User space program Inlinehook method based on Loongarch architecture and medium

The precise hook of applications and static library functions is implemented on LoongArch CPU through ptrace and mmap memory injection technology, solving the compatibility and dependency problems of the existing technology, and providing non-invasive function monitoring and analysis tools.

CN120578438AActive Publication Date: 2025-09-02中孚安全技术有限公司
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
CN202511086422.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-05
Publication Date
2025-09-02
Estimated Expiration
2045-08-05

AI Technical Summary

Technical Problem

The existing Inline Hook framework does not support LoongArch CPU, cannot hook the application's own functions or functions loaded by static libraries, and it relies heavily on the system kernel version implementation, resulting in compatibility and stability issues.

Method used

Through ptrace's process control and mmap memory injection technology, the target process's registers are hijacked and hook modules are injected, and the function's beginning instructions are backed up and replaced to accurately intercept applications and static library functions, and to use pure user space to avoid kernel dependencies.

Benefits of technology

It realizes the comprehensive Hook capability of the application's own functions and static library functions, eliminates strong dependence on the system kernel version, and builds a non-invasive function behavior monitoring system, providing finer-grained analysis tools and better system compatibility.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120578438A_ABST
    Figure CN120578438A_ABST
Patent Text Reader

Abstract

The invention discloses a user space program Inlinehook method based on a Loongarch architecture and a medium, and mainly relates to the technical field of user space programs. The method and the device are used for solving the problems that in an existing scheme, a function of an application program based on a Loongarch architecture or a function loaded by a static library cannot be hooked, a behavior of calling a common library function by the application program cannot be hooked, and implementation of system kernel versions is seriously depended. Comprising the following steps: skipping to a second-level springboard of a hook module by presetting a first-level springboard assembly code; the current execution site is stored through a second-level springboard, and execution is performed by skipping to a preset unified hook logic execution function; calling a user-defined function through a preset unified hook logic execution function; and after the user-defined function is executed, skipping back to the secondary springboard, skipping to the repaired assembly instruction code, and skipping to the head of the hook function which is shifted by 6 bytes.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field of user space program inlinehook, and in particular to a user space program inlinehook method and medium based on Loongarch architecture. Background Art

[0002] Inline hooks, also known as inline hooks, are a method for intercepting target function calls, primarily used in antivirus, security, and sandbox software. The basic idea is to redirect a function to your own function, allowing for pre- and post-processing. This can include parameter checking, stubbing, logging, modifying return data, and filtering calls. Security software often uses this technique to prevent or monitor potentially malicious activity.

[0003] None of the existing Inline Hook frameworks support LoongArch CPUs. On LoongArch-based domestic systems, such as Kylin and Tongxin UOS, preload hooks, kernel syscall hooks, and ebpf are often used to implement behavior monitoring and other functions. However, these technologies all have their limitations. Specifically, preload hooks cannot hook the application's own functions or functions loaded by static libraries. Kernel syscall hooks cannot hook the behavior of applications calling ordinary library functions. Ebpf heavily relies on the system kernel version for implementation, and most functional modules cannot be used. Summary of the Invention

[0004] The present application provides a user space program inlinehook method and medium based on the Loongarch architecture to solve the problems of existing solutions that are unable to hook the application's own functions or functions loaded from static libraries, unable to hook the behavior of the application calling ordinary library functions, and heavily dependent on the system kernel version implementation.

[0005] In a first aspect, the present application provides a user space program inlinehook method based on the Loongarch architecture, the method comprising: The control program's own process tracer uses the attach operation of ptrace to hijack the preset controlled process tracee; After the attach operation is successfully hijacked, the current register of the process tracee is obtained for caching; Use the libc library loading address and mmap function address of process tracer and the library loading address of process tracee to obtain the mmap function address of process tracee; Configure the register configuration related to the mmap function in the process tracee through the process tracer, run the mmap function of the process tracee, allocate a preset memory in the process tracee, obtain the return address of the mmap function of the process tracee, and inject the hook module into the preset memory; The backup process tracee hooks the first 5 bytes of the assembly instruction code of the function into the allocated preset memory; the backup first 5 bytes of the assembly instruction code are repaired by address jump instructions to obtain the repaired assembly instruction code; Replace the first 5 bytes of the function to be hooked with the preset first-level springboard assembly code, and convert the function to be hooked into the hooked function; after the replacement is completed, end the hijacking process tracee; The process tracee resumes normal use. When the process tracee executes the hooked function, it executes the preset first-level springboard assembly code, and jumps to the second-level springboard of the hook module through the preset first-level springboard assembly code; the current execution scene is saved through the second-level springboard, and the input parameter information of the hooked function is obtained, and then it jumps to the preset unified hook logic execution function for execution; wherein, the preset unified hook logic execution function is used to extend the user-defined function; The user-defined function is called through the preset unified hook logic execution function, and the input parameters are passed to the user-defined function; after executing the user-defined function, it jumps back to the secondary springboard, restores the execution scene, jumps to the repaired assembly instruction code, jumps to the offset of 6 bytes at the beginning of the hooked function, and executes the process tracee of the hooked function.

