Host and guest message tunnel communication method and system based on virtualized black box escape
By deploying multiple modules on the virtual machine side and building message tunnels using QEMU vulnerabilities, the hidden data exchange problem between the host and the virtual machine is solved, and the host command injection and result echo are automated. It is suitable for multi-version QEMU and multi-cloud manufacturer environments, improving the efficiency of cloud computing security auditing and operation and maintenance diagnosis.
Patent Information
- Application Number
- CN202510603217.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-12
- Publication Date
- 2025-08-26
AI Technical Summary
In a cloud computing environment, how to establish a hidden data exchange channel between the host and the virtual machine, realize host command execution and result echo, especially automated operations under external network isolation and unknown network connectivity, and is suitable for multi-version QEMU or multiple cloud vendor environments.
By deploying multiple collaboration modules on the virtual machine side, including function address detection, command listening, shellcode generation and command injection execution modules, the QEMU vulnerability is used to build a message tunnel, and the host command injection and result return are realized, avoiding external network dependencies and manually writing complex shellcodes.
It realizes efficient and stable communication between the host and the virtual machine, lowers the technical threshold, improves the efficiency of security auditing and operation and maintenance diagnosis, and is suitable for cloud computing scenarios with strict network isolation.
Smart Images

Figure CN120541844A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of cloud computing and virtualization security, and in particular to a host-guest message tunnel communication method and system based on virtualization black box escape. Background Art
[0002] In cloud computing scenarios, a large number of virtual machine instances are centrally managed and scheduled by the host, providing users with flexible computing and storage resources. To meet performance and compatibility requirements, many cloud servers use QEMU (QuickEmulator) to implement hardware emulation and virtualization, assisting kernel modules like KVM in better managing virtual machines. Through QEMU, the host can provide diverse hardware emulations for CPU, memory, I / O, and other functions in user mode, meeting the operational requirements of different virtual machine images or operating systems.
[0003] In this environment, a certain security boundary often exists between the host and virtual machines. However, with the rapid development of cloud computing, new vulnerabilities are constantly being discovered and disclosed, particularly those targeting QEMU itself. Because QEMU executes in user mode and requires data to be passed between multiple child processes or background services, any memory out-of-bounds reads and writes, function pointer tampering, or device emulation flaws can be exploited by malicious users to break through the original isolation mechanism between the host and virtual machines.
[0004] In common virtualization attack scenarios, attackers need to obtain sensitive information from the host machine or execute unauthorized system commands. However, traditional methods often require the host machine to have external network connectivity or the attacker to have partial visibility and interaction with the host machine. If the host machine is highly isolated and disconnected from the external network, it is difficult for the attacker to directly transmit command results or log information back to the virtual machine. In addition, many exploitation steps for QEMU vulnerabilities only provide basic "host execution privilege acquisition" methods, lacking a systematic solution for how to subsequently transmit the host machine's execution results or echo data back to the virtual machine and complete automated operations in network isolation scenarios.
[0005] When conducting security audits or attack and defense drills, researchers hope to automatically generate exploit code, trigger host command execution, and obtain complete echo output through the virtual machine, without an unknown host environment and unknown network connectivity. If there are no available external network tunnels or bypass channels, they need to rely on in-depth research on QEMU vulnerability characteristics, shared memory, or device simulation communication mechanisms to establish a "covert" data exchange channel between the virtual machine and the host. In practice, if this process still needs to be completed manually, such as manually writing shellcode or trying function pointer addresses line by line, the technical threshold is high and the portability is weak, which is not conducive to rapid adaptation to multiple versions of QEMU or multiple cloud vendor environments.
[0006] Therefore, how to automatically complete host command execution and transmit output results to the virtual machine side without relying on external network connections under the premise that there are vulnerabilities in the underlying QEMU of the cloud server has become one of the key challenges in virtualization security research and operation and maintenance diagnosis. Summary of the Invention
[0007] The present invention aims to provide a host-guest message tunnel communication method and system based on virtualization black box escape. By combining a multi-script linkage mechanism with the QEMU vulnerability exploitation framework, this method enables efficient and stable host command injection and real-time echo result acquisition, even when the host is isolated from the external network and users are unable to directly interact with the host. By deploying a tool system containing multiple collaborative modules on the virtual machine side, this method addresses the existing problem of being unable to obtain host execution results in real time. This method is widely applicable to security audits and vulnerability verification in QEMU / KVM virtualization environments.
