart contract. An automatic crawling framework is used for collecting source codes of reusable components of mainstream smart contracts to be analyzed and document information of the reusable components of the mainstream smart contracts to be analyzed. And the crawled information of the reusable component of the smart contract is processed by using the task planning intermediate, and the planning of the reusable component use specification automatic analysis working process is completed according to a two-layer planning principle of'process task-subtask '. And constructing and using an intelligent analysis model oriented to reusable component code semantic understanding to process the code understanding class subtasks. And constructing and using a contract analysis tool set to process the program analysis class subtasks. And constructing and using an auxiliary tool set to process the message conversion type subtasks. And integrating the analysis result of each process task, and outputting a usage specification report of the reusable component of the smart contract, thereby realizing efficient and accurate automatic reasoning of usage specification information of the reusable component of the smart contract.
Owner:ZHEJIANG UNIV

Security analysis of diverse identity provider and single sign-on configurations

PendingUS20260052165A1Securing communicationIdentity providerSecurity analysis
The present application relates to devices and components including apparatus, systems, and methods to perform risk analysis of authentication systems and presenting results of the risk analysis. The approaches can transform configuration data indicating authentication operations to a data format representation for performing risk analysis of the authentication systems.
Owner:BEYOND IDENTITY INC

Method, system, medium and equipment for prime power RSA (Rivest-Shamir Adleman) modulus decomposition

The invention discloses a prime power RSA modulus decomposition method and system, a medium and equipment, and the method comprises the following steps: obtaining a value through the information of a part of high bits leaked by a private key, a prime power RSA modulus and a small public key index; recovering partial information of the prime number by using the obtained information, specifically comprising the following steps: constructing a modular equation to solve the value of the prime number; the method comprises the following steps: constructing two functions, and approaching a prime number in a binary search mode by using a size relationship of function values to obtain high bit information of a prime number part; constructing a first-order modular equation by using part of information of the recovered prime number, and recovering a complete prime number in combination with a Appersmith algorithm; and decomposing by using prime numbers and moduli. According to the method, less private key bit information is utilized, and modulus decomposition is completed, so that security analysis of the prime power RSA cryptographic algorithm is realized.
Owner:HUBEI UNIV

A security analysis method for a post-quantum NTRU cryptographic algorithm

The application provides a security analysis method for a post-quantum NTRU cryptographic algorithm, which comprises the following steps: an attacker samples a public key to obtain a plurality of public key samples, a different private key g with a Hamming weight open to the public, and a fixed target private key; a modular equation is established according to each public key sample and the private key Hamming weight open-to-the-public information, and the plurality of modular equations are solved in combination with a linear technique and a preset initial value; based on a linear relationship between the equation set solution and the rest of a second polynomial except for a constant term and a linear relationship between the preset initial value and the constant term of the second polynomial, a complete value of the second polynomial is obtained; a guess value of the target private key is obtained by using a GS algorithm according to the public key sample and the complete value of the second polynomial, and a security analysis is performed on a cryptographic security system according to a relationship between the guess value and an actual value of the target private key. The application restores the private key by using the relationship between the solution of the modular equation and the private key, and breaks through the bottleneck of the prior art means.
Owner:HUBEI UNIV +1

Facilitating automated security analysis

PendingDE102025142773A1Semantic analysisReverse engineeringSecurity analysisDatabase
Various examples reveal systems and procedures related to facilitating automated security analysis. Specifically, a security analysis can be performed on a software product or a part thereof to identify potential security risks associated with the product. To perform code security data analysis, various types of code security data can be analyzed for a comprehensive analysis of any potential security risks associated with a product. For example, different phases of product development can be analyzed to enable the prevention of security breaches. During implementation, design analysis, design-to-code analysis, and / or code analysis can be performed to identify potential security risks.Performing such diverse analyses enables a robust and comprehensive safety assessment of a product from design to implementation.
Owner:NVIDIA CORP

LWE problem solving method combined with leaked information in post quantum cryptography environment and security analysis method and device

The invention provides an LWE problem solving method in combination with leaked information in a post quantum cryptography environment, and a security analysis method and device. The solving method comprises the following steps: aiming at a to-be-analyzed cryptographic system, constructing an LWE instance about the cryptographic system; extracting leakage information of the password system by adopting a side channel analysis technology and formally representing the leakage information as prompt information; constructing a first lattice basis matrix and a corresponding transformation matrix according to the prompt information; and fusing the LWE instance with the first lattice basis matrix and the transformation matrix to construct a second lattice basis matrix, carrying out lattice basis reduction on the generated lattice, obtaining a short vector, verifying whether the short vector is a private key of the cryptographic system, and if not, continuing to carry out lattice basis reduction on the lattice generated by the second lattice basis matrix. According to the method, LLL reduction is replaced by regular calculation, so that the operation speed is increased; in the LWE solving stage, batch processing of different quantities and types of prompt information is realized, flexible adjustment of the used LWE sampling quantity is supported, and the problem calculation efficiency is improved.
Owner:Chinese People's Liberation Army Cyberspace Force Information Engineering University

