用于数字取证检查和迁移保障的剥离二进制文件中后量子密码算法的静态检测
Static Detection of Post-Quantum Cryptographic Algorithms in Stripped Binaries for Digital Forensic Examination and Migration Assurance
AI总结:
本文提出静态分析方法Kestrel,可在剥离二进制文件中准确识别ML-KEM和ML-DSA,在实验中实现128/128召回率且零误报,还发现生产系统中未被察觉的后量子代码,为相关应用提供实用基础。
AI中文摘要:
当前,尚无方法能从编译后的二进制代码中验证易受量子攻击的算法是否已被替换为经批准的后量子算法。密码学发现工具通过符号、库依赖关系和运行时行为识别算法,但剥离、静态链接和优化二进制文件会破坏所有这些信号。本文提出Kestrel,这是一种用于在剥离二进制代码中识别标准化格基方案ML-KEM和ML-DSA的静态分析方法。Kestrel通过检测构成算术所依赖只读数据的数论变换常量表来识别ML-KEM和ML-DSA。Kestrel从公开方案参数中推导的指纹通过归一化和多集匹配过程进行定位,其误报概率通过分析确定。在对四个独立实现谱系及所有构建转换(包括编译器级混淆)的实验中,Kestrel在128个样本中实现了128的召回率,且零误报。将Kestrel应用于生产Linux系统上的6224个二进制文件,发现了12个包含ML-KEM的未编目程序,其中包括OpenSSH密钥交换程序和容器管理栈。在其中几个程序中,后量子代码在分发项目不知情的情况下通过语言运行时进入生产环境。Kestrel可区分真正的后量子实现与底层代码不支持的宣传声明,将每次检测归因于其起源代码库,且在取证磁盘映像试验中,于已删除二进制文件无法再重建的未分配空间中恢复了检测结果。因此,Kestrel为密码迁移保障、软件供应链检查和后量子取证检查提供了实用基础。
英文摘要:
Identifying which post-quantum algorithm a compiled binary implements is a core problem in binary analysis, and it becomes acute once the binary has been stripped, statically linked, and optimised, since the symbols, library dependencies, and runtime behaviour that conventional discovery tools rely on are then gone. This paper presents Kestrel, a static analysis method that identifies an algorithm from the number-theoretic transform constant tables its arithmetic depends on, and applies it to the standardised lattice schemes ML-KEM and ML-DSA, for which no prior method could confirm, from a shipped binary alone, that a quantum-vulnerable algorithm had been replaced by its approved successor. The fingerprints Kestrel derives from public scheme parameters are localised by a normalisation-and-multiset-matching procedure; the false-positive probability is established analytically. Across four independent implementation lineages and all build transformations, including compiler-level obfuscation, Kestrel achieved recall of 128 of 128 with zero false positives. Applied to 6,224 binaries on a production Linux system, it disclosed twelve uncatalogued programs containing ML-KEM, among them the OpenSSH key-exchange program and the container-management stack, where post-quantum code had entered production through the language runtime without the awareness of the projects distributing them. Kestrel distinguishes genuine implementations from advertised claims not backed by the underlying code, attributes each detection to its originating codebase, and, in a forensic disk-image trial, recovered a detection from unallocated space after the deleted binary could no longer be reconstructed. It thus provides a practical basis for cryptographic migration assurance, compliance verification, software supply-chain inspection, and post-quantum forensic examination.