计算机科学
可执行文件
控制流程图
二进制数
脆弱性(计算)
二进制代码
建筑
图形
编码(集合论)
理论计算机科学
分布式计算
数据挖掘
程序设计语言
计算机安全
数学
算术
视觉艺术
集合(抽象数据类型)
艺术
作者
Hao Wu,Hui Shu,Fei Kang,Xiaobing Xiong
出处
期刊:IEEE Access
[Institute of Electrical and Electronics Engineers]
日期:2019-01-01
卷期号:7: 169548-169564
被引量:5
标识
DOI:10.1109/access.2019.2953173
摘要
With the popularity of IoT (Internet of Things) devices, the security risks of these devices are increasing. However, due to the multisource heterogeneity of IoT devices, there are significant differences between the vulnerability detection of the Internet of Things and the PC-based vulnerability search method. Therefore, determining how to accurate search for vulnerabilities in large-scale cross-platform binary executable files is an urgent problem to be solved. At present, the solution to this problem mostly calculates code similarities by generating a CFG (control flow graph) from binary code, but due to the choice of architecture, OS (operating system) or compilation options, the same source code will be compiled into different assembly codes. The performance of existing vulnerability search methods for cross-architecture binaries has been challenged. To alleviate the vast differences in the assembly codes caused by different compilation scenarios, this paper proposes a cross-platform large-scale binary vulnerability search method based on two-level feature semantic learning. The contribution is that we have defined a new functional structured signature method to mitigate the massive grammatical and structural differences of binary files caused by different compilation environments. Moreover, we reasonably integrate the hierarchical model of Structure2Vec and GAT (graph attention network) and implement training from the internal control flow characteristics of the function and the call relationship between functions to obtain a more accurate functional semantic expression.
科研通智能强力驱动
Strongly Powered by AbleSci AI