Binary program analysis method, terminal device and storage medium
By obtaining the instruction set architecture characteristics and determining the partition address of the binary program, the executable format file is reconstructed, which solves the analysis problem of the bare binary program of the IoT device and realizes effective decompilation and code association.
Patent Information
- Application Number
- CN202111609503.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-12-27
- Publication Date
- 2025-09-09
- Estimated Expiration
- 2041-12-27
AI Technical Summary
Existing technologies make it difficult to effectively analyze bare binary programs on IoT devices, especially the lack of program partition layout information, which makes it impossible for decompilation tools to properly associate string data and functions.
By obtaining the instruction set architecture characteristics of the binary program, determining the running start address, using continuous constant strings to extract the read-only data area, combining the stack initialization code to determine the data area, and reconstructing the executable format binary program file for decompilation.
It achieves effective decompilation and code correlation analysis of binary programs without specific program structure, solving the forensics problem of IoT devices.
Smart Images

Figure CN114443055B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of embedded technology, and in particular to a binary program analysis method, terminal equipment and storage medium. Background Art
[0002] As IoT device security becomes increasingly complex, IoT device forensics present challenges such as system account and password encryption, communication protocol privatization, stored data encryption, and data format customization. These challenges require analysis of chip binary programs. However, firmware on IoT devices is often bare binary without an executable structure, making analysis challenging.
[0003] Currently, the primary method for analyzing binary programs is to use common decompilation tools such as IDA, WinDBG, and ObjDump. These tools are effective for decompiling programs with executable formats. However, after decompiling binary programs without executable formats, the start address is not determined, and the code area, read-only data area, and data area are not distinguished. This often leads to problems such as string data not being properly associated, data being decompiled as code, and function association not being properly associated. Therefore, there is currently a lack of effective methods for analyzing binary programs without a specific program structure. Summary of the Invention
[0004] In order to solve the above problems, the present invention proposes a binary program analysis method, a terminal device and a storage medium.
[0005] The specific plan is as follows:
[0006] A binary program analysis method comprises the following steps:
[0007] S1: Obtain the instruction set architecture characteristics of the binary program;
[0008] S2: Obtain the binary program's running start address by matching the dump memory with the binary program's instruction set architecture features.
[0009] S3: extracting the starting address of the read-only data area of the binary program through multiple consecutive constant character strings in the binary program, and obtaining the ending address of the read-only data area through multiple consecutive characters that do not meet the characteristics of the constant character string after the starting address of the read-only data area, thereby obtaining the size of the read-only data area;
[0010] S4: By analyzing the stack initialization code of the binary program, the starting address of the stack is used as the end address of the data area of the binary program, and the starting address of the data area is obtained by subtracting the size of the read-only data area from the end address of the data area;
[0011] S5: reconstructing the binary program into an executable binary program file according to the binary program's running start address, the read-only data area start address, and the data area start address;
[0012] S6: Decompile and analyze the reconstructed executable binary program file using a decompilation tool.
[0013] Furthermore, the instruction set architecture of the binary program can be obtained through corresponding embedded chip data or a pre-built instruction architecture feature set.
[0014] Furthermore, the method of obtaining the running start address of the binary program in step S2 can also be obtained through the startup log or the interrupt vector table.
[0015] Furthermore, the file formats of executable binary program files include: elf format, exe format, and ipa format.
[0016] Furthermore, before step S5, the method further includes: determining whether the binary program includes a binary subroutine in a custom format, and if so, determining a running start address, a read-only data area start address, and a data area start address of the binary subroutine in the custom format according to the content of the header area of the binary subroutine in the custom format;
[0017] Step S5 also includes: reconstructing the custom format binary subroutine into an executable format binary program file according to the running start address, the read-only data area start address and the data area start address of the custom format binary subroutine.
[0018] A binary program analysis terminal device includes a processor, a memory, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the steps of the method described above are implemented.
[0019] A computer-readable storage medium stores a computer program, which, when executed by a processor, implements the steps of the method described above in an embodiment of the present invention.
[0020] The present invention adopts the above technical solution to enable decompilation and code association analysis of binary programs without executable program structures. BRIEF DESCRIPTION OF THE DRAWINGS
[0021] Figure 1 Shown is a flow chart of embodiment 1 of the present invention.
[0022] Figure 2 Shown is a subroutine schematic diagram of the binary image in this embodiment. DETAILED DESCRIPTION
[0023] To further illustrate various embodiments, the present invention provides accompanying drawings. These drawings form part of the present disclosure and are primarily used to illustrate the embodiments and, in conjunction with the relevant description in the specification, to explain the operating principles of the embodiments. By referring to these drawings, those skilled in the art will be able to understand other possible implementations and the advantages of the present invention.
[0024] The present invention will now be further described with reference to the accompanying drawings and specific embodiments.