[0008] On the one hand, the present invention proposes a host-guest message tunnel communication method based on virtualized black box escape, comprising the following steps:
[0009] S1. Start the QEMU virtual machine environment on the host machine, the user enters the virtual machine, and then uses the QEMU vulnerability to detect the host machine's key function address or symbol information, and output the results to the terminal.
[0010] S2. Capture the commands entered by the user in real time and display them on the terminal. At the same time, continuously monitor the command execution result data returned by the host machine and display it on the terminal in real time.
[0011] S3, based on the output results of S1 and S2, dynamically parses and generates a shellcode string that can trigger the execution of host commands, and outputs the shellcode to the terminal or file.
[0012] S4. Overwrite the generated shellcode to the corresponding file reserved area and compile it. When the virtual machine runs, its embedded shellcode triggers the host machine command execution through the QEMU vulnerability attack surface, and uses the message tunnel built by the vulnerability to transmit the execution result back to the virtual machine in real time to complete the communication.
[0013] On the other hand, the present invention provides a host-guest message tunnel communication system based on virtualization black box escape. The technical solution utilizes the memory management defects, function pointer leakage or device simulation vulnerabilities existing in QEMU user mode operation, and executes multiple modules in sequence on the virtual machine side: function address detection module (getfunc module), command monitoring module (watch module), shellcode generation module (getshellcode module) and command injection execution module (workshellcode module).
[0014] Function address detection module, which uses QEMU vulnerabilities to detect key function addresses or symbol information of the host machine and outputs the results to the terminal;
[0015] The command monitoring module is used to capture the commands entered by the user in real time and display them on the terminal. At the same time, it continuously monitors the command execution result data returned by the host machine and displays it on the terminal in real time.
[0016] The shellcode generation module dynamically parses and generates a shellcode string that can trigger the execution of host commands based on the output results of the function address detection module and the command monitoring module, and outputs the shellcode to the terminal or file;
[0017] The command injection execution module is used to overwrite the generated shellcode into the reserved area of the file corresponding to the command injection execution module, compile and generate a new command injection execution module. When the user runs the command injection execution module on the virtual machine side, its embedded shellcode triggers the host machine command execution through the QEMU vulnerability attack surface, and uses the message tunnel built by the vulnerability to transmit the execution result back to the virtual machine side in real time.
[0018] Through the linkage of the above-mentioned collaborative modules, the present invention does not require the host machine to be connected to the external network, nor does it require the user to manually write complex shellcode or perform tedious configuration. It can automatically implement command injection and result feedback, significantly reducing the difficulty of cloud environment security auditing and operation and maintenance diagnosis, and has good versatility and convenience.
[0019] Beneficial effects of the present invention:
[0020] The black box escape system described in the present invention is widely applicable to cloud computing security audits, vulnerability verification, operation and maintenance troubleshooting, and emergency response scenarios. It is particularly suitable for typical cloud computing security scenarios where the host machine is strictly isolated from the network and users cannot directly interact with the host machine. It can effectively improve the visibility and troubleshooting efficiency of security issues in virtualized environments. BRIEF DESCRIPTION OF THE DRAWINGS
[0021] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0022] Figure 1 This diagram illustrates the overall process of black box escape in the QEMU virtualization environment, covering the process of host machine command injection and result transmission back to the virtual machine.
[0023] Figure 2 A schematic diagram illustrating the logical framework of the module linkage execution process in the present invention;
[0024] Figure 3 A schematic diagram illustrating the command output and return structure of the present invention;
[0025] Figure 4 A typical application scenario deployment example of the present invention is illustrated;
[0026] The above drawings merely illustrate one or more typical embodiments of the present invention and are used to assist in illustrating the technical principles and processes of the present invention; they are not intended to limit the scope of protection of the present invention. Those skilled in the art may, without inventive effort, replace, refine, or partially modify the drawings to achieve the same functions or objectives as the present invention.
[0027] The specific embodiments of the present invention are described in detail below with reference to the accompanying drawings.
[0028] When implementing the present invention, unless otherwise specified, the logical order of each step or module may be appropriately changed, or may be executed simultaneously by parallel processes. The present invention is not limited to the specific hardware and software environment in which it is implemented. All such implementations fall within the scope of protection of the present invention, provided that they do not violate the spirit and substance of the present invention. DETAILED DESCRIPTION
[0029] In order to make the purpose, technical solutions and advantages of this application more clear, the following further describes this application in detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain this application and are not intended to limit this application.