[0006] In one implementation of the present application, the attach operation of ptrace is used to hijack the preset control process tracee, specifically including: According to the preset process number pid of the control process tracee, use ptrace attach to operate to the process with the process number pid; Wait for the process to enter the STOPPED state and obtain the current registers of the process tracee for caching.

[0007] In one implementation of the present application, the mmap function address of the process tracer is obtained by using the libc library loading address and mmap function address of the process tracee and the library loading address of the process tracee, specifically including: Use dlsym to get the mmap function address of the tracer process; Use the Linux system / proc / pid / maps to obtain the libc library function address of the tracer process and process tracee; The relative offset is calculated based on the offset of the tracer process's mmap function address relative to its own libc library function address; Add the relative offset to the libc library function address of the process tracee to get the mmap function address of the process tracee.

[0008] In one implementation of the present application, the register configuration of the process tracee is modified by the tracer process, and then the mmap function of the process tracee is called to allocate a preset memory in the process tracee through the mmap function, specifically including: According to the Loongarch register preset convention, the tracer process uses ptrace PTRACE_SETREGSET to set the six parameters of the mmap function address of the process tracee to the r4-r9 registers of the process tracee, set the r1 register of the process tracee to an illegal address, and set the pc register of the process tracee to the mmap function address; The tracer process uses ptrace PTRACE_CONT to resume execution of the process tracee. The process tracee executes the mmap function and allocates a preset memory specified by the mmap function in the process tracee.

[0009] In one implementation of the present application, injecting a hook module into a preset memory specifically includes: Read the hook module binary file into the process tracer memory, and use ptrace PTRACE_POKEDATA to write the hook module into the preset memory allocated by the process tracee.

[0010] In one implementation of the present application, the backup process tracee hooks the first 5 bytes of the assembly instruction code of the function into the allocated preset memory; performs address jump instruction repair on the backup first 5 bytes of the assembly instruction code to obtain the repaired assembly instruction code, specifically including: Use ptrace PTRACE_SETREGSET to set the r1 register of the process tracee to an illegal address and the pc register to the preset memory start address allocated by the process tracee; Use ptrace PTRACE_CONT to resume the process tracee and execute the injection function of the hook module; The injection function is allocated to the preset memory, and the first 5 bytes of the assembly instruction code of the function to be hooked are copied to the allocated preset memory; The injected function is used to repair the address jump instruction of the copied first 5 bytes of assembly instruction code: Repairing the branch jump instruction relative to the pc register and determining the instruction type of the branch jump instruction to be repaired; wherein the instruction type includes a non-logical judgment instruction and a logical judgment instruction; When it is a non-logical judgment instruction, obtain the pc address and relative offset of the non-logical judgment instruction according to the formula: Absolute address = pc address + sign_extend64(off, 28), Calculate the absolute address of the jump; where sign_extend64 is the unsigned extension defined by Loongarch; transfer the calculated absolute address to the four assembly instructions lu12i.w, ori, lu32i.d, and lu52i.d; and then use the four assembly instructions lu12i.w, ori, lu32i.d, and lu52i.d together with the jirl instruction as the repaired assembly instruction code; When it is a logic judgment instruction, get the value and offset value of the pc register according to the formula: Absolute address = value of pc register + offset value, The absolute address of the jump is calculated, and the branch jump instruction is replaced with an instruction that is logically opposite to the branch jump instruction as the repaired assembly instruction code.

[0011] In one implementation of the present application, after the replacement is completed, the attach operation hijacking process tracee is terminated, specifically including: When the injection function of the hook module injected into the process tracee completes replacing the first 5 bytes of the hook function with the preset first-level springboard assembly code, Use ptrace PTRACE_SETREGS to set the registers to the register values ​​cached when the attach operation is successfully hijacked, and restore the initial register state of the process tracee when it was hijacked; Call ptrace PTRACE_DETACH to release the hijacking of process tracee, and process tracee resumes normal execution.

[0012] In one implementation of the present application, the current execution scene is saved through a secondary springboard, the input parameter information of the hooked function is obtained, and then the execution function is executed by jumping to the preset unified hook logic, specifically including: The secondary springboard of the hook module saves the current execution scene of the hooked function; specifically, the current CPU register values ​​are saved to the stack through assembly instructions; the data to be saved include: parameter registers a0-a7, save registers s0-s8, frame pointer fp and return address ra; Configure the input parameter information of the hooked function to the current CPU register; Execute the function by presetting a unified hook logic: invocation(FunctionContext* func_ctx, CpuContext * cpu_ctx), passes the input parameter information to the user-defined function; Among them, func_ctx contains the user-defined function and the hooked function information, cpu_ctx is the current register information of the hooked function, and contains the input parameter information of the hooked function.