[0025] Example 1:
[0026] Compared with common executable binary programs, binary programs without specific program structure often lack information related to program partition layout, such as program execution start address, program size, constant area start address, constant area size, initialized data area start position and size, and other key structural information required for program decompilation analysis. Based on this, the embodiment of the present invention provides a binary program analysis method, such as Figure 1 As shown, the method includes the following steps:
[0027] S1: Obtain the instruction set architecture characteristics of the binary program.
[0028] Binary programs can be bare binary programs in single-chip microcomputers, system boot programs (such as U-BOOT and BIOS) in embedded devices, and manufacturer-defined Img and Bin programs that cannot be directly analyzed using decompilation tools. Executable files in common operating systems are also a type of binary program, such as elf format programs in Linux systems, exe format programs in Windows systems, and ipa format programs in iOS systems. However, most binary programs in fixed structure formats in these operating systems can be directly analyzed using decompilation tools and are beyond the scope of this embodiment.
[0029] Instruction set architecture features can be obtained from the embedded chip data corresponding to the binary program, or from a pre-built instruction architecture feature set. For example, instruction set architecture feature sets such as ARM, MIPS, and POWERPC are formed based on the binary values corresponding to the first few bytes of the starting execution address. For example, the instruction set architecture feature set corresponding to the ARM architecture is JH-ARM{0xEA,0x00,0x00,0xNN}. The first 4 bytes of the ARM architecture store jump instructions, where NN is variable and varies between different chip models.
[0030] S2: Obtain the binary program's running start address by matching the dump memory with the binary program's instruction set architecture features.
[0031] In this embodiment, the method of matching the features of the instruction set architecture of the binary program by dumping the memory can be adopted by dumping the memory binary data in 4K size in sequence, matching the first few bytes of the binary data with the instruction set architecture feature set, and if the match is qualified, it means that the memory address is the execution start address.
[0032] In other embodiments, the starting address of the operation can also be obtained through a boot log or interrupt vector table that stores the starting address of the operation. The starting address of the operation can be obtained from the boot log, such as the boot log U-Boot code:08000000 of the U-Boot system boot, where 08000000 represents the starting address of the binary program booted by the U-Boot system. The interrupt vector table method, such as the interrupt vector table of the ARM architecture, has a field to store the starting address of the operation, which is often located at 0x40, but it varies depending on the CPU model and can be further determined in conjunction with the chip manual.
[0033] S3: Extract the starting address of the read-only data (rodata) area of the binary program through multiple constant character strings that appear continuously in the binary program, and obtain the ending address of the read-only data area through multiple consecutive characters that do not meet the characteristics of the constant character string after the starting address of the read-only data area, thereby obtaining the size of the read-only data area.
[0034] Since constant strings are often placed in the read-only data area when the code is compiled and linked, the starting address of the area storing multiple constant strings is generally the starting address of the read-only data area.
[0035] To ensure accuracy, the number of the multiple constant character strings that appear consecutively in this embodiment should be at least five.
[0036] S4: By analyzing the stack initialization code of the binary program, the starting address of the stack is used as the end address of the data area of the binary program, and the starting address of the data area is obtained by subtracting the size of the read-only data area from the end address of the data area.
[0037] Since the data area often stores initialized global variables or static variables, which are data determined by code variable links, the stack address is required for memory management, and initialization usually follows the data area.
[0038] S5: Reconstruct the binary program into an executable format binary program file according to the running start address of the binary program, the start address of the read-only data area, and the start address of the data area.
[0039] The file formats of the reconstructed executable binary program file include but are not limited to elf format, exe format, and ipa format.
[0040] S6: Decompile and analyze the reconstructed executable binary program file using a decompilation tool.
[0041] Furthermore, since a binary program may contain a custom-format binary subroutine composed of user-defined functions rather than general-purpose functions, and since such a subroutine needs to be analyzed separately rather than directly analyzed via a CPU jump instruction, this embodiment further includes, before step S5, determining whether the binary program contains a custom-format binary subroutine, and if so, determining the execution start address, read-only data area start address, and data area start address of the custom-format binary subroutine based on the contents of the header area of the custom-format binary subroutine. After the address determination is performed, it is also necessary to reconstruct the custom-format binary subroutine into an executable binary program file in step S5 based on the execution start address, read-only data area start address, and data area start address of the custom-format binary subroutine.
[0042] Since subroutines in custom formats also need to be loaded and run, the corresponding information will be stored in the binary program header or inside the program. Figure 2 As shown, this is a subroutine in a binary image of an IoT device, which contains an Img header, indicating that the other three subroutines in the binary program are to be loaded and executed at the starting addresses 01000000, 012BEE00, and 012CFB00, respectively. Therefore, it is necessary to split this subroutine into three subroutines for analysis. Each subroutine determines the starting address of the read-only data area and the starting address of the data area through S3 and S4 above, and then performs structural analysis according to S5.
[0043] After conducting in-depth research and analysis on the characteristics of raw binary programs, the present invention reconstructs the executable binary program files and implements decompilation analysis. This embodiment plays an important role in the forensic analysis of encrypted data and custom format data in IoT devices.
