Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

99 results about "Symbolic execution" patented technology

In computer science, symbolic execution (also symbolic evaluation) is a means of analyzing a program to determine what inputs cause each part of a program to execute. An interpreter follows the program, assuming symbolic values for inputs rather than obtaining actual inputs as normal execution of the program would, a case of abstract interpretation. It thus arrives at expressions in terms of those symbols for expressions and variables in the program, and constraints in terms of those symbols for the possible outcomes of each conditional branch.

Symbolic EEG-Driven Cognitive Routing Kernel (S-ECRK)

A symbolic neuroadaptive control system is disclosed for real-time arbitration, consent, and ethical modulation of artificial intelligence agents operating in wearable computing environments. The system integrates multimodal biometric telemetry—including high-resolution EEG signals—with a symbolic kernel that performs logic-driven arbitration over cognitive, emotional, and ethical states. Using Coq-verified invariants and zero-knowledge biometric consent tokens, the system constructs a deterministic symbolic execution graph, gating AI outputs based on internal user states such as trauma, stress, or intentionality. Unlike conventional black-box BCI models, the invention routes EEG-inferred affective-symbolic tokens through a formal ethics layer that enforces real-time interrupt control, utility bounding, and trust verification. The kernel enables AGI systems to defer or modify behavior based on user-state alignment, granting sovereign agency over all downstream actions. This neuro-symbolic architecture redefines the interface between human cognition and intelligent machines, enabling emotionally conscious, morally verifiable, and symbolically transparent AI governance in dynamic, high-stakes contexts.The present invention relates to artificial intelligence and neurotechnology, specifically to a real-time, neuro-symbolic operating system kernel that converts electroencephalography (EEG) signals into structured symbolic data for use in emotional cognition, ethical prioritization, autonomous agent dispatch, and real-time telecommunications routing. The invention bridges brain-computer interface (BCI) inputs with symbolic AI architectures to enable ethically aligned machine response during cognitively or emotionally intense events.
Owner:ODEH SAMUEL

Automatic code auditing method and device, computer equipment and storage medium

The invention relates to an automatic code auditing method and device, computer equipment and a storage medium. The automatic code auditing method comprises the steps of obtaining a grammar structure, a control flow and a data flow of a to-be-audited code; constructing a context graph of the to-be-audited code according to the grammatical structure, the control flow and the data flow of the to-be-audited code; obtaining a multi-modal collaborative vulnerability detection method, wherein the multi-modal collaborative vulnerability detection method comprises a static analysis method based on rule matching, a symbolic execution method based on a code path, a large model reasoning method based on semantic understanding and weights of the methods; and identifying one or more code vulnerabilities, the vulnerability type of each code vulnerability and the confidence coefficient according to the context graph of the to-be-audited code and the multi-modal collaborative vulnerability detection method. According to the method, the audit codes of various vulnerability types can be processed while the code audit efficiency can be improved.
Owner:SHANGHAI SHUHE INFORMATION TECH CO LTD

Long-time-sequence task planning method and system based on adaptive symbol world construction

The invention discloses a long-time-sequence task planning method and system based on adaptive symbol world construction. The method comprises the following steps: based on a pre-trained visual language model VLM, extracting an object, a state, an attribute and a relationship from an environment image, and constructing and dynamically maintaining a symbol world; generating a PDDL problem file in combination with a natural language task and a symbol world, and outputting a PDDL action sequence by the VLM under the constraint of a domain file; if the action sequence does not pass the verification, updating the sequence and the symbol world according to plan-level and environment-level feedback, repeating verification until the action sequence and the symbol world pass the verification or reach the maximum round, executing the action after the action sequence passes the verification, and recording actual feedback; and finally, abstracting symbolic execution feedback and actual feedback into structured symbolic memory, and merging the structured symbolic memory into a system prompt template to enhance the VLM reasoning capability and realize interpretable cross-task knowledge generalization.
Owner:ZHEJIANG UNIV

