首页|基于动态执行日志和反向分析的漏洞成因分析技术

基于动态执行日志和反向分析的漏洞成因分析技术

扫码查看
软件漏洞给软件安全带来了巨大的威胁,全球每年因软件漏洞导致的安全事件层出不穷.然而,在实际的开发过程中,因开发人员的安全意识不够、代码和业务逻辑越来越复杂等原因,软件代码中难以避免地存在着安全漏洞.文章针对现有方法面临错误代码定位不准确、分析效率不高等难题,突破指令运行时信息获取和反向分析、错误代码准确定位等挑战,提出一种基于追踪日志和反向执行的程序错误原因定位方法,能够跟踪程序的代码执行流,记录指令在运行状态下的寄存器状态信息以及存储访问状态信息,分析引发执行错误的指针相关联的指针值生成、使用、计算的指令集合,实现高效、准确的漏洞成因分析和定位.
Vulnerability Causation Analysis Based on Dynamic Execution Logging and Reverse Analysis
Software vulnerabilities pose a great threat to software security,and there are numerous security incidents due to software vulnerabilities around the world every year.However,in the actual development process,due to the lack of security awareness of developers and the increasing complexity of code and business logic,it is difficult to avoid the existence of security vulnerabilities in software code.Aiming at the challenges of inaccurate error code positioning and inefficient analysis faced by the existing methods,this paper broke through the challenges of obtaining and reverse analysis of instruction runtime information and accurate positioning of error code,and proposed a method for locating the cause of program errors based on trace logs and reverse execution,which was capable of tracking the code execution flow of the program,recording the register state information and storage access state information of the instruction in the runtime state,and analyzing the pointer associated with the pointer that triggered the execution error.It can track the code execution flow of the program,record the register state information and storage access state information in the running state of the instruction,analyze the set of instructions that generate,use,and compute the pointer value associated with the pointer that triggers the execution error,and realize the efficient and accurate vulnerability cause analysis and localization.

dynamic execution logreverse analysisvulnerability causation analysis

沈钦涛、梁瑞刚、王宝林、张倞诚、陈恺

展开 >

中国科学院信息工程研究所,北京 100085

北京小米移动软件有限公司,北京 100089

动态执行日志 反向分析 漏洞成因分析

国家自然科学基金国家自然科学基金国家自然科学基金

623024976230249892270204

2024

信息网络安全
公安部第三研究所 中国计算机学会计算机安全专业委员会

信息网络安全

CSTPCDCHSSCD北大核心
影响因子:0.814
ISSN:1671-1122
年,卷(期):2024.24(10)