.NET Core已编译程序集安全分析及Roslyn反编译可行性咨询
关于用Roslyn检查.NET Core插件程序集的问题解答
1. Roslyn能否用于反编译,还是仅作为代码编译器?
Roslyn本质是.NET的编译器平台,核心能力是处理源代码的语法分析、语义分析和编译,本身并不直接提供反编译已编译程序集(DLL/EXE)的功能。但它可以和免费开源的反编译库(比如ICSharpCode.Decompiler)配合使用:先通过反编译库把已编译程序集还原为Roslyn能识别的C#语法树,再利用Roslyn强大的代码分析能力实现自定义的安全检查规则。
2. 简单入门示例
以下示例使用ICSharpCode.Decompiler(免费开源,NuGet可获取)配合Roslyn,实现你提到的几项基础安全检查:禁止引用指定底层程序集、禁止调用System.IO类型、检测实例化操作。
步骤1:安装依赖NuGet包
在项目中安装以下包:
Install-Package ICSharpCode.Decompiler Install-Package Microsoft.CodeAnalysis.CSharp
步骤2:检查代码实现
using ICSharpCode.Decompiler; using ICSharpCode.Decompiler.CSharp; using Microsoft.CodeAnalysis; using Microsoft.CodeAnalysis.CSharp; using Microsoft.CodeAnalysis.CSharp.Syntax; using System; using System.Collections.Generic; using System.IO; using System.Linq; class PluginSecurityChecker { static void Main(string[] args) { string pluginPath = "YourPlugin.dll"; if (!File.Exists(pluginPath)) { Console.WriteLine("插件文件不存在"); return; } // 初始化反编译器,将程序集转为Roslyn语法树 var decompilerSettings = new DecompilerSettings(); var decompiler = new CSharpDecompiler(pluginPath, decompilerSettings); SyntaxTree syntaxTree = decompiler.DecompileWholeModuleAsSyntaxTree(); // 构建编译上下文,用于语义分析 var compilation = CSharpCompilation.Create("PluginSecurityCheck") .AddSyntaxTrees(syntaxTree) .AddReferences(decompiler.References); var issues = new List<string>(); // 规则1:禁止引用数据库等底层程序集 var forbiddenAssemblies = new HashSet<string> { "System.Data.SqlClient", "Microsoft.EntityFrameworkCore" }; foreach (var reference in compilation.References.OfType<PortableExecutableReference>()) { string assemblyName = reference.GetAssemblyName().Name; if (forbiddenAssemblies.Contains(assemblyName)) { issues.Add($"违规引用底层程序集:{assemblyName}"); } } // 规则2:禁止调用System.IO相关类型的方法 SemanticModel semanticModel = compilation.GetSemanticModel(syntaxTree); var invocationNodes = syntaxTree.GetRoot().DescendantNodes().OfType<InvocationExpressionSyntax>(); foreach (var invocation in invocationNodes) { SymbolInfo symbolInfo = semanticModel.GetSymbolInfo(invocation.Expression); if (symbolInfo.Symbol is IMethodSymbol methodSymbol) { string typeFullName = methodSymbol.ContainingType?.ToString() ?? string.Empty; if (typeFullName.StartsWith("System.IO.")) { int line = invocation.GetLocation().GetLineSpan().StartLinePosition.Line + 1; issues.Add($"行{line}:违规调用System.IO方法 {methodSymbol.Name}"); } } } // 规则3:检测所有实例化操作(用于后续记录依赖) var objectCreationNodes = syntaxTree.GetRoot().DescendantNodes().OfType<ObjectCreationExpressionSyntax>(); foreach (var creation in objectCreationNodes) { TypeInfo typeInfo = semanticModel.GetTypeInfo(creation.Type); if (typeInfo.Type is INamedTypeSymbol typeSymbol) { int line = creation.GetLocation().GetLineSpan().StartLinePosition.Line + 1; issues.Add($"行{line}:检测到实例化 {typeSymbol.Name}"); } } // 输出检查结果 if (issues.Count == 0) { Console.WriteLine("插件安全检查通过"); } else { Console.WriteLine("插件安全检查不通过,存在以下问题:"); foreach (var issue in issues) { Console.WriteLine($"- {issue}"); } } } }
扩展说明
- 若追求更高性能,可直接使用
System.Reflection.Metadata读取程序集元数据(无需完全反编译),比如检查程序集引用、类型依赖等场景,速度更快。 - 后续扩展规则时,可基于Roslyn的分析器框架(
Microsoft.CodeAnalysis.Analyzers)编写更模块化的检查逻辑,便于维护和扩展。
内容的提问来源于stack exchange,提问作者Sky
相关产品推荐
相关产品推荐