[0013] In one implementation of the present application, after executing the user-defined function, the process jumps back to the secondary springboard, restores the execution scene, jumps to the repaired assembly instruction code, jumps to the beginning of the hooked function offset by 6 bytes, and executes the process tracee of the hooked function, specifically including: After executing the user-defined function, jump back to the secondary springboard and restore the parameter registers a0-a7, save registers s0-s8, frame pointer fp and return address ra previously saved to the stack; Jump to the assembly instruction code after the repair of the hook module, jump to the beginning of the hooked function offset by 6 bytes for execution, and execute the process tracee of the hooked function.

[0014] In a second aspect, the present application provides a non-volatile computer storage medium having computer instructions stored thereon, which, when executed, implements any of the above-mentioned user space program inlinehook methods based on the Loongarch architecture.

[0015] It can be seen from the above technical solutions that this application has the following advantages: 1. Comprehensive Hooking capabilities for application functions and static library functions are realized: Traditional solutions are limited by the interception range of dynamic link library functions. However, this technology uses the process control mechanism of ptrace and mmap memory injection technology to dynamically modify the instruction stream of the target process. Specifically, (1) After using the tracer process to obtain the mmap function address of the process tracee, ptrace can be used to allocate preset memory and inject the hook module at any location in its memory space, breaking the limitation of the fixed address of static library functions; (2) By backing up and replacing the initial instructions of the original function, both internal functions of the application and static link library functions can be accurately intercepted, overcoming the limitation of traditional solutions that can only hook dynamic library functions. This deep control capability provides more fine-grained analysis tools for software debugging, security monitoring and other fields.

[0016] 2. Eliminate strong dependence on the system kernel version: Existing technologies usually rely on specific kernel modules or system call interfaces, while this application adopts a pure user space implementation: by configuring Loongarch registers and repairing assembly instructions (such as dynamic relocation of relative addressing instructions), the hooking process is completely run in user mode. Its advantages are: (1) There is no need to modify kernel code or load kernel modules, avoiding compatibility issues caused by kernel version differences; (2) Process control is achieved through the ptrace standard interface, ensuring universality between different system versions of the Loongarch architecture; (3) Memory injection and instruction repair are both completed in user space, reducing the risk of system crashes.

[0017] 3. Constructing a non-intrusive function behavior monitoring system: The technical solution achieves transparent interception of common library function calls through a three-stage "backup-replace-jump" mechanism (backup original instruction → jump to custom function → execute original instruction and return). Its core features are: (1) dynamic writing of the springboard address eliminates the need to modify the source code of the hooked program during the monitoring process; (2) register state preservation and instruction stream recovery mechanisms ensure the integrity of the hooked process's execution logic; (3) flexible insertion of custom execution functions provides a standardized interface for scenarios such as performance analysis and vulnerability detection. This design not only ensures system stability but also provides a programmable monitoring framework for function-level behavior analysis. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] In order to more clearly illustrate the technical solution of the present invention, the following is a brief introduction to the drawings required for the description. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0019] Figure 1 This is a flow chart of a user space program Inlinehook method based on the Loongarch architecture provided in an embodiment of the present application. DETAILED DESCRIPTION

[0020] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.

[0021] It should be understood by those skilled in the art that the embodiments described below are merely preferred embodiments of the present disclosure and do not imply that the present disclosure can only be implemented through these preferred embodiments. These preferred embodiments are merely intended to explain the technical principles of the present disclosure and are not intended to limit the scope of protection of the present disclosure. Based on the preferred embodiments provided by the present disclosure, all other embodiments obtained by those skilled in the art without creative effort should still fall within the scope of protection of the present disclosure.

[0022] It should also be noted that the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, commodity, or apparatus that includes a series of elements includes not only those elements but also other elements not explicitly listed, or includes elements inherent to such process, method, commodity, or apparatus. In the absence of further limitations, an element defined by the phrase "comprises a ..." does not exclude the presence of other identical elements in the process, method, commodity, or apparatus that includes the element.

[0023] The technical solutions proposed in the embodiments of the present application are described in detail below with reference to the accompanying drawings.

[0024] The embodiment provides a user space program Inlinehook method based on Loongarch architecture, such as Figure 1 As shown, the method provided in the embodiment of the present application mainly includes the following steps: Step 110, the control program's own process tracer uses the attach operation of ptrace to hijack the preset controlled process tracee; ​​after the attach operation is successfully hijacked, the current register of the process tracee is obtained for caching; the mmap function address of the process tracee is obtained by using the libc library loading address and mmap function address of the process tracer and the library loading address of the process tracee.

