Determining a security score in binary software code
Systems, methods, and software can be used to determine a security score of a binary software code. In some aspects, a computer-implemented method comprises: receiving a binary software code; inspecting the binary software code to determine at least one Common Vulnerability Scoring Standard (CVSS) factor; and determining a CVSS score based on the at least one CVSS factor.
1 . A computer-implemented method, comprising:
receiving, by at least one hardware processor on a software service platform, a binary software code;
inspecting, by the at least one hardware processor, the binary software code to determine at least one Common Vulnerability Scoring Standard (CVSS) factor, wherein the at least one CVSS factor comprises an attack vector factor, and the inspecting the binary software code comprises:
scanning a byte stream of the binary software code to detect text strings related to remote network functionalities that will be performed by a device executing the binary software code, wherein detecting text strings related to the remote network functionalities comprises detecting text strings corresponding to a network protocol in the binary software code;
determining a first numerical number of the text strings related to remote network functionalities;
comparing the first numerical number of text strings related to the remote network functionalities and a first configured number threshold for remote network functionalities;
determining a second numerical number of text strings related to local network functionalities that will be performed by the device executing the binary software code;
comparing the second numerical number of text strings related to local remote network and a second configured number threshold for local network functionalities; and
determining the attack vector factor based on the comparing between the first numerical number and the first configured number threshold for remote network functionalities and the comparing between the second numerical number and the second configured number threshold for local network functionalities;
determining, by the at least one hardware processor, a CVSS score based on the at least one CVSS factor; and
outputting, by the software service platform, the CVSS score.
2 . The method of claim 1 , wherein the at least one CVSS factor comprises at least one of an attack complexity factor, a privileges required factor, a user interaction factor, a scope factor, a confidentiality factor, an integrity factor, or an availability factor.
3 . The method of claim 1 , wherein the at least one CVSS factor comprises an attack complexity factor, and the inspecting the binary software code comprises:
determining a number of routines related to compiler defense, obfuscation, validation, or exception handling in the binary software code, and
determining the attack complexity factor based on the number of routines related to compiler defense, obfuscation, validation, or exception handling.
4 . The method of claim 1 , wherein the at least one CVSS factor comprises a privileges required factor, and the inspecting the binary software code comprises:
determining a number of application program interfaces (APIs) related to privilege processing in the binary software code, and
determining the privileges required factor based on the number of APIs related to privilege processing.
5 . The method of claim 1 , wherein the at least one CVSS factor comprises a user interaction factor, and the inspecting the binary software code comprises:
determining a number of routines related to user input in the binary software code, and
determining the user interaction factor based on the number of routines related to user input.
6 . A server, comprising:
at least one hardware processor; and
one or more computer-readable storage media coupled to the at least one hardware processor and storing programming instructions for execution by the at least one hardware processor, wherein the programming instructions, when executed, cause the at least one hardware processor to perform operations comprising:
receiving a binary software code;
inspecting the binary software code to determine at least one Common Vulnerability Scoring Standard (CVSS) factor, wherein the at least one CVSS factor comprises an attack vector factor, and the inspecting the binary software code comprises:
scanning a byte stream of the binary software code to detect text strings related to remote network functionalities that will be performed by a device executing the binary software code, wherein detecting text strings related to the remote network functionalities comprises detecting text strings corresponding to a network protocol in the binary software code;
determining a first numerical number of the text strings related to remote network functionalities;
comparing the first numerical number of text strings related to the remote network functionalities and a first configured number threshold for remote network functionalities;
determining a second numerical number of text strings related to local network functionalities that will be performed by the device executing the binary software code;
comparing the second numerical number of text strings related to local remote network and a second configured number threshold for local network functionalities; and
determining the attack vector factor based on the comparing between the first numerical number and the first configured number threshold for remote network functionalities and the comparing between the second numerical number and the second configured number threshold for local network functionalities;
determining a CVSS score based on the at least one CVSS factor; and
outputting, at the server, the CVSS score.
7 . The server of claim 6 , wherein the at least one CVSS factor comprises at least one of an attack complexity factor, a privileges required factor, a user interaction factor, a scope factor, a confidentiality factor, an integrity factor, or an availability factor.
8 . The server of claim 6 , wherein the at least one CVSS factor comprises an attack complexity factor, and the inspecting the binary software code comprises:
determining a number of routines related to compiler defense, obfuscation, validation, or exception handling in the binary software code, and
determining the attack complexity factor based on the number of routines related to compiler defense, obfuscation, validation, or exception handling.
9 . The server of claim 6 , wherein the at least one CVSS factor comprises a privileges required factor, and the inspecting the binary software code comprises:
determining a number of application program interfaces (APIs) related to privilege processing in the binary software code, and
determining the privileges required factor based on the number of APIs related to privilege processing.
10 . The server of claim 6 , wherein the at least one CVSS factor comprises a user interaction factor, and the inspecting the binary software code comprises:
determining a number of routines related to user input in the binary software code, and
determining the user interaction factor based on the number of routines related to user input.
11 . One or more non-transitory computer-readable media containing instructions which, when executed, cause a computing device to perform operations comprising:
receiving, by at least one hardware processor, a binary software code;
inspecting, by the at least one hardware processor, the binary software code to determine at least one Common Vulnerability Scoring Standard (CVSS) factor, wherein the at least one CVSS factor comprises an attack vector factor, and the inspecting the binary software code comprises:
scanning a byte stream of the binary software code to detect text strings related to remote network functionalities that will be performed by a device executing the binary software code, wherein detecting text strings related to the remote network functionalities comprises detecting text strings corresponding to a network protocol in the binary software code;
determining a first numerical number of the text strings related to remote network functionalities;
comparing the first numerical number of text strings related to the remote network functionalities and a first configured number threshold for remote network functionalities;
determining a second numerical number of text strings related to local network functionalities that will be performed by the device executing the binary software code;
comparing the second numerical number of text strings related to local remote network and a second configured number threshold for local network functionalities; and
determining the attack vector factor based on the comparing between the first numerical number and the first configured number threshold for remote network functionalities and the comparing between the second numerical number and the second configured number threshold for local network functionalities;
determining, by the at least one hardware processor, a CVSS score based on the at least one CVSS factor; and
outputting, at the computing device, the CVSS score.
12 . The computer-readable media of claim 11 , wherein the at least one CVSS factor comprises at least one of an attack complexity factor, a privileges required factor, a user interaction factor, a scope factor, a confidentiality factor, an integrity factor, or an availability factor.
13 . The computer-readable media of claim 11 , wherein the at least one CVSS factor comprises an attack complexity factor, and the inspecting the binary software code comprises:
determining a number of routines related to compiler defense, obfuscation, validation, o exception handling in the binary software code, and
determining the attack complexity factor based on the number of routines related to compiler defense, obfuscation, validation, or exception handling.
14 . The computer-readable media of claim 11 , wherein the at least one CVSS factor comprises a privileges required factor, and the inspecting the binary software code comprises:
determining a number of application program interfaces (APIs) related to privilege processing in the binary software code, and
determining the privileges required factor based on the number of APIs related to privilege processing.
15 . The computer-readable media of claim 11 , wherein the at least one CVSS factor comprises a user interaction factor, and the inspecting the binary software code comprises:
determining a number of routines related to user input in the binary software code, and
determining the user interaction factor based on the number of routines related to user input.