首页> 外国专利> APPARATUS AND METHOD FOR ANALYZING EMBEDED SOFTWARE VULNERABILITY BASED ON BINARY CODE

APPARATUS AND METHOD FOR ANALYZING EMBEDED SOFTWARE VULNERABILITY BASED ON BINARY CODE

机译:基于二进制代码的嵌入式软件易损性分析的装置和方法

摘要

The present invention relates to an apparatus and a method for analyzing vulnerability of binary code-based embedded software. The apparatus according to one embodiment of the present invention includes: a binary analysis unit for confirming whether a binary code can be converted into an intermediate representation format by extracting architecture information from the binary code; an intermediate representation conversion unit for converting the binary code into an intermediate representation code according to the confirmation resu an intermediate representation analysis unit for selecting a function to be analyzed for vulnerability by extracting a function call graph and a control flow graph from the intermediate representation code; a static vulnerability analysis unit for generating a static vulnerability detection list by determining whether the function to be analyzed for vulnerability has security vulnerability corresponding to a common weakness enumeration (CWE) vulnerability list; and a dynamic vulnerability analysis unit for performing symbolic execution by generating a test case for a function having vulnerability selected from the static vulnerability detection list. Therefore, the precision of vulnerability detection can be improved.
机译:本发明涉及一种用于分析基于二进制代码的嵌入式软件的脆弱性的设备和方法。根据本发明的一个实施例的设备包括:二进制分析单元,用于通过从二进制代码中提取体系结构信息来确认是否可以将二进制代码转换为中间表示格式;以及中间表示转换单元,用于根据确认结果将二进制代码转换为中间表示代码;中间表示分析单元,用于通过从中间表示代码中提取函数调用图和控制流程图来选择要进行漏洞分析的函数;静态漏洞分析单元,用于通过确定待分析漏洞的功能是否具有对应于普通漏洞列举(CWE)漏洞列表的安全漏洞,生成静态漏洞检测列表;动态漏洞分析单元,用于通过为具有从静态漏洞检测列表中选择的漏洞的功能生成测试用例来执行符号执行。因此,可以提高漏洞检测的精度。

著录项

  • 公开/公告号KR20180060497A

    专利类型

  • 公开/公告日2018-06-07

    原文格式PDF

  • 申请/专利权人 KOREA ELECTRIC POWER CORPORATION;

    申请/专利号KR20160160035

  • 发明设计人 LIM YONG HOON;KWON YOO JIN;

    申请日2016-11-29

  • 分类号G06F21/57;

  • 国家 KR

  • 入库时间 2022-08-21 12:39:55

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号