《電子技術應用》
您所在的位置:首頁 > 通信与网络 > 设计应用 > 基于补丁特性的漏洞扫描研究
基于补丁特性的漏洞扫描研究
信息技术与网络安全
刘思琦,王一鸣
(北京交通大学 计算机与信息技术学院,北京100044)
摘要: 为抵御漏洞引发的黑客攻击和漏洞自身产生的威胁,1day漏洞应用修复的通用办法是使用代码匹配检测。但目前源代码匹配误报率高,二进制代码匹配不精确且不通用。基于此,提出了一种由源代码到二进制的基于补丁特性的漏洞扫描模型——BinScan。它先形成已知漏洞数据库并对源代码进行已知漏洞扫描得出漏洞检测结果;然后利用源代码检测信息对打补丁前后源代码编译生成二进制文件,形成二进制漏洞库;最后比较目标二进制文件相似性,利用源代码结果进行检验。最终生成Linux Kernel的2 700条漏洞数据,15 496个patch文件,实现了利用源代码检测限制二进制文件的漏洞检测范围,然后基于CFG和二进制代码相似性检测补丁存在以检测漏洞。检测结果表明,此方法与其他二进制漏洞检测工具相比,可以将源代码级的漏洞扫描能力应用于二进制,是有效的。
中圖分類號: TP309
文獻標識碼: A
DOI: 10.19358/j.issn.2096-5133.2021.07.009
引用格式: 劉思琦,王一鳴. 基于補丁特性的漏洞掃描研究[J].信息技術與網絡安全,2021,40(7):52-58.
Research on vulnerability scanning based on patch characteristics
Liu Siqi,Wang Yiming
(School of Computer and Information Technology,Beijing Jiaotong University,Beijing 100044,China)
Abstract: In order to resist the hacker attack caused by the vulnerability and the threat generated by the vulnerability itself, the general method of 1day vulnerability application repair is to use code matching to detect. But at present, the false alarm rate of source code matching is high, and the binary code similarity matching is not accurate and universal. Based on this, this paper proposes a vulnerability scanning model from source code to binary code, BinScan, which is based on patch features. Firstly, it forms a known vulnerability database and scans the source code for known vulnerabilities to obtain the vulnerability detection results; then it uses the source code detection information to compile the source code before and after the patch to generate a binary file and to form a binary vulnerability library; finally it compares the target binary files for similarity performance, using the source code results for verification. In the end, this paper generates 2 700 vulnerability data and 15 496 patch files of Linux Kernel. It has been realized to use source code detection to limit the vulnerability detection range of binary files, and to detect the existence of patches based on the similarity of CFG and binary code to detect vulnerabilities. The detection results show that compared with other binary vulnerability detection tools, this method can apply source code level vulnerability scanning capabilities to binary and is effective.
Key words : patch characteristics;vulnerability scanning;binary;source code;security

0 引言

 在時間維度上,漏洞都會經歷產生、發現、公開和消亡等過程,不同的時間段,漏洞有不同的名稱和表現形式。1day漏洞是指在廠商發布安全補丁之后,大部分用戶還未打補丁的漏洞,此類漏洞依然具有可利用性。在各類型軟件中,許多漏洞的壽命超過12個月,針對此類漏洞的通用應用修復辦法是使用代碼匹配[1],但是往往通過補丁做出的修補都是一些細微的變化,這會導致許多代碼匹配的方法不精確且不通用,造成結果高誤報。




本文詳細內容請下載:http://m.tom3567.com/resource/share/2000003678




作者信息:

劉思琦,王一鳴

(北京交通大學 計算機與信息技術學院,北京100044)


此內容為AET網站原創,未經授權禁止轉載。
主站蜘蛛池模板: 欧美精品自拍视频| 欧美亚洲视频在线看网址| 精品视频一区在线| 在线一区日本视频| 欧美高清中文字幕| www高清在线视频日韩欧美| 欧美亚洲激情在线| 亚洲www永久成人夜色| 亚洲精品在线免费| 国产精品日韩欧美综合| 久久久国产在线视频| av观看久久| 国产在线98福利播放视频| 日韩av中文字幕第一页| 91精品视频在线看| 欧美视频在线第一页| 97国产精品久久| 91av福利视频| 91精品国产高清| 伊人久久99| 亚洲伊人久久综合| 91久久大香伊蕉在人线| 91国产丝袜在线放| 亚洲在线观看视频网站| 国产精品国内视频| 国产激情视频一区| 久久精品国产免费观看| 欧美日本国产在线| 欧美一区二区三区在线免费观看| 日本一区二区三区视频在线观看 | 久章草在线视频| 欧美日本高清一区| 蜜桃视频一区二区在线观看 | 真实国产乱子伦对白视频 | julia一区二区中文久久94| 国产精品久久视频| 久久精品人人做人人爽| 国产精品高清网站| 九九九九九九精品| 国产美女视频免费| 国产精品美女免费|