[0025] In some embodiments, the control program's own process tracer uses the attach operation of ptrace to hijack the preset controlled process tracee, specifically including: According to the preset process number pid of the control process tracee, use ptrace attach to operate to the process with the process number pid; Wait for the process to enter the STOPPED state and obtain the current registers of the process tracee for caching.

[0026] It should be noted that after using ptrace's attach operation to hijack the preset control process tracee, the current registers of the process can be obtained and cached for future restoration after the injection is completed.

[0027] The mmap function address of the process tracee is obtained by using the libc library loading address and mmap function address of the process tracer and the library loading address of the process tracee, specifically including: Use dlsym to get the mmap function address of the tracer process; Use the Linux system / proc / pid / maps to obtain the libc library function address of the tracer process and process tracee; The relative offset is calculated based on the offset of the tracer process's mmap function address relative to its own libc library function address; Add the relative offset to the libc library function address of the process tracee to get the mmap function address of the process tracee.

[0028] Based on the above description, those skilled in the art will appreciate that this step achieves precise control of the target process through the ptrace process control mechanism. This has three beneficial effects: First, by hijacking the target process through the attach operation and caching its register state, the target process maintains a stable execution environment for subsequent injection operations and provides a foundation for process state recovery. This non-destructive process control approach avoids the risk of process crashes that can occur with traditional approaches. Second, by dynamically calculating the mmap function address, the target function is located by comparing the libc base address offsets of the tracer and the process tracee. This effectively addresses the function location challenge caused by address space randomization (ASLR) between different processes. This method does not rely on specific kernel versions or debug symbols, resulting in improved system compatibility. Finally, the entire process is performed entirely in user space, requiring no kernel module support or special permission configuration. Necessary information is obtained through the standard ptrace interface and the / proc file system, meeting the requirements of security monitoring scenarios while minimizing intrusion into the system's operating environment.

[0029] Step 120: Configure register configuration related to the mmap function in the process tracee through the process tracer, run the mmap function of the process tracee, allocate a preset memory in the process tracee, obtain the return address of the mmap function of the process tracee, and inject the hook module into the preset memory.

[0030] The process tracer configures register configuration related to the mmap function in the process tracee, runs the mmap function of the process tracee, allocates a preset memory in the process tracee, and obtains the return address of the mmap function of the process tracee, including: According to the Loongarch register preset convention, the tracer process uses ptrace PTRACE_SETREGSET to set the six parameters of the mmap function address of the process tracee to the r4-r9 registers of the process tracee, set the r1 register of the process tracee to an illegal address, and set the pc register of the process tracee to the mmap function address; The tracer process uses ptrace PTRACE_CONT to resume execution of the process tracee. The process tracee executes the mmap function and allocates a preset memory specified by the mmap function in the process tracee.

[0031] It should be noted that the process tracee executes the mmap function and allocates a preset memory specified by the mmap function in the process tracee. The tracer process uses waitpid to wait for the SIGSEGV signal of tracee. Since an illegal return address is set, after tracee executes mmap, a segmentation fault will occur due to encountering an illegal return address, so the control is returned to the tracer.

[0032] Among them, the hook module is injected into the preset memory, specifically including: Read the hook module binary file into the initial memory; Use ptrace PTRACE_POKEDATA to write the initial memory to the preset memory allocated by the process tracee.

[0033] Based on the above description, those skilled in the art will appreciate that this step achieves a secure and controllable memory injection operation through register control and inter-process collaboration mechanisms. Its beneficial effects are as follows: First, based on the Loongarch architecture's register default conventions (r4-r9 parameter passing, r1 setting an illegal address, and pc pointing to mmap), precise control of target process function calls is achieved. This architecture-specific parameter passing method ensures cross-platform accuracy. Second, by setting a mechanism to trigger a SIGSEGV signal when an illegal return address is received, a reliable execution flow control method is established. This ensures that the mmap function can fully execute memory allocation and that control is safely returned to the tracer process, avoiding the process runaway issue that can occur in traditional solutions. Finally, using PTRACE_POKEDATA to write to memory enables binary-level precise injection of the hook module. This method does not rely on a dynamic linker or symbol resolution, directly operates on raw memory data, and effectively avoids the positioning difficulties caused by address randomization. The entire process is completed through the standard ptrace interface, maintaining the stability of the target process while providing a reliable memory foundation for subsequent hook operations.

[0034] Step 130: Back up the first 5 bytes of the assembly instruction code of the function to be hooked by process tracee to the allocated preset memory; perform address jump instruction repair on the backed up first 5 bytes of the assembly instruction code to obtain the repaired assembly instruction code; replace the first 5 bytes of the function to be hooked with the preset first-level springboard assembly code, and convert the function to be hooked into the hooked function; after the replacement is completed, end the hijacking process tracee.