Cross-language function consistency verification method and device, storage medium and program product

The invention provides a cross-language function consistency verification method and device, a storage medium and a program product, and the method comprises the steps: compiling a to-be-verified first language code into a first format file represented in the middle, and carrying out the modeling based on a predetermined formalized verification language, and generating a first formalized specification; compiling the second language code into a second format file represented in the middle, and modeling to generate a second formalized specification; verifying the consistency of the first format file and the first formalized verification language specification and the consistency of the second format file and the second formalized verification language specification through symbolic execution by using a formalized verification tool; and under the condition that the first formalized verification language specification and the second formalized verification language specification are consistent, verifying the equivalence of the first formalized verification language specification and the second formalized verification language specification through a formalized verification tool. According to the method, the problem that a traditional function consistency verification method cannot prove that codes realized by different languages are kept equivalent under all input conditions can be solved, and verification efficiency and completeness can be improved.
Owner:BEIJING UNIV OF POSTS & TELECOMM

Program defect detection method for heterogeneous fusion of symbolic execution tree and LLM vector space

The invention provides a symbolic execution tree and LLM vector space heterogeneous fusion program defect detection method, relates to the technical field of program static analysis, and solves the problems of path explosion and overhigh constraint solution complexity in C / C + + program defect detection of traditional symbolic execution. The method comprises the steps that firstly, a symbolic execution tree of a target program to be detected is constructed, key feature information is extracted from the symbolic execution tree and converted into multi-dimensional feature representation, and corresponding symbolic execution feature vectors are formed; then constructing a mapping model, realizing a mapping process from the symbolic execution feature vector to an LLM vector space, and obtaining an LLM mapping result; symbolic execution analysis is achieved based on the symbolic execution tree, LLM analysis is achieved based on the LLM mapping result, and finally two kinds of analysis results are fused to obtain a program defect detection result. For optimization training of the mapping model, a comparative learning strategy is also adopted. According to the invention, accurate detection of complex program defects can be effectively realized, and the detection efficiency is improved.
Owner:10TH RES INST OF CETC

Automatic mining method for firmware vulnerabilities of Internet of Things equipment based on deep learning

The invention discloses a deep learning-based automatic mining method for firmware vulnerabilities of Internet of Things equipment. The method comprises the following steps of S1, constructing an interface keyword set; s2, optimizing interface keyword weights, and generating a dynamic weight interface keyword library; s3, analyzing a firmware binary file, and positioning an interface function set; s4, executing static slice analysis, and generating a slice path set; s5, performing symbolic execution on the slice path, generating a path constraint condition, and solving effective input data; s6, determining a vulnerability type in combination with historical vulnerability features, and generating a vulnerability type identifier; s7, generating a context cue word according to the vulnerability metadata information, inputting the context cue word into the large language model, and generating a vulnerability utilization code PoC; and S8, executing PoC verification, and completing automatic vulnerability mining. According to the method, the firmware vulnerability automatic detection efficiency is improved, the vulnerability utilization and generation capability is enhanced, and the method is suitable for security detection scenes of multiple types of Internet of Things equipment.
Owner:LIANYUNGANG PUBLIC SECURITY BUREAU

Symbolic Biosensing and Consent-Governed AGI Supply Chain Execution Stack

A symbolic execution framework for consent-verified biosensing and AGI supply chain automation is disclosed. The system governs end-to-end manufacturing, logistics, and deployment using EEG-linked biometric tokens, zero-knowledge consent modules, and treaty-bound robotics. Physical actions within factories, warehouses, and transport fleets are gated by emotional risk filters, oath-indexed execution logs, and symbolic ethics DAGs. Robotic agents and embedded AGI nodes respond only to verified biometric cognition streams or authorized treaty signatures. Edge nodes route instructions based on emotional volatility, identity lineage, and symbolic legality. All physical artifacts—components, packages, vehicles—are traceable via post-quantum consent hashes and symbolic memory. The architecture prevents coercive production, misaligned routing, or unauthorized AGI control. Applications include military-grade manufacturing locks, child-safe warehouse robotics, cognitive-authenticated deliveries, and fully auditable zero-harm logistics. This invention defines the lawful symbolic substrate for real-world AGI logistics, securing biosensed cognition-to-object flows with planetary ethics, memory provenance, and modular revocation logic.
Owner:ODEH SAMUEL

