arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.17254cs.CR

SEMA-GUARD:汇编代码中的语义与基于图的漏洞检测

SEMA-GUARD: Semantic and Graph-Based Vulnerability Detection in Assembly Code

  • Western Michigan University(西密歇根大学)

机构由 AI 辅助整理,请以论文原文为准。

Halil Dursunoglu, Kaan Sulkalar

AI总结:

SEMA-GUARD提出结合语义分析与图神经网络,在汇编代码中检测漏洞,通过增强控制流图表示,在Juliet测试集上达到85.1%准确率和0.801的F1分数。

AI中文摘要:

在源代码不可用的情况下,例如恶意软件分析、固件分析和嵌入式系统分析中,对编译后程序的漏洞检测已变得日益重要。当前的方法严重依赖于语法规律或更高级别的表示,这些表示易受编译器变化的影响,并且可能无法直接适用于汇编代码。在本文中,我们提出了SEMA-GUARD,一个利用语义分析和图神经网络来识别汇编代码缺陷的框架。该方法通过添加程序在更低抽象级别上的执行信息(包括栈操作、内存访问和数据流)来改进控制流图的表示。使用基于Juliet测试套件的一个集合来评估SEMA-GUARD的有效性。在该集合中,每段源代码首先被翻译成汇编语言,然后被分解为函数级块。所提出的方法仅依赖于统计或结构数据,根据结果,达到了85.1%的准确率和0.801的F1分数。这些结果表明,在基于图的模型中包含语义信息可能是识别编译代码漏洞的一种成功方法。

英文摘要:

In cases where source code is not available, such as malware analysis, firmware analysis, and embedded systems analysis, vulnerability detection in compiled programs has gained importance. Current methods are heavily reliant on syntactical regularities or higher level representations that are vulnerable to changes in the compiler and may not be readily applicable to assembly code.In this article, we present SEMA-GUARD, a framework that uses semantic analysis and graph neural networks to identify flaws in assembly code. The approach improves the representation of control flow graphs by adding information about the program's execution at a lower level of abstraction, including stack manipulations, memory accesses, and data flow. A set based on the Juliet Test Suite was used to evaluate the effectiveness of SEMA-GUARD. In this set, each piece of source code is initially translated into assembly language and then broken down into function-level chunks. The suggested method, which relies only on statistical or structural data, achieves an accuracy of 85.1\% and an F1 score of 0.801, according to the results. Such results imply that including semantic information in graph-based models may be a successful method for identifying vulnerabilities in compiled code.

↑