[0035] The backup process tracee hooks the first 5 bytes of the assembly instruction code of the function into the allocated preset memory; performs address jump instruction repair on the backup first 5 bytes of the assembly instruction code to obtain the repaired assembly instruction code, specifically including: Use ptrace PTRACE_SETREGSET to set the r1 register of the process tracee to an illegal address and the pc register to the preset memory start address allocated by the process tracee; Use ptrace PTRACE_CONT to resume the process tracee and execute the injection function of the hook module; The injection function is allocated to the preset memory, and the first 5 bytes of the assembly instruction code of the function to be hooked are copied to the allocated preset memory; The injected function is used to repair the address jump instruction of the copied first 5 bytes of assembly instruction code: Repairing the branch jump instruction relative to the pc register and determining the instruction type of the branch jump instruction to be repaired; wherein the instruction type includes a non-logical judgment instruction and a logical judgment instruction; When it is a non-logical judgment instruction, obtain the pc address and relative offset of the non-logical judgment instruction according to the formula: Absolute address = pc address + sign_extend64(off, 28), Calculate the absolute address of the jump; where sign_extend64 is the unsigned extension defined by Loongarch; transfer the calculated absolute address to the four assembly instructions lu12i.w, ori, lu32i.d, and lu52i.d; and then use the four assembly instructions lu12i.w, ori, lu32i.d, and lu52i.d together with the jirl instruction as the repaired assembly instruction code; When it is a logic judgment instruction, get the value and offset value of the pc register according to the formula: Absolute address = value of pc register + offset value, The absolute address of the jump is calculated, and the branch jump instruction is replaced with an instruction that is logically opposite to the branch jump instruction as the repaired assembly instruction code.

[0036] As an example, a non-logical judgment instruction: for example, b offs26: According to the pc address and relative offset of the instruction, the absolute address of the jump is calculated: Absolute address imm = pc address + sign_extend64(off, 28); Among them, sign_extend64 is the implementation of unsigned extension defined by Loongarch: static long sign_extend64(long off, int bits){return ((off<<(64 -bits))>>(64 - bits)); }; Assign the calculated address imm to the temporary register t5 and use the jirl instruction to jump; lu12i.w $t5,imm[31:12]; ori$t5,imm[11:0]; lu32i.d $t5,imm[51:32]; lu52i.d $t5,imm[63:52]; jirl$r0,$t5,0; The four assembly instructions lu12i.w ori lu32i.d lu52i.d write the address imm into register t5, and the jirl instruction jumps to the address saved in t5 to start executing the function call.

[0037] As a second example, a logic judgment instruction, such as beq rj,rd,offs16, means: Compare the values ​​of general registers rj and rd. If they are equal, jump to the target address for execution. Otherwise, do not jump. The target address is the value of the current pc register plus the offset value. The replacement solution is: first calculate the absolute jump address imm based on the pc and offs16 of the beq instruction: imm = pc + offs16; Then use the opposite logical judgment bne to implement the function: bne $rj,$rd,24; lu12i.w $t5,imm[31:12]; ori$t5,imm[11:0]; lu32i.d $t5,imm[51:32]; lu52i.d $t5,imm[63:52]; jirl$r0,$t5,0; The bne instruction means that if the rj and rd registers are not equal, then jump to the target address for execution. The target address here is pc+24, which means skipping the 5 instructions lu12i.w ori lu32i.d lu52i.d jirl after bne. 24 means 5 instructions plus the bne instruction itself, a total of 6 instructions. Each instruction of Loongarch occupies 4 bytes, a total of 6*4=24 bytes. If the rj and rd registers are equal, then no jump will be made and the following instruction will be executed: lu12i.w ori lu32i.d lu52i.djirl, which means jumping to the relative address of the original beq jump.

[0038] Based on the above description, those skilled in the art will appreciate that this step achieves secure backup and redirection of the hook function through instruction-level operations. Its beneficial effects are as follows: First, addressing the unique instruction formats of the Loongarch architecture (such as the sign extension of 28-bit offsets), two processing paths, non-logical check instructions and logical check instructions, are designed. By calculating the PC address and offset value, the accuracy of address translation during the instruction backup process is ensured, avoiding jump errors caused by different instruction types. Second, the temporary register t5 is used as a transfer station for the jump address, combined with the jirl instruction to achieve control flow transfer. This architecture-specific implementation not only complies with the Loongarch ABI specification but also ensures the integrity of the original instruction semantics. Finally, by differentiating the address calculation logic for different instruction types (non-logical instructions use the sign_extend64 extension, while logical instructions directly calculate the offset), the compatibility issue of relative address translation in mixed instruction environments is resolved, providing a reliable foundation for subsequent instruction recovery. This fine-grained instruction processing mechanism ensures the stability of the hook function while significantly reducing the risk of process crashes caused by incomplete instruction backups.