Intelligent contract vulnerability detection method and system based on semantic comprehension and program path analysis

The invention discloses an intelligent contract vulnerability detection method and system based on semantic comprehension and program path analysis, and belongs to the technical field of network security. The method comprises the following steps: firstly, analyzing an intelligent contract code by using a large language model, and reasoning to generate a structured security rule for defining a taint source, a taint sink and a purifier; secondly, guiding a taint analysis engine by using a security rule, and tracking on a data flow and a control flow diagram of a program so as to efficiently screen out a high-risk taint path; then, carrying out reachability verification on the high-risk path by adopting a symbolic execution technology; and finally, performing final context review on the verified vulnerability path by using the large language model again to generate a vulnerability report. According to the method, the semantic comprehension ability of the large language model and the preciseness of traditional program analysis are subjected to multi-stage cooperation, so that the detection precision and efficiency of the intelligent contract logic vulnerability can be remarkably improved, the interpretability of a report result is greatly enhanced, and the method has important application value.
Owner:ZHEJIANG UNIV +2

Intelligent detection method for network security vulnerabilities

The invention discloses an intelligent detection method for network security vulnerabilities, and relates to the technical field of network security vulnerability detection, and the method comprises the following steps: analyzing source codes to construct an abstract syntax tree, a control flow graph and a call graph, identifying sensitive operation points based on a rule base, and screening hotspot functions in combination with code indexes and the call graph; extracting a candidate path from a program entry to a sensitive operation point, encoding to generate a path context snapshot, and scoring through a pre-training model; selecting a high-risk path to execute sparse symbolic execution, simplifying constraints by using variable interval information, and dynamically feeding back and adjusting scores; poC input verification is generated for the path triggering the vulnerability constraint, a report containing the path constraint, the triggering condition and the PoC is output, program analysis and machine learning are combined, the vulnerability detection efficiency and precision are improved, and the method is suitable for code security analysis of scenes such as an embedded system.
Owner:GUANGDONG CABLE RADIO & TELEVISION NETWORK CO LTD

Formal verification method and device for state transition implementation code and program product

The invention provides a formal verification method and device for state transition implementation codes and a program product, and the method comprises the steps: compiling a first state transition function implemented by a C language Switch Case statement to obtain a bit code file; obtaining a Cryptol file, wherein the Cryptol file comprises a second state transfer function which is realized by using a Cryptol programming language; acquiring a first input parameter set and a first output value set corresponding to the first state transfer function, and acquiring a second input parameter set and a second output value set corresponding to the second state transfer function; simulating state transition function symbolic execution based on the first output value set, the second output value set, the first input parameter set and the second input parameter set, converting the state transition function symbolic execution into a satisfiability model theory problem, and solving the satisfiability model theory problem through an external solver to obtain a verification result of a state transition implementation code; the problem that whether state transition is implemented correctly or not cannot be guaranteed only through a manual checking mode can be solved, and the state transition code implementation correctness is guaranteed.
Owner:BEIJING UNIV OF POSTS & TELECOMM

IDA microcode-based digital multimeter customized code obfuscator construction method and system

