检索规则说明:AND代表“并且”;OR代表“或者”;NOT代表“不包含”;(注意必须大写,运算符两边需空一格)
检 索 范 例 :范例一: (K=图书馆学 OR K=情报学) AND A=范并思 范例二:J=计算机应用与软件 AND (U=C++ OR U=Basic) NOT M=Visual
作 者:时启亮 沙乐天 潘家晔[1] SHI Qiliang;SHA Letian;PAN Jiaye(School of Computer Science,Nanjing University of Posts and Telecommunications;Jiangsu High Technology Research Key Laboratory for Wireless Sensor Networks,Nanjing 210023,China)
机构地区:[1]南京邮电大学计算机学院 [2]江苏省无线传感网高技术研究重点实验室,江苏南京210023
出 处:《软件导刊》2025年第3期109-118,共10页Software Guide
基 金:国家自然科学基金面上项目(62072253)。
摘 要:物联网漏洞挖掘主要面向源码未知的二进制程序,但存在大量人工审计工作,迫切需要一种高度自动化的流程来进行引导。在静态分析技术领域,指针分析作为一项底层技术,以其高度自动化的分析流程和出色的效果展现出适应多种应用场景的潜力。借助指针分析的优势,依托于反汇编平台Ghidra,对其引入的P-code进行封装形成PIR;以PIR为基础,设计符合漏洞挖掘需求的指针分析算法和污点分析算法,最终实现了一个可扩展的分析框架。针对CWE78漏洞的检测性能测试结果显示,所提框架正确检测出大部分漏洞,与现有漏洞分析工具相比,漏洞检出率提升86.2%,时间效率提升38.7%。该框架不仅能够验证已知漏洞,而且具备发现新漏洞的能力。IoT vulnerability mining mainly targets binary programs with unknown source code,but there is a significant amount of manual auditing work that urgently requires a highly automated process for guidance.In the field of static analysis technology,pointer analysis,as an underlying technology,has shown the potential to adapt to various application scenarios with its highly automated analysis process and excellent results.By leveraging the advantages of pointer analysis and relying on the disassembly platform Ghidra,the introduced P-code is encapsulated to form PIR;Then,based on PIR,we designed pointer analysis algorithms and taint analysis algorithms that meet the requirements of vulnerability mining,and ultimately implemented an extensible analysis framework.The performance test results for CWE78 vulnerability detection show that the proposed framework correctly detects most vulnerabilities.Compared with existing vulnerability analysis tools,the vulnerability detection rate has increased by 86.2%and the time efficiency has increased by 38.7%.This framework not only verifies known vulnerabilities,but also has the ability to discover new vulnerabilities.
分 类 号:TP311[自动化与计算机技术—计算机软件与理论]
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在链接到云南高校图书馆文献保障联盟下载...
云南高校图书馆联盟文献共享服务平台 版权所有©
您的IP:216.73.216.7