[0039] After the replacement is completed, the hijacking process tracee is terminated, including: When the injection function of the hook module injected into the process tracee completes replacing the first 5 bytes of the hook function with the preset first-level springboard assembly code, Use ptrace PTRACE_SETREGS to set the registers to the register values ​​cached when the attach operation is successfully hijacked, and restore the initial register state of the process tracee when it was hijacked; Call ptrace PTRACE_DETACH to release the hijacking of process tracee, and process tracee resumes normal execution.

[0040] Step 140: Process tracee resumes normal use. When process tracee executes the hooked function, it executes the preset first-level springboard assembly code and jumps to the second-level springboard of the hook module through the preset first-level springboard assembly code; saves the current execution scene through the second-level springboard, obtains the input parameter information of the hooked function, and then jumps to the preset unified hook logic execution function for execution.

[0041] It should be noted that the preset unified hook logic execution function is used to extend the user-defined function.

[0042] In step 140: the execution flow of the recovery process tracee is executed normally, which may be: When the process tracee executes the injection function of the hook module, a SIGSEGV signal is generated because the r1 register is set to an illegal address; The tracer process uses waitpid to wait for the SIGSEGV signal of the process tracee; Use ptrace PTRACE_SETREGS to set the register values ​​to the register values ​​cached at the time of initial attach, thereby restoring the initial register state of the process tracee when it was hijacked; Call ptrace PTRACE_DETACH to release the hijacking of process tracee, and process tracee resumes normal execution.

[0043] In step 140: jump to the secondary springboard of the hook module through the preset primary springboard assembly code, which can be specifically: Make the beginning code of the hook function jump to the secondary springboard address and execute the hook logic: lu12i.w $t5,imm[31:12]; ori$t5,imm[11:0]; lu32i.d $t5,imm[51:32]; lu52i.d $t5,imm[63:52]; jirl$r0,$t5,0; The four instructions lu12i.w ori lu32i.d and lu52i.d implement the storage of the secondary springboard address imm into the t5 register, and jirl implements an unconditional jump to the t5 register to start executing the function.

[0044] Among them, the current execution scene is saved through the secondary springboard, the input parameter information of the hooked function is obtained, and then the execution function is executed by jumping to the preset unified hook logic, specifically including: The secondary springboard of the hook module saves the current execution scene of the hooked function; specifically, the current CPU register values ​​are saved to the stack through assembly instructions; the data to be saved include: parameter registers a0-a7, save registers s0-s8, frame pointer fp and return address ra; Configure the input parameter information of the hooked function to the current CPU register; Execute the function by presetting a unified hook logic: invocation(FunctionContext* func_ctx, CpuContext * cpu_ctx), passes the input parameter information to the user-defined function; Among them, func_ctx contains the user-defined function and the hooked function information, cpu_ctx is the current register information of the hooked function, and contains the input parameter information of the hooked function.

[0045] It should be noted that, in the above step 140, after the injection process is completed, the process tracee resumes normal use, and the execution process of the process tracee may be specifically as follows: When the program executes the hooked function: the 5-byte first-level springboard assembly code is executed, jumping to the second-level springboard of the hook module. The second-level springboard saves the current execution scene, obtains the input parameters of the hooked function, and jumps to the preset unified hook logic execution function (third-level springboard) for execution. This function will call the user-defined function, pass the parameter information of the hooked function, and realize the tracking and analysis function of the hooked function.

[0046] Step 150: Call the user-defined function through the preset unified hook logic execution function, and pass the input parameters to the user-defined function; after executing the user-defined function, jump back to the secondary springboard, restore the execution scene, jump to the repaired assembly instruction code, jump to the beginning of the hooked function offset by 6 bytes, and execute the process tracee of the hooked function.

[0047] After executing the user-defined function, it jumps back to the secondary springboard, restores the execution scene, jumps to the repaired assembly instruction code, jumps to the beginning of the hooked function offset by 6 bytes, and executes the process tracee of the hooked function, specifically including: After executing the user-defined function, jump back to the secondary springboard and restore the parameter registers a0-a7, save registers s0-s8, frame pointer fp and return address ra previously saved to the stack; Jump to the assembly instruction code after the repair of the hook module, jump to the beginning of the hooked function offset by 6 bytes for execution, and execute the process tracee of the hooked function.

[0048] It should be noted that in step 150, the hook module's secondary jump board saves the current CPU register values ​​to the stack via assembly instructions. The values ​​to be saved include parameter registers a0-a7, save registers s0-s8, frame pointer fp, and return address ra. The parameters passed by the hooked function are configured in the current CPU registers, and the third-level jump board function (preset unified hook logic execution function) is called. invocation(FunctionContext* func_ctx, CpuContext * cpu_ctx) passes the parameter information to the user-defined function.