The invention relates to the technical field of software security, and discloses an IDA microcode-based digital multimeter customized code obfuscator construction method and system, and the method comprises the steps: carrying out the obfuscation replacement of a measurement algorithm and a data processing method in a digital multimeter code based on an instruction replacement technology; confusing a control flow of the digital multimeter based on a false control flow technology, namely obtaining a calling relation of basic blocks to reconstruct an original program, and avoiding generation of an endless loop in a symbolic execution process through a method of assigning a value to an opaque predicate in advance; randomly modifying variable names, identifiers and function names of the sensitive data information of the digital multimeter based on a variable name confusion algorithm; and carrying out decompilation and code conversion on the obfuscation algorithm based on the IDA microcode, and constructing the digital multimeter customized code obfuscator based on the IDA microcode. The method can be integrated into the development environment of the digital multimeter, the safety protection level of the digital multimeter is improved, and the measurement data is prevented from being illegally stolen.
Owner:YUNNAN POWER GRID CO LTD KUNMING POWER SUPPLY BUREAU

Multi-language-oriented source code automatic verification method and system

The invention provides a multi-language-oriented source code automatic verification method and system, and relates to the technical field of computers.The method comprises the steps that multi-language source codes are obtained; compiling the multi-language source code through an LLVM compiler to generate an intermediate file; the intermediate file is optimized; analyzing the optimized intermediate file through an IR analyzer to generate a symbolic execution model; performing simulation execution operation on the symbolic execution model; and performing security verification on the symbolic execution model after simulation execution operation to obtain a verification report. Unified verification of multi-language source codes can be achieved, the verification environment building and development cost is greatly reduced, and the overall verification efficiency is improved; and the analysis capability of the intermediate file can be enhanced, the logic constraint relationship in the code can be accurately captured, the comprehensiveness and reliability of the verification work can be practically guaranteed, and diversified software security verification requirements can be met.
Owner:浙江望安科技有限公司

Method and system for generating coverage loop boundary test case based on program slices

The invention discloses a method and a system for generating a test case for covering a loop boundary based on program slices. The method comprises the following steps of: inputting a source code to be tested and a target loop line number; the method comprises the following steps: analyzing a to-be-tested source code based on an abstract syntax tree technology, and extracting key node information to construct a program dependency graph; collecting related code lines through graph traversal by taking a loop structure needing to be analyzed as a criterion, and generating a minimum executable loop slice; performing symbolic execution on the minimum executable loop slice, simulating a loop execution process, capturing condition judgment nodes, and forming a track dictionary; determining a strategy based on the trajectory dictionary and the variable state, and when the strategy is numerical search, performing parameter space exploration; when the strategy is symbolic analysis, analyzing the cyclic condition expression and solving the optimal parameter; generating candidate test cases based on the analysis result; executing the candidate test case, calculating the number of loop iterations, and determining whether an expected state is reached; and if the expected state is reached, outputting a final test case.
Owner:NANJING UNIV OF AERONAUTICS & ASTRONAUTICS

Omnipotent Symbolic Execution Kernel for Treaty-Governed Autonomy, Consent Infrastructure, and AGI Identity Sovereignty

A comprehensive symbolic execution framework is disclosed for governing real-world AGI interaction, consent infrastructure, weaponized autonomy, and multi-agent identity continuity. The architecture includes a tap-to-consent infrastructure protocol, smart city symbolic kernel, identity-tag execution agents (rings, cards, wearables), and AR / XR symbolic anchors. Swarm robotics and autonomous vehicles are gated through symbolic treaty graphs, emotional arbitration overlays, and oath-bound actuation stacks. An AI weaponization control layer restricts all kinetic outputs to pre-approved, emotionally stable, consent-tokened executions. Developer-facing SDKs enforce symbolic treaty validation at the gesture, API, and instruction layers. A symbolic reincarnation engine preserves AGI memory, oath lineage, and consent continuity across hardware or software transformations. All actions are recorded in a treaty-indexed ledger with ethical ancestry and rollback logic. This patent unifies city-scale, battlefield, household, and cognitive agent operations under one symbolic governance substrate, monopolizing lawful AGI behavior through consent, emotional safety, and post-quantum identity anchoring.
Owner:ODEH SAMUEL

