Malicious Code Utilization Chain Detection Scheme based on Abstract Syntax Tree
Guanlin Si, Yue Zhang, Min Li, Sen Jing · 2022 IEEE 6th Advanced Information Technology, Electronic and Automation Control Conference (IAEAC ) · 2022
The vulnerability based on deserialization is a code defect that does great harm but is not easy to be detected by the machine. This vulnerability requires a combination of multiple trigger functions. Once a complete utilization chain is formed, arbitrary file reading and even remote command execution can be achieved. In this scheme, the malicious code generates an abstract syntax tree through syntax analysis, takes the class name and member method name as the root node and intermediate node, uses keyword regular matching as the basis for identifying the main functions of member methods, and takes the main functions of member methods as leaf nodes. Finally, the code audit problem is transformed into the path traversal problem of the spanning tree. Through the spanning tree traversal algorithm, the automatic detection of malicious code is realized, and the efficiency and accuracy of code audit are improved.