[0049] It should be noted that during execution, this application needs to save the value of func_ctx to the a0 register and the value of cpu_ctx to the a1 register according to the Loongarch ABI definition. According to the Loongarch instruction set definition, the structure address (64 bits) is split from high to low into 4 bytes and called separately: lu12i.w$a0,imm[31:12]; ori$a0, $a0,imm[11:0]; lu32i.d$a0,imm[51:32]; lu52i.d$a0, $a0,imm[63:52]; The meaning of the above assembly instructions is: The meaning of the assembly instruction lu12i.w is: connect the lower 20 bits of the immediate value to 12 bits of 0 and write them into the general register; The meaning of the assembly instruction lu32i.d is: connect the lower 20 bits of the immediate value to the [31:0] bits in the general register a0 and write them into the a0 register; The meaning of the assembly instruction lu52i.d is: connect the lower 20 bits of the immediate value to the [51:0] bits in the general register a0 and write them into the a0 register; ori is the bitwise logical OR of the number in register a0 and the lower 12 bits of the immediate number, and writes them into register a0.

[0050] Jump to the three-level springboard function: use the temporary register t5 to save the function address and use the jirl instruction to jump: lu12i.w $t5,imm[31:12]; ori$t5,imm[11:0]; lu32i.d $t5,imm[51:32]; lu52i.d $t5,imm[63:52]; jirl$r0,$t5,0; The jirl instruction is an unconditional jump instruction. jirl $r0,$t5,0 means an unconditional jump to the address saved in the t5 register.

[0051] In addition, an embodiment of the present application further provides a non-volatile computer storage medium on which executable instructions are stored. When the executable instructions are executed, a user space program Inlinehook method based on the Loongarch architecture as described above is implemented.

[0052] The above description of the disclosed embodiments is intended to enable one skilled in the art to implement or use the present invention. Various modifications to these embodiments will be readily apparent to one skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention is not limited to the embodiments shown herein but is intended to conform to the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. A user space program inlinehook method based on Loongarch architecture, characterized in that: The method comprises: The control program's own process tracer uses the attach operation of ptrace to hijack the preset controlled process tracee; After the attach operation is successfully hijacked, the current register of the process tracee is obtained for caching; Use the libc library loading address and mmap function address of process tracer and the library loading address of process tracee to obtain the mmap function address of process tracee; Configure the register configuration related to the mmap function in the process tracee through the process tracer, run the mmap function of the process tracee, allocate a preset memory in the process tracee, obtain the return address of the mmap function of the process tracee, and inject the hook module into the preset memory; The backup process tracee hooks the first 5 bytes of the assembly instruction code of the function into the allocated preset memory; the backup first 5 bytes of the assembly instruction code are repaired by address jump instructions to obtain the repaired assembly instruction code; Replace the first 5 bytes of the function to be hooked with the preset first-level springboard assembly code, and convert the function to be hooked into the hooked function; after the replacement is completed, end the hijacking process tracee; The process tracee resumes normal use. When the process tracee executes the hooked function, it executes the preset first-level springboard assembly code, and jumps to the second-level springboard of the hook module through the preset first-level springboard assembly code; the current execution scene is saved through the second-level springboard, and the input parameter information of the hooked function is obtained, and then it jumps to the preset unified hook logic execution function for execution; wherein, the preset unified hook logic execution function is used to extend the user-defined function; The user-defined function is called through the preset unified hook logic execution function, and the input parameters are passed to the user-defined function; after executing the user-defined function, it jumps back to the secondary springboard, restores the execution scene, jumps to the repaired assembly instruction code, jumps to the offset of 6 bytes at the beginning of the hooked function, and executes the process tracee of the hooked function.

2. The user space program inlinehook method based on Loongarch architecture according to claim 1, characterized in that: Use ptrace's attach operation to hijack the preset control process tracee, specifically including: According to the preset process number pid of the control process tracee, use ptrace attach to operate to the process with the process number pid; Wait for the process to enter the STOPPED state and obtain the current registers of the process tracee for caching.

3. The user space program inlinehook method based on Loongarch architecture according to claim 1, characterized in that: Using the libc library loading address and mmap function address of the process tracer and the library loading address of the process tracee, the mmap function address of the process tracee is obtained, specifically including: Use dlsym to get the mmap function address of the tracer process; Use the Linux system / proc / pid / maps to obtain the libc library function address of the tracer process and process tracee; The relative offset is calculated based on the offset of the tracer process's mmap function address relative to its own libc library function address; Add the relative offset to the libc library function address of the process tracee to get the mmap function address of the process tracee.

4. The user space program inlinehook method based on Loongarch architecture according to claim 1, characterized in that: The tracer process modifies the register configuration of the tracee process, and then calls the mmap function of the tracee process. The mmap function allocates a preset memory in the tracee process, specifically including: According to the Loongarch register preset convention, the tracer process uses ptrace PTRACE_SETREGSET to set the six parameters of the mmap function address of the process tracee to the r4-r9 registers of the process tracee, set the r1 register of the process tracee to an illegal address, and set the pc register of the process tracee to the mmap function address; The tracer process uses ptrace PTRACE_CONT to resume execution of the process tracee. The process tracee executes the mmap function and allocates a preset memory specified by the mmap function in the process tracee.