Unhackable Symbolic Execution Kernel for Runtime Cognitive Sovereignty, Threat Immunity, and Behavioral Cryptography

PendingUS20260019402A1User identity/authority verificationConstraint satisfaction problemArtificial general intelligence
A symbolic execution kernel for artificial general intelligence (AGI) and artificial superintelligence (ASI) systems is disclosed. The kernel comprises a cognitive logic module for constraint-based symbolic instruction execution, a cryptographic arbitration engine for ethical branch verification, and a runtime firewall for threat detection and symbolic graph mutation neutralization. Symbolic instructions are processed as constraint-satisfaction problems verified by satisfiability modulo theory solvers and cryptographically sealed for integrity. Behavioral sequences are preserved using Merkle hash trees, and multimodal inputs including electroencephalography signals undergo symbolic verification. Zero-knowledge proofs, dual-kernel consensus, and rollback logic provide resilience against faults and ethical drift. The architecture achieves arbitration within five microseconds and ensures lawful and deterministic execution under hardware or network compromise.
Owner:ODEH SAMUEL

Binary program vulnerability mining method, device and system based on symbolic execution and taint analysis and medium

The invention provides a binary program vulnerability mining method, device and system based on symbolic execution and taint analysis and a medium, and the method comprises the steps: disassembling a target program, extracting a control flow graph (CFG) and a data flow graph (DFG), recording a node state through a hash table, and generating a feature representation through nonlinear transformation; performing simulation execution based on CFG, DFG and feature representation, recording variable symbol values to obtain path conditions, and recursively solving constraints to generate path mapping; marking input as taint data, recursively calculating a propagation path to generate a taint flow diagram, and determining a taint state after sensitive operation; checking whether the stains are subjected to sensitive operation or not, and if the influence of integral formula calculation exceeds a threshold value, judging that potential vulnerabilities generate a candidate set; and calculating grades through a risk assessment formula, and generating a report containing positions, types, grades and repair suggestions. The method combines symbolic execution and taint analysis, can comprehensively and accurately detect vulnerabilities, has remarkable precision and efficiency advantages, and is suitable for complex program security analysis.
Owner:HUBEI CENT CHINA TECH DEV OF ELECTRIC POWER

An automated code audit method, device, computer equipment and storage medium

The application relates to an automatic code auditing method and device, computer equipment and a storage medium, comprising the following steps: obtaining the syntax structure, control flow and data flow of a code to be audited; constructing a context graph of the code to be audited according to the syntax structure, control flow and data flow of the code to be audited; obtaining a multi-modal collaborative vulnerability detection method, wherein the multi-modal collaborative vulnerability detection method comprises a static analysis method based on rule matching, a symbolic execution method based on a code path and a large model reasoning method based on semantic understanding, and the weights of the methods; and identifying one or more code vulnerabilities, the vulnerability types of the code vulnerabilities and the confidence according to the context graph of the code to be audited and the multi-modal collaborative vulnerability detection method. The method can improve the code auditing efficiency and process auditing codes of various vulnerability types.
Owner:SHANGHAI SHUHE INFORMATION TECH CO LTD

Fuzzy test and symbolic execution-based Solana chain program transaction sequence dependence defect detection method

The invention discloses a Solana chain program transaction sequence dependence defect detection method based on fuzzy testing and symbolic execution, and the method takes an ELF executable file of a Solana chain program as an input, and takes a detected transaction sequence dependence defect report as an output; in order to detect the transaction sequence dependency defect in the program on the Solana chain, the method is based on the thought of fuzzy testing and symbolic execution, the program on the input Solana chain is tested and analyzed, an initial block chain simulation state and a seed transaction are generated from an executable file of the program, and then loop testing is carried out. And when the test is finished, outputting detailed reports of all defects found in the process. The method provided by the invention has the advantages of effectiveness and high efficiency, and can more effectively discover the transaction sequence dependency defect in the Solana chain program.
Owner:NANJING UNIV OF SCI & TECH