[0044] Example 2:
[0045] The present invention also provides a binary program analysis terminal device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the steps in the above-mentioned method embodiment of the first embodiment of the present invention are implemented.
[0046] Furthermore, as an executable solution, the binary program analysis terminal device can be a computing device such as a desktop computer, laptop, PDA, or cloud server. The binary program analysis terminal device may include, but is not limited to, a processor and memory. Those skilled in the art will appreciate that the above-described component structure of the binary program analysis terminal device is merely an example of a binary program analysis terminal device and does not constitute a limitation on the binary program analysis terminal device. The binary program analysis terminal device may include more or fewer components than those described above, or a combination of certain components, or different components. For example, the binary program analysis terminal device may also include input / output devices, network access devices, buses, etc., which are not limited in this embodiment of the present invention.
[0047] Furthermore, as an executable solution, the processor may be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or any conventional processor, etc. The processor is the control center of the binary program analysis terminal device, and utilizes various interfaces and lines to connect various parts of the entire binary program analysis terminal device.
[0048] The memory can be used to store the computer programs and / or modules. The processor implements various functions of the binary program analysis terminal device by running or executing the computer programs and / or modules stored in the memory and calling the data stored in the memory. The memory can mainly include a program storage area and a data storage area, wherein the program storage area can store an operating system and at least one application required for a function; the data storage area can store data created based on the use of the mobile phone, etc. In addition, the memory can include high-speed random access memory and non-volatile memory, such as a hard disk, internal memory, a plug-in hard disk, a smart media card (SMC), a secure digital (SD) card, a flash card, at least one disk storage device, a flash memory device, or other volatile solid-state storage device.
[0049] The present invention also provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps of the above method in the embodiment of the present invention are implemented.
[0050] If the module / unit integrated in the binary program analysis terminal device is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the present invention implements all or part of the process in the above-mentioned embodiment method, and can also be completed by instructing the relevant hardware through a computer program. The computer program can be stored in a computer-readable storage medium, and when the computer program is executed by the processor, it can implement the steps of the above-mentioned various method embodiments. Among them, the computer program includes computer program code, and the computer program code can be in source code form, object code form, executable file or some intermediate form. The computer-readable medium may include: any entity or device that can carry the computer program code, recording medium, USB flash drive, mobile hard disk, magnetic disk, optical disk, computer memory, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory) and software distribution medium, etc.
[0051] Although the present invention has been particularly shown and described in conjunction with preferred embodiments, it will be understood by those skilled in the art that various changes in form and details may be made to the present invention without departing from the spirit and scope of the invention as defined in the appended claims, and all such changes are within the scope of protection of the present invention.
Claims
1. A binary program analysis method, characterized in that: The following steps are involved: S1: Obtain the instruction set architecture characteristics of the binary program; S2: Obtain the binary program's running start address by matching the dump memory with the binary program's instruction set architecture features. S3: extracting the starting address of the read-only data area of the binary program through multiple consecutive constant character strings in the binary program, and obtaining the ending address of the read-only data area through multiple consecutive characters that do not meet the characteristics of the constant character string after the starting address of the read-only data area, thereby obtaining the size of the read-only data area; S4: By analyzing the stack initialization code of the binary program, the starting address of the stack is used as the end address of the data area of the binary program, and the starting address of the data area is obtained by subtracting the size of the read-only data area from the end address of the data area; S5: reconstructing the binary program into an executable binary program file according to the binary program's running start address, the read-only data area start address, and the data area start address; S6: Decompile and analyze the reconstructed executable binary program file using a decompilation tool.
2. The binary program analysis method according to claim 1, wherein: The instruction set architecture of the binary program can be obtained through corresponding embedded chip data or a pre-built instruction architecture feature set.
3. The binary program analysis method according to claim 1, wherein: The method of obtaining the running start address of the binary program in step S2 can also be obtained through the startup log or the interrupt vector table.
4. The binary program analysis method according to claim 1, wherein: The file formats of executable binary program files include: elf format, exe format, and ipa format.
5. The binary program analysis method according to claim 1, wherein: Before step S5, the method further includes: determining whether the binary program includes a binary subroutine in a custom format, and if so, determining a running start address, a read-only data area start address, and a data area start address of the binary subroutine in the custom format according to the content of the header area of the binary subroutine in the custom format; Step S5 also includes: reconstructing the custom format binary subroutine into an executable format binary program file according to the running start address, the read-only data area start address and the data area start address of the custom format binary subroutine.
6. A binary program analysis terminal device, characterized by: The method comprises a processor, a memory, and a computer program stored in the memory and running on the processor, wherein the processor implements the steps of the method according to any one of claims 1 to 5 when executing the computer program.
7. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 5 are implemented.
Citation Information
Patent Citations
Extracting system for internal curing data of windows application program
CN101393521A