[0030] The present invention will be further described below with reference to the accompanying drawings and specific embodiments.
[0031] In a typical embodiment, the present invention may be based on Figure 1The overall process shown in the figure is executed. This process mainly includes the following stages: virtual machine environment deployment stage, function and command collection stage, shellcode generation and compilation stage, and host machine command echo acquisition stage.
[0032] First, install and start QEMU on the cloud server host to form a virtual machine instance that can be accessed by users remotely. The virtual machine provides standard remote access methods such as SSH, and users log in to the virtual machine system with corresponding credentials. The multi-module tool set of the present invention is pre-deployed in the virtual machine (see Figure 1 ), including a function address detection module (getfunc module), a command monitoring module (watch module), a shellcode generation module (getshellcode module), and a command injection execution module (workshellcode module).
[0033] A host-guest message tunnel communication method based on virtualized black box escape Figure 2 The overall process shown includes the following steps:
[0034] Step S1: After the user logs in to the virtual machine system with the corresponding credentials, the pre-set function address detection module (getfunc module) is first executed. This module exploits known or potential vulnerabilities in QEMU (such as memory read / write out-of-bounds, function pointer leakage, etc.) to automatically detect key function addresses or symbol information within the host machine that can be used for attack, and directly outputs this detected information to the virtual machine terminal. This process utilizes QEMU user-mode memory mapping or device emulation mechanism to enable the virtual machine to indirectly obtain relevant information about the host machine.
[0035] Step S2: User Execution Command Monitoring Module (watch module). This module captures commands entered by the user through the terminal in real time, such as system management instructions or sensitive information viewing instructions, and displays these commands on the terminal to assist in the subsequent shellcode generation. Furthermore, the watch module monitors the echo data displayed by the host after executing commands. Once the command execution result is detected, the echo data is immediately displayed on the virtual machine terminal in real time, providing real-time and intuitive feedback to the user.
[0036] Step S3: The user runs the shellcode generation module (getshellcode module). During runtime, the user needs to provide the module with several necessary parameters, which come from the output results of the function address detection module (getfunc module) and the command monitoring module (watch module). The shellcode generation module parses these input parameters to obtain the key function addresses that can be used by the host machine and the target command entered by the user. It uses the specific jump mechanism or memory operation logic in the QEMU vulnerability environment to dynamically generate shellcode code that can trigger the execution of the target command on the host machine. After the generation is completed, the shellcode generation module will output the generated shellcode as a string to the terminal or file for compilation in the next stage.
[0037] Step S4: After the user obtains the above shellcode code, it is overwritten into the designated shellcode placeholder area prepared in advance in the command injection execution module to complete the replacement of the original placeholder code. Subsequently, the user generates a new command injection execution module (workshellcode module).
[0038] Step S5: The user executes the command injection execution module (workshellcode module) generated above on the virtual machine. The shellcode embedded in this module leverages the QEMU vulnerability attack surface to trigger corresponding system calls or function calls in the host environment, enabling remote execution of the user's previously entered commands. The execution results are then transmitted back to the virtual machine in real time using the message tunnel established by the vulnerability. This process does not require the host machine to have external network connectivity, nor does it require the user to have additional permissions or specific configuration conditions on the host machine to complete the cross-border instruction injection operation on the host machine.
[0039] Step S6: At the same time (such as Figure 3 As shown in the figure, the echo output generated by the host command execution is redirected to a specific address space or I / O buffer area accessible to the virtual machine by exploiting the QEMU vulnerability. At this time, the command monitoring module (watch module) continuously monitors the host machine's output data in real time and immediately displays the monitored data directly on the virtual machine terminal, allowing users to intuitively observe and verify the specific results of the host command execution without additional operation.
[0040] The present invention also provides a host-guest message tunnel communication system based on virtualized black box escape, comprising the following modules:
[0041] The function address detection module exploits QEMU vulnerabilities to detect key function addresses or symbol information of the host machine and outputs the results to the terminal.
[0042] The command monitoring module is used to capture the commands entered by the user in real time and display them on the terminal. At the same time, it continuously monitors the command execution result data returned by the host machine and displays it on the terminal in real time.
