基于敏感语义关联的代码切片及应用研究
2024-05-21帅活力唐成华
帅活力 唐成华



摘 要:利用程序的可伸縮性对程序进行代码切片,识别出受敏感变量影响的关键语句,消除噪音并挖掘程序内部依赖,用以检测代码的漏洞与缺陷。针对切片对依赖过于敏感的问题,提出一种基于敏感语义关联的代码过程间切片方法,提取表征敏感信息的有效语句,捕获语义依赖关联,将代码漏洞触发点转化为上下文敏感的缺陷依赖流,并基于约束规则提升切片效率,结合缺陷约束获取代码漏洞的异常来源。实验结果表明该方法在代码切片的效率、质量以及漏洞检测的精度上有较好的表现。
关键词:代码切片 敏感语义 控制流 漏洞检测
中图分类号:TP309
Research on Code Slicing Based on Sensitive Semantic Association and Its Application
SHUAI Huoli TANG Chenghua
Guangxi Key Laboratory of Trusted Software, Guilin University of Electronic Technology, Guilin, Guangxi Zhuang Autonomous Region, 541004 China
Abstract: By utilizing the scalability of the program to slice the code of the program, key statements affected by sensitive variables can be identified, noise can be eliminated, and the internal dependencies of the program can be mined, so as to detect vulnerabilities and defects in the code. In order to solve the problem of the excessive sensitivity of slicing to dependencies, this paper proposes an inter-procedural slicing method of the code based on sensitive semantic association, which extracts effective statements that represent sensitive information,, captures semantic dependent association, transforms the trigger points of code vulnerabilities into context-sensitive defect dependency flows, improves slicing efficiency based on constraint rules, and obtains the abnormal source of code vulnerabilities in combination with defect constraints. Experimental results show that this method performs well in the efficiency and quality of code slicing and the accuracy of vulnerability detection.
Key Words: Code slicing; Sensitive semantics; Control flow; Vulnerability detection
更新迭代的软件在提供优质服务的同时,结构不断复杂,并发、循环、函数调用等动态执行机制使得存在于整个软件开发生命周期的代码缺陷更难以避免,若在开发中复用到漏洞代码,新程序将延续其脆弱性,则识别出缺陷的难度更大。研究表明,缺陷修复将消耗软件开发成本的50%~70%。为重视代码安全,提高软件鲁棒性,进行缺陷漏洞与恶意代码检测等相关工作必不可少。程序是软件中相应表征分解的语义及其集合,程序行为特征能从指令层直观体现代码功能,而挖掘漏洞与缺陷发现往往以程序内部依赖关系、语义信息以及行為特征做支撑,由于对程序理解层面的不完善导致代码缺陷漏检等问题,学者们不断从程序代码本身提取相关信息,增强语义理解[1]。……