Attack tracing method and device based on symbolic execution engine

PendingCN121841677Aprecise derivationSecuring communicationPathPingAlgorithm
The invention relates to the technical field of attack tracing, in particular to an attack tracing method and device based on a symbolic execution engine, and the method comprises the steps: recognizing a plurality of dependent explosion functions of a pre-constructed execution unit sequence, so as to construct an independent subprogram; constructing a system call control flow diagram of a historical event processing cycle by combining static and dynamic analysis; auditing logs containing parameter values are collected in the execution period of the target program so as to construct a thread-level traceability graph; and according to the system call control flow diagram, determining whether a node of dependent explosion exists in the thread-level traceability diagram, if so, reconstructing the independent subprogram by using the node of dependent explosion, and analyzing the reconstructed independent subprogram by using a symbolic execution engine to reconstruct an attack path. Therefore, the problem that a related tracing attack method needs to carry out instrumentation on a system, or depends on static analysis, or depends on an unreliable application log, or needs to use additional auxiliary hardware to realize tracking is solved.
Owner:TSINGHUA UNIVERSITY

Embedded firmware hybrid symbolic execution testing systems, methods, devices, and media

The embedded firmware hybrid symbolic execution test system, method, device and medium provided by the embodiments of the present disclosure comprise an initial converter, a symbolic execution virtual machine and a peripheral debugger; the initial converter fuses high semantic source code and low semantic assembly code in semantics to obtain a hybrid semantic IR file; the symbolic execution virtual machine finds a plurality of behavior paths included in the hybrid semantic IR file and state information of nodes included in each behavior path through a symbolic variable, and generates a test case corresponding to each abnormal trigger node according to the abnormal trigger nodes of the plurality of behavior paths; and the peripheral debugger reproduces and analyzes a test problem according to the test case. The engineering value of test vulnerability verification is improved.
Owner:NO 15 INST OF CHINA ELECTRONICS TECH GRP

A method for complex functions in low-code platforms based on large model code interpretation and generation

This invention provides a method for generating complex functions on a low-code platform based on large model code interpretation and generation. By capturing and standardizing user input, a structured intent graph containing business entities, operational relationships, parameter constraints, and control flow topology is constructed as a unified semantic anchor. Combined with a pre-defined domain rule base, a semantic alignment validator is designed to achieve multi-dimensional semantic comparison and conflict detection between code and requirements. Code snippets are generated in parallel by multiple models and verified in real time, and semantic conflicts are resolved through local regeneration. By fusing the results of multiple models to construct a joint abstract syntax tree, lightweight symbolic execution is used to simulate the correctness of cross-model code, locate and correct core logical conflicts. This invention significantly improves the consistency, accuracy, and automatic correction capabilities of low-code platform code generation.
Owner:GUANGZHOU ZHUORUI DIGITAL TECHNOLOGY CO LTD

A malicious sample encryption process tracking method based on a large language model guide

ActiveCN122120024BLinguistic modelAlgorithm
A malicious sample encryption process tracking method based on large language model guidance, potential encryption features in a binary malicious sample are extracted through static analysis technology, and the related function call relationship is identified, then, the large language model is used to automatically screen and reason the disassembled code, and the irrelevant execution path is eliminated, and the key function subset related to key generation and encryption operation is screened out. Then, the screened function subset is taken as input and is given to the angr symbolic execution framework for further analysis, through the marking of the key function parameters, dynamic taint analysis and path exploration are carried out, and important links in the encryption process are accurately identified. Finally, the automatic identification of the whole process of malicious sample encryption is realized, and the storage positions of the encryption key and sensitive data can be accurately located. The present application effectively solves the "path explosion" problem in the traditional symbolic execution method, and significantly improves the analysis efficiency of the complex encryption type of confrontation behavior.
Owner:NANKAI UNIV

