A software upgrade security analysis method based on program analysis
Xiaoshao Lv, Hui Shu, Fei Kang, Yuyao Huang · 2021 IEEE International Conference on Computer Science, Electronic Information Engineering and Intelligent Control Technology (CEI) · 2021
Security of online software upgrade has become one of the most important evaluation criteria of cyber security. It is too inefficient to evaluate the security of software upgrade by manual reverse analysis method, which requires high-level cryptography knowledge and reverse analysis ability of researchers. The universality of software upgrade vulnerability puts forward high requirements for efficient and automatic analysis methods. In this paper, we propose a program analysis method combining dynamic analysis and static analysis to automatically evaluate software upgrade security. By parsing the process of software online upgrade deeply, we establish the upgrade vulnerability models, and utilize the program analysis method to evaluate the upgrade security. The experimental result has shown that this method can evaluate the security of software upgrade accurately and quickly.