5. The user space program inlinehook method based on Loongarch architecture according to claim 1, characterized in that: Inject the hook module into the preset memory, including: Read the hook module binary file into the process tracer memory, and use ptrace PTRACE_POKEDATA to write the hook module into the preset memory allocated by the process tracee.

6. The user space program inlinehook method based on Loongarch architecture according to claim 1, characterized in that: The backup process tracee will hook the first 5 bytes of the assembly instruction code of the function to the allocated preset memory; Perform address jump instruction repair on the first 5 bytes of the backup assembly instruction code to obtain the repaired assembly instruction code, which specifically includes: Use ptrace PTRACE_SETREGSET to set the r1 register of the process tracee to an illegal address and the pc register to the preset memory start address allocated by the process tracee; Use ptrace PTRACE_CONT to resume the process tracee and execute the injection function of the hook module; The injection function is allocated to the preset memory, and the first 5 bytes of the assembly instruction code of the function to be hooked are copied to the allocated preset memory; The injected function is used to repair the address jump instruction of the copied first 5 bytes of assembly instruction code: Repairing the branch jump instruction relative to the pc register and determining the instruction type of the branch jump instruction to be repaired; wherein the instruction type includes a non-logical judgment instruction and a logical judgment instruction; When it is a non-logical judgment instruction, obtain the pc address and relative offset of the non-logical judgment instruction according to the formula: Absolute address = pc address + sign_extend64(off, 28), Calculate the absolute address of the jump; where sign_extend64 is the unsigned extension defined by Loongarch; transfer the calculated absolute address to the four assembly instructions lu12i.w, ori, lu32i.d, and lu52i.d; and then use the four assembly instructions lu12i.w, ori, lu32i.d, and lu52i.d together with the jirl instruction as the repaired assembly instruction code; When it is a logic judgment instruction, get the value and offset value of the pc register according to the formula: Absolute address = value of pc register + offset value, The absolute address of the jump is calculated, and the branch jump instruction is replaced with an instruction that is logically opposite to the branch jump instruction as the repaired assembly instruction code.

7. The user space program inlinehook method based on Loongarch architecture according to claim 1, characterized in that: After the replacement is completed, the hijacking process tracee is terminated, including: When the injection function of the hook module injected into the process tracee completes replacing the first 5 bytes of the hook function with the preset first-level springboard assembly code, Use ptrace PTRACE_SETREGS to set the registers to the register values ​​cached when the attach operation is successfully hijacked, and restore the initial register state of the process tracee when it was hijacked; Call ptrace PTRACE_DETACH to release the hijacking of process tracee, and process tracee resumes normal execution.

8. The user space program inlinehook method based on Loongarch architecture according to claim 1, characterized in that: The current execution scene is saved through the secondary springboard, the input parameter information of the hooked function is obtained, and then the execution function is executed by jumping to the preset unified hook logic, specifically including: The secondary springboard of the hook module saves the current execution scene of the hooked function; specifically, the current CPU register values ​​are saved to the stack through assembly instructions; the data to be saved include: parameter registers a0-a7, save registers s0-s8, frame pointer fp and return address ra; Configure the input parameter information of the hooked function to the current CPU register; Execute the function by presetting a unified hook logic: invocation(FunctionContext* func_ctx, CpuContext * cpu_ctx), passes the input parameter information to the user-defined function; Among them, func_ctx contains the user-defined function and the hooked function information, cpu_ctx is the current register information of the hooked function, and contains the input parameter information of the hooked function.

9. The user space program inlinehook method based on Loongarch architecture according to claim 8, characterized in that: After executing the user-defined function, it jumps back to the secondary springboard, resumes the execution scene, jumps to the repaired assembly instruction code, jumps to the beginning of the hooked function offset by 6 bytes, and executes the process tracee of the hooked function, specifically including: After executing the user-defined function, jump back to the secondary springboard and restore the parameter registers a0-a7, save registers s0-s8, frame pointer fp and return address ra previously saved to the stack; Jump to the assembly instruction code after the repair of the hook module, jump to the beginning of the hooked function offset by 6 bytes for execution, and execute the process tracee of the hooked function.

10. A non-volatile computer storage medium, characterized in that Computer instructions are stored thereon, and when the computer instructions are executed, they implement a user space program inlinehook method based on the Loongarch architecture as described in any one of claims 1 to 9.

Citation Information

Patent Citations

  • Modeled software key behavior tracking method based on memory management

    CN103631712A

  • Method and a device for monitoring the dynamic loading behavior of a mobile application program

    CN109344616A

  • Tracking method and device for dynamic link library function

    CN111290952A

  • Process information security interception method, system, equipment and medium

    CN116502190A

  • Novel API HOOK method

    CN116541100A