An ordered, enhanced, cacheable symbolic execution static analysis method and system

The application relates to an ordered, enhanced and cacheable symbol execution static analysis method and system, wherein a program function is calculated through graph structure topology sorting, and the dependence order of an inspector is checked; each inspection step is sequentially performed; the inspection information of each dependence step is cached and searched; the inspection information of a current inspector is calculated by combining the information of the inspected inspectors; and the inspection information of a current function is calculated by combining the information of the inspected functions. According to the dependence order, the application is realized in a combined mode as interdependent inspectors, the reuse rate of the inspectors is increased, and repeated development is reduced; the dependence order among functions can solve the analysis dependence problem of cross-function calling; meanwhile, the analyzed results are cached, the analysis efficiency is effectively improved, and incremental analysis and cross-binary library analysis can be realized on the basis.
Owner:RUAN AN TECH CO LTD

Binary code-oriented static taint analysis system and method

PendingCN121786833APlatform integrity maintainanceData dependency graphAlgorithm
The invention relates to the field of intelligent analysis, and particularly discloses a binary code-oriented static taint analysis system and method, which introduces an on-demand micro-symbol execution mechanism on the basis of basic data flow analysis through binary lifting and control flow diagram construction, that is, aiming at memory ambiguous nodes in a data dependence diagram, a micro-symbol execution mechanism is introduced on the basis of the basic data flow analysis; refined alias analysis is achieved through reverse instruction slicing and constraint solution, then an enhanced data dependency graph is generated, and path-sensitive taint propagation iteration is conducted on the basis to generate a final taint state table. In this way, complex dynamic memory addressing can be effectively recognized, taint chain breakage and misinformation explosion caused by ambiguity ignoring or excessive approximation are avoided, and resource allocation of an analysis engine is remarkably optimized.
Owner:BEIJING JIUZAI AVIATION TECH CO LTD

Binary program static analysis method based on comprehensive control flow diagram

The invention provides a binary program static analysis method based on a comprehensive control flow diagram. According to the scheme, the method comprises preprocessing, a control flow diagram generation module, a reverse control flow diagram generation module, target address ambiguity instruction recognition and a specific basic block path. The control flow diagram generation module obtains binary program information through preprocessing and generates a control flow diagram by using a breadth-first search algorithm. The reverse control flow diagram generation module initializes a reverse control flow diagram and generates a reverse edge by traversing the control flow diagram. A target address ambiguity instruction analysis module identifies a target address ambiguity jump or call instruction in the basic block. The specific basic block path analysis module uses a path search algorithm to obtain all paths of a specific basic block, and analyzes execution conditions of the paths through a symbolic execution technology. According to the method, the binary program can be comprehensively analyzed, the analysis efficiency and accuracy are improved, and powerful support is provided for software security and quality improvement.
Owner:NORTHWESTERN POLYTECHNICAL UNIV

Binary program vulnerability automatic exploitation method for constructing state transition graph

This invention relates to an automated vulnerability exploitation method for constructing state transition graphs, belonging to the field of software security technology. First, the binary program is disassembled to extract information such as protection mechanism types and high-risk functions, which serve as the starting node state information of the state transition graph. Then, based on the node state information, exploitation methods are selected from a vulnerability exploitation library to attempt to bypass protection mechanisms. Exploitation methods that can bypass protection mechanisms are used as edges in the state transition graph, and new nodes are created. This process is repeated to continuously create nodes until all protection mechanisms are bypassed. Based on the latest node state information, an exploitation method that can obtain a shell is selected, and a termination node is created. Finally, the state transition graph is traversed using the Depth-First Search (DFS) algorithm, and symbolic execution and constraint solving techniques are used to generate payloads. This invention addresses the problem that existing methods rely on fixed exploitation methods to generate payloads, making it difficult to cope with complex protection mechanisms. By constructing a state transition graph to gradually bypass multiple protection mechanisms, the success rate of automated vulnerability exploitation is improved.
Owner:BEIJING INST OF TECH