[0043] The shellcode generation module dynamically parses and generates a shellcode string that can trigger the execution of host commands based on the output results of the function address detection module and the command monitoring module, and outputs the shellcode to the terminal or file.
[0044] The command injection execution module is used to overwrite the generated shellcode into the reserved area of the file corresponding to the command injection execution module, compile and generate a new command injection execution module. When the user runs the command injection execution module on the virtual machine side, its embedded shellcode triggers the host machine command execution through the QEMU vulnerability attack surface, and uses the message tunnel built by the vulnerability to transmit the execution result back to the virtual machine side in real time.
[0045] Example:
[0046] The present invention can be deployed and verified in a typical cloud computing platform or virtualization environment. During specific implementation, QEMU and KVM modules are installed on the host machine to create and manage multiple virtual machine instances. One of the virtual machine instances is selected as the target instance for security testing, attack and defense drills or vulnerability verification. The virtual machine instance is pre-installed with a tool set such as a function address detection module (getfunc module), a command monitoring module (watch module), a shellcode generation module (getshellcode module) and a command injection execution module (workshellcode module). After researchers or operation and maintenance personnel remotely log in to the virtual machine, they can run the above modules in sequence to efficiently generate shellcode for host machine vulnerabilities, and ultimately realize the remote injection and echo return functions of host machine commands, completing black box escape testing and verification.
[0047] In actual use, the present invention also has the following extension methods:
[0048] The symbol resolution logic in the script can be adjusted for different QEMU versions or QEMU branches customized by cloud service providers.
[0049] The shellcode generation strategy can be optimized, such as adding custom encryption or obfuscation, to evade security detection or delay protection mechanisms.
[0050] The present invention can be used in conjunction with other penetration testing tools and embedded as a module into the existing security audit system to achieve automated batch verification and recording.
[0051] In summary, the present invention automatically generates and executes shellcode by deploying multiple modules on the virtual machine side and implementing linkage operations, thereby building a message tunnel between the host machine and the virtual machine. Without relying on external network connections, requiring additional host machine permissions or special configurations, cross-border injection of host machine commands and efficient return of echo results are achieved. The technical solution of the present invention lowers the threshold for technical verification of black box escape attacks in cloud environments, security operation and maintenance audits, vulnerability analysis and emergency response, and has broad application prospects. It should be understood that the above is only a typical embodiment of the present invention. Without departing from the principles of the present invention, those skilled in the art may make appropriate changes or adjustments to the specific embodiments, and these changes and adjustments are still within the scope of protection of the present invention.
[0052] Experimental verification:
[0053] The feasibility of this invention was verified on a local cloud experimental platform. The hardware and software environment used in the experiment is as follows:
[0054] QEMU version: 5.1.0 (KVM acceleration enabled, default compilation options)
[0055] Host operating system: Ubuntu 20.04LTS, Linux 5.15.0 kernel.
[0056] Virtual machine (guest) operating system: Ubuntu 20.04LTS.
[0057] During the experiment, an Ubuntu 20.04 virtual machine instance was first created on the host machine using QEMU 5.1.0, and the four core modules of the present invention were pre-installed: a function address detection module (getfunc), a command monitoring module (watch), a shellcode generation module (getshellcode), and a command injection execution module (workshellcode). After the researchers logged into the virtual machine, they executed the getfunc module in sequence to obtain the key function address of the host machine, executed the watch module to input the system command to be run and prepared to monitor the echo, ran the getshellcode module to generate shellcode for the current environment, and embedded and compiled the generated result into the workshellcode module. The workshellcode module was then started on the virtual machine side, and the QEMU user mode vulnerability was used to successfully trigger the " / sbin / ifconfig" command on the host machine. The watch module echoed the host machine network card configuration (such as the IP / MAC information of the eth0 and lo interfaces) in real time, verifying the validity of the message tunnel. The entire process does not rely on external network connection, and there is no need to grant additional permissions on the host side.
[0058] The experimental results are as follows Figure 4As shown, the terminal not only records the command input but also displays the execution results of the host machine in real time. Tests show that under QEMU 5.1.0 and Linux 5.15.0, the host-to-virtual machine message tunnel constructed by this invention can stably complete command injection and result transmission, fully verifying the feasibility and versatility of the system design.