Intelligent contract security analysis method and system based on neighbor contrast learning

The invention discloses an intelligent contract security analysis method and system based on neighbor contrast learning, and the method comprises the steps: firstly carrying out the function-level slicing of an intelligent contract source code, recognizing a key node, a common node and a rollback node based on a rule, and constructing a contract graph fusing the grammar and multi-dimensional semantic relation; for the problems of graph sparsity and noise, a neighbor node set is updated through semantic feature similarity and a graph topology distance, feature aggregation is carried out by adopting a graph attention network fused with a dynamic edge semantic correction mechanism, and an edge semantic scoring network synthesizes edge features, node similarity and global context to generate a dynamic edge weight so as to correct attention. And finally, training a classification model by using a total loss function fusing neighbor contrast learning loss and classification loss. According to the method, through the synergistic effect of node distinguishing, double-neighbor contrast learning and dynamic edge correction, the data sparsity is effectively relieved, noise interference is inhibited, a key path is amplified, and the accuracy, robustness and generalization ability of vulnerability detection are remarkably improved.
Owner:JIANGSU UNIV

Fault transmission analysis method based on functional physical mapping model

The invention provides a fault transmission analysis method based on a functional physical mapping model, and belongs to the technical field of complex system safety analysis, and the method comprises the following steps: S1, carrying out the preparation before modeling; s2, creating a functional physical mapping model of the system; and S3, carrying out security analysis on the functional physical mapping model. By adopting the fault transmission analysis method based on the functional physical mapping model, the problem of repeated modeling work caused by separation of functional modeling and physical modeling is solved, a method for associating a system function with a physical architecture is provided, the efficiency of safety analysis work based on the model is improved, and the method is suitable for popularization and application. And the integrity and accuracy of hardware fault identification are ensured.
Owner:TIANHANG CHANGYING (JIANGSU) TECH CO LTD

Intelligent task management system and operation method thereof

The invention provides an intelligent task management system and an operation method thereof, and the system comprises a task scheduling center which is used for receiving a collection task submitted by a user, and obtaining the task data of the collection task through a collection engine; the task analysis module is used for performing security analysis on the task data and processing a security analysis result according to a preset processing strategy to obtain a task processing result; the security analysis comprises sensitive information identification and compliance check, and the disposal strategy comprises abnormal data interception, data desensitization, data annotation and manual auditing; and the management module is used for executing query, configuration and monitoring operations on the collection task according to a management instruction input by the user, the security analysis result and the task processing result, and generating a management report. According to the system and the operation method thereof, the safety of data acquisition is improved, and the data management efficiency is improved.
Owner:WUHAN HONGXU INFORMATION TECH

Dynamically generating operational technology asset groupings for health and security analysis

Systems, methods, and apparatus are disclosed for analyzing Operational Technology (OT) networks. A cyber security appliance includes an OT module to receive data from a plurality of OT assets. An asset identification module passively monitors data to identify asset properties and generate a human-readable label for each OT asset. One or more machine-learning models are trained on a normal pattern of life for the plurality of OT assets. A comparator module compares network data to the normal pattern of life to detect anomalous activity, distinguishing between cyber threats and operational health issues, such as an absence of expected communication, and generates distinct alerts for each. An architecture generation module uses the labels to apply a grouping, such as by shared characteristic or user-defined filter, creating one or more asset groupings and generating visualization data for presentation on a display.
Owner:DARKTRACE HLDG LTD

Security degree analysis method for water supply system

PendingCN120471289AResourcesSecurity indexSecurity analysis
The invention discloses a guarantee degree analysis method for a water supply system, the water supply system is a system formed by a forebay and a water delivery pump group, the method comprises the following steps: collecting the water inflow of the forebay and the performance parameters of a plurality of water delivery pumps for measuring the availability of the water delivery pumps in real time, the performance parameters at least comprising the water delivery amount and the power; according to the water inflow and the performance parameters collected in real time, instantaneous supportability is obtained, and according to the water inflow and the performance parameters in the historical time window, theoretical supportability is obtained; and according to the instantaneous supportability and the theoretical supportability, obtaining a comprehensive supportability index for judging the guarantee degree. Through a plurality of parameters acquired in real time, the one-sidedness problem that the prior art depends on a single index is solved. Theoretical supportability is calculated in combination with data in a historical time window, future risks are predicted, and real-time disjunction with historical data is avoided. By integrating the instantaneous supportability and the theoretical supportability, a comprehensive supportability index considering the real-time state and the long-term trend is formed, and misjudgment is effectively reduced.
Owner:INSPUR GENERSOFT CO LTD