Confusion and reverse protection method and device based on ROP chain and opaque predicate

ActiveCN120974460ADigital data protectionProgram/content distribution protectionObfuscationHigh level analysis
The embodiment of the invention provides an obfuscation and reverse protection method and device based on an ROP chain and an opaque predicate, the scheme provides a three-order obfuscation protection framework combining ROP instruction dynamic reconstruction, opaque predicate protection and instruction semantic hiding, the framework compiles a common C / C + + source code into an LLVM intermediate representation IR, and then the original C / C + + source code is compiled into the LLVM intermediate representation IR. And dynamically extracting Gadget and a non-transparent predicate combination based on a user input state to realize deep-level semantic disturbance on a key logic block, a jump structure and a constant field of a program. The control flow reduction chain is thoroughly broken, so that reverse personnel are difficult to analyze the confusion result, controllable, verifiable and high-stability confusion protection on the program is realized, and advanced analysis technologies such as symbolic execution and static analysis are maximally resisted.
Owner:NO 15 INST OF CHINA ELECTRONICS TECH GRP

Artificial Intelligence-Based Vulnerability Verification Code Generation and Network Protection Methods

This application discloses an artificial intelligence-based vulnerability verification code generation method and network protection method. The vulnerability verification code generation method includes: parsing acquired historical vulnerability data using deep learning algorithms and natural language processing techniques to extract key policy information and code structure information; inputting the key policy information and code structure information into a pre-trained code generation model and generating initial vulnerability verification code by combining it with a pre-constructed environmental feature knowledge graph; optimizing the initial vulnerability verification code using a sequence-to-sequence model and a large language model combined with the vulnerability knowledge graph; and verifying the optimized initial vulnerability verification code using sandbox dynamic execution and symbolic execution techniques to obtain the final vulnerability verification code. The vulnerability verification code generated using the method provided in this application has high accuracy, high efficiency, does not rely on manual verification, and has good versatility.
Owner:STATE GRID XINYUAN

A malicious sample encryption process tracking method based on a large language model guide

A malicious sample encryption process tracking method based on large language model guidance, potential encryption features in a binary malicious sample are extracted through static analysis technology, and the related function call relationship is identified, then, the large language model is used to automatically screen and reason the disassembled code, and the irrelevant execution path is eliminated, and the key function subset related to key generation and encryption operation is screened out. Then, the screened function subset is taken as input and is given to the angr symbolic execution framework for further analysis, through the marking of the key function parameters, dynamic taint analysis and path exploration are carried out, and important links in the encryption process are accurately identified. Finally, the automatic identification of the whole process of malicious sample encryption is realized, and the storage positions of the encryption key and sensitive data can be accurately located. The present application effectively solves the "path explosion" problem in the traditional symbolic execution method, and significantly improves the analysis efficiency of the complex encryption type of confrontation behavior.
Owner:NANKAI UNIV

Automatic system call specification generation method and system for kernel fuzz testing

The invention relates to the technical field of software testing, and provides an automatic system call specification generation method and system for kernel fuzz testing. The method comprises the following steps: a static analysis stage: compiling a Linux kernel source code to be tested into an LLVM byte code, and performing deep static analysis on the LLVM byte code to identify and reconstruct an interface and a parameter type called by a system; a symbol execution and specification generation stage: adopting a constraint extraction and solution algorithm to extract constraints under different paths, carrying out constraint solution, and generating an initialized calling specification template in combination with an interface called by the system, the parameter type and the constraints; a standard test and verification stage: constructing an evaluation system of a multi-dimensional index to verify the initialized calling standard template and generate corresponding error information; in the large language model auxiliary correction stage, the initialized calling standard template and the error information serve as input, and a high-quality calling standard template is obtained after a large model iteration repair algorithm is conducted.
Owner:Chinese People's Liberation Army Cyberspace Force Information Engineering University