Claims
1. A host-guest message tunnel communication method based on virtualized black box escape, characterized in that: The following steps are involved: S1. Start the QEMU virtual machine environment on the host machine, the user enters the virtual machine, and then uses the QEMU vulnerability to detect the host machine's key function address or symbol information and output the results to the terminal; S2. Capture the commands entered by the user in real time and display them on the terminal. Meanwhile, continuously monitor the command execution result data returned by the host machine and display them on the terminal in real time. S3, based on the output results of S1 and S2, dynamically parses and generates a shellcode string that can trigger the execution of host commands, and outputs the shellcode to the terminal or file; S4. Overwrite the generated shellcode to the corresponding file reserved area and compile it. When the virtual machine runs, its embedded shellcode triggers the host machine command execution through the QEMU vulnerability attack surface, and uses the message tunnel built by the vulnerability to transmit the execution result back to the virtual machine in real time to complete the communication.
2. The host-guest message tunnel communication method based on virtualized black box escape according to claim 1 is characterized in that: The specific implementation of step S1 is as follows: after the user logs in to the virtual machine system with the corresponding credentials, function address detection is first performed, and known or potential vulnerabilities of QEMU are used to automatically detect key function addresses or symbol information used for attack in the host machine, and the detected information is directly output to the virtual machine terminal. This process uses the memory mapping or device simulation mechanism of QEMU user mode to enable the virtual machine to indirectly obtain relevant information of the host machine.
3. The host-guest message tunnel communication method based on virtualized black box escape according to claim 2 is characterized in that: The specific implementation of step S2 is as follows: on the one hand, the commands to be executed entered by the user through the terminal are captured in real time, and these commands are immediately displayed on the terminal to assist in the subsequent generation of shellcode; on the other hand, the watch module simultaneously monitors the echo data after the host machine executes the command in real time; once the command execution result returned by the host machine is detected, the echo data is immediately displayed in real time on the virtual machine terminal, providing the user with real-time and intuitive feedback information.
4. The host-guest message tunnel communication method based on virtualized black box escape according to claim 3 is characterized in that: Step S3 is specifically implemented as follows: the user provides several parameters, which are output from function address detection and command monitoring; according to the input parameters, the key function address used by the host machine and the target command input by the user are parsed, and the jump mechanism or memory operation logic in the QEMU vulnerability environment is used to dynamically generate shellcode code that can trigger the execution of the target command on the host machine side; After the generation is completed, the shellcode generation module outputs the generated shellcode in the form of a string to the terminal or file.
5. The host-guest message tunnel communication method based on virtualized black box escape according to claim 4 is characterized in that: The specific implementation process of step S4 is as follows: Step S4.1: After the user obtains the above shellcode, it is written over the designated shellcode placeholder area prepared in advance in the command injection execution module to replace the original placeholder code; Step S4.2: The shellcode uses the QEMU vulnerability attack surface to trigger the corresponding system call or function call in the host environment, thereby remotely executing the command previously entered by the user, and uses the message tunnel established by the vulnerability to transmit the execution result back to the virtual machine in real time; Step S4.3: The echo output result generated after the host command is executed is redirected to the address space or I / O buffer area accessible to the virtual machine by exploiting the QEMU vulnerability. At this time, the host machine's output data is continuously monitored in real time, and the monitored data is immediately displayed directly on the virtual machine terminal, allowing the user to intuitively observe and verify the specific results of the host command execution.
6. A host-guest message tunnel communication system based on virtualized black box escape, used to implement the host-guest message tunnel communication method according to any one of claims 1 to 5, characterized in that: Includes the following modules: Function address detection module, which uses QEMU vulnerabilities to detect key function addresses or symbol information of the host machine and outputs the results to the terminal; The command monitoring module is used to capture the commands entered by the user in real time and display them on the terminal. At the same time, it continuously monitors the command execution result data returned by the host machine and displays it on the terminal in real time. The shellcode generation module dynamically parses and generates a shellcode string that can trigger the execution of host commands based on the output results of the function address detection module and the command monitoring module, and outputs the shellcode to the terminal or file; The command injection execution module is used to overwrite the generated shellcode into the reserved area of the file corresponding to the command injection execution module, compile and generate a new command injection execution module. When the user runs the command injection execution module on the virtual machine side, its embedded shellcode triggers the host machine command execution through the QEMU vulnerability attack surface, and uses the message tunnel built by the vulnerability to transmit the execution result back to the virtual machine side in real time.