Security analysis method and device for RSA variant cryptographic algorithm and storage medium

The invention provides a security analysis method for an RSA variant cryptographic algorithm, attack on the variant cryptographic algorithm is realized by using leaked high bit and low bit information of a private key and a Appersmith algorithm, the leaked private key information can be effectively utilized, the prior art is broken through, and bit information required for attack is reduced. In addition, the invention also provides a security analysis device for the RSA variant cryptographic algorithm and a storage medium.
Owner:HUBEI UNIV

Malicious code automatic detection method and system for smart contract, and computing device

The invention discloses an automatic malicious code detection method and system for a smart contract, and a computing device, relates to the technical field of security analysis, and solves the technical problem of malicious code detection missing report caused by the risk of missing a key execution state in the prior art. According to the method, source codes are analyzed to generate an abstract syntax tree; traversing and identifying all types of address variables in the abstract syntax tree, marking the address variables as an address variable set, and classifying the address variables; calling the initial state, constructing a symbolic execution engine with a cache pool, and outputting a matrix through the symbolic execution engine by taking the initial state as input; constructing and initializing a result deviation table based on the output matrix; updating the result deviation table according to the symbol displacer and generating a deviation function queue; performing iterative analysis on the result deviation based on the deviation function queue to obtain a final deviation variable set; judging whether the corresponding smart contract is malicious or not according to the final deviation variable set; according to the method, malicious contract codes in a larger range are covered.
Owner:ANHUI UNIV

Systems and methods for software security analysis

ActiveUS12462041B2Platform integrity maintainanceSecurity analysisData science
A security analysis of software includes analyzing security risks at each level of the hierarchy of the software and aggregating identified risks within the hierarchy levels. Weights applied during aggregation assist in homogenizing risk scores originating from different types of identified security risks and provide for the ability to communicate a meaningful risk score at each level of the hierarchy.
Owner:CODELOGIC INC

Systems and methods for software security analysis

PendingUS20260147899A1Platform integrity maintainanceSecurity analysisData science
A security analysis of software includes analyzing security risks at each level of the hierarchy of the software and aggregating identified risks within the hierarchy levels. Weights applied during aggregation assist in homogenizing risk scores originating from different types of identified security risks and provide for the ability to communicate a meaningful risk score at each level of the hierarchy.
Owner:CODELOGIC INC

Safety analysis method for fully homomorphic encryption

The invention discloses a fully homomorphic encryption-oriented security analysis method, which belongs to the technical field of information security, and comprises the following steps of: receiving an input parameter, and judging whether a current problem type is an LWE problem or a ring LWE problem; based on the input parameters, a computational complexity function model is established to derive an explicit expression of the optimal guess dimension, and the computational complexity function model is used for representing the total attack overhead of an attacker under the guess dimension; determining an optimal guess dimension by using the display expression, and determining the size of a minimum integer block according to the optimal guess dimension and the current problem type; and calculating the security strength according to the optimal guess dimension and the size of the minimum integer block. According to the method and the device, the optimal guess dimension is expressed in a displayed manner, so that time-consuming exhaustive search in the prior art is avoided, automatic output from parameter input to safety intensity is realized, and the evaluation speed of the safety intensity is greatly improved.
Owner:XIDIAN UNIV

Smart contract vulnerability detection method and system based on taint analysis

ActiveCN120197178BPlatform integrity maintainanceControl flow analysisSecurity analysis
The present application relates to the field of vulnerability detection, in particular to a smart contract vulnerability detection method and system based on taint analysis, control flow analysis is performed on the EVM bytecode of the smart contract, key operation instructions in the control flow graph and key parameters of each key operation instruction are extracted; based on the defined access permission control condition, the access permission control of the EVM bytecode is identified, and the access permission control check and the access permission control state variable are identified; then based on the key operation instruction, the access permission control state variable sets the taint sink, carries out the taint analysis, generates the constraint condition of the taint flow path through the symbolic execution, efficiently and accurately distinguishes the expected normal operation in the smart contract from the real security vulnerability, takes the inverse of the constraint condition to obtain the negative constraint condition, further solves the negative constraint condition, significantly improves the accuracy and reliability of the smart contract security analysis, and provides strong support for the security protection of the smart contract.
Owner:YANTAI UNIV