SO file reinforcement method, device, electronic device and storage medium

By integrating the SO file to be reinforced with the preset SO file in dynamic view, combining anti-attack logic and segment merging encryption technology, the security problems of SO file cracked in Android applications are solved, achieving convenient and efficient protection effects.

CN111984940BActive Publication Date: 2025-05-16BEIJING QIHOOD TECHNOLOGY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN201910429838.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2019-05-22
Publication Date
2025-05-16
Estimated Expiration
2039-05-22

AI Technical Summary

Technical Problem

In Android applications, SO files as dynamic link libraries are vulnerable to attacks during cracking. How to effectively protect SO files while ensuring development convenience has become a challenge.

Method used

Through a dynamic view based on SO files, the SO file to be reinforced is fused with the preset SO file to generate the reinforced SO file. The preset SO file contains anti-attack logic and merges and encrypts the specified type of segments during the fusion process to ensure the security of the file.

Benefits of technology

It realizes effective protection of SO files, provides a protection method independent from outside the development process, simplifies the protection process, and can provide better protection effects in practical applications.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN111984940B_ABST
    Figure CN111984940B_ABST
Patent Text Reader

Abstract

The present invention discloses a method, device, electronic device and storage medium for reinforcing an SO file. The method comprises: obtaining an SO file to be reinforced; based on a dynamic view of the SO file, fusing the SO file to be reinforced with a preset SO file to obtain a reinforced SO file; wherein the preset SO file comprises anti-attack logic. The beneficial effect of this technical solution is that, for a large number of SO files to be reinforced, only one or more SO files for protecting anti-attack logic need to be preset, and reinforcement is achieved through the fusion of SO files, providing a SO file protection method that is independent of the development process, and is relatively convenient to implement, and can also achieve good protection effects.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security, and in particular to a method, device, electronic device and storage medium for reinforcing an SO file. Background Art

[0002] SO files refer to dynamic link library files in .so format, which are widely used in Android applications and have become the focus of attention in the process of cracking Android applications. Therefore, how to protect SO files is a problem that needs to be solved. If developers need to pay attention to the functions that SO files need to implement and consider how to protect them, it will undoubtedly increase the development cost. However, if the protection of SO files is achieved through an independent process, how to provide a protection plan with good protection effect is a new challenge. Summary of the invention

[0003] In view of the above problems, the present invention is proposed to provide a method, device, electronic device and storage medium for reinforcing an SO file that overcomes the above problems or at least partially solves the above problems.

[0004] According to one aspect of the present invention, a method for reinforcing a dynamic link library SO file is provided, comprising:

[0005] Get the SO file to be reinforced;

[0006] Based on the dynamic view of the SO file, the SO file to be reinforced is merged with the preset SO file to obtain a reinforced SO file;

[0007] Wherein, the preset SO file includes anti-attack logic.

[0008] Optionally, the dynamic view based on the SO file, merging the SO file to be reinforced with a preset SO file to obtain the reinforced SO file includes:

[0009] The SO file to be reinforced and the preset SO file are parsed respectively, and the segments of the specified type are merged based on the parsing results.

[0010] Optionally, the analysis result includes one or more of the following information:

[0011] The loading address of the SO file, the ELF header information of the SO file, the segment table information of the SO, the starting address of each segment in the SO file, and the size of each segment in the SO file.

[0012] Optionally, the specified type of segment includes: a PT_LOAD type segment;

[0013] The merging of the specified type of segments includes: adding the segment table information of type PT_LOAD parsed from the preset SO file to the segment table information parsed from the SO file to be consolidated to obtain new segment table information.

[0014] Optionally, the specified type of segment includes: a segment related to dynamic linking.

[0015] Optionally, the segments related to dynamic linking include: segments corresponding to a symbol table and segments corresponding to a string table;

[0016] The merging of the segments of the specified type includes: removing repeated symbols and character strings.

[0017] Optionally, removing repeated symbols and character strings includes:

[0018] If there is JNI_Onload in the SO file to be reinforced, its name is replaced and the address of the JNI_Onload is saved, so that after the reinforced SO file is loaded, the saved address of the JNI_Onload is called according to the anti-attack logic.

[0019] Optionally, the segments related to dynamic linking include: segments corresponding to a relocation table;

[0020] The merging of the segments of the specified type includes: correcting the offset of the relocation table, and encrypting the relocation table of the SO file to be reinforced;

[0021] The anti-attack logic is used to decrypt the encrypted relocation table after the hardened SO file is loaded.

[0022] Optionally, the encryption key and the decryption key are generated according to the package name of the application containing the hardened SO file and / or the MD5 value of the signature file;

[0023] The anti-attack logic is also used to prevent the interface for obtaining the application package name and / or signature file from being hooked.

[0024] Optionally, the merging of the SO file to be reinforced with the preset SO file further includes:

[0025] Generate new related segments based on the merged segments;

[0026] New related segments and merged segments will be generated and merged into a new PT_LOAD segment.

[0027] Optionally, the merging of the SO file to be reinforced with the preset SO file further includes:

[0028] Erase the ELF header information and segment table information of the SO file to be reinforced, and write the information into the target SO file in the following order to obtain the reinforced SO file:

[0029] New ELF header information, new segment table information, null bytes, the SO file to be hardened, the entire content of the preset SO file, the new PT_LOAD segment, the new section header and section.

[0030] According to another aspect of the present invention, a device for reinforcing a dynamic link library SO file is provided, comprising:

[0031] An acquisition unit, adapted to acquire the SO file to be reinforced;

[0032] The fusion unit is adapted to fuse the SO file to be reinforced with a preset SO file based on a dynamic view of the SO file to obtain a reinforced SO file; wherein the preset SO file includes anti-attack logic.

[0033] Optionally, the fusion unit is adapted to parse the SO file to be reinforced and the preset SO file respectively, and merge the segments of a specified type based on the parsing results.

[0034] Optionally, the analysis result includes one or more of the following information:

[0035] The loading address of the SO file, the ELF header information of the SO file, the segment table information of the SO, the starting address of each segment in the SO file, and the size of each segment in the SO file.

[0036] Optionally, the specified type of segment includes: a PT_LOAD type segment;

[0037] The fusion unit is adapted to add the segment table information of type PT_LOAD parsed from the preset SO file to the segment table information parsed from the SO file to be reinforced, so as to obtain new segment table information.

[0038] Optionally, the specified type of segment includes: a segment related to dynamic linking.

[0039] Optionally, the segments related to dynamic linking include: segments corresponding to a symbol table and segments corresponding to a string table;

[0040] The fusion unit is adapted to remove repeated symbols and character strings.

[0041] Optionally, the fusion unit is adapted to replace the name of JNI_Onload and save the address of the JNI_Onload if there is JNI_Onload in the SO file to be reinforced, so that after the reinforced SO file is loaded, the saved address of the JNI_Onload is called according to the anti-attack logic.

[0042] Optionally, the segments related to dynamic linking include: segments corresponding to a relocation table;

[0043] The fusion unit is suitable for correcting the offset of the relocation table and encrypting the relocation table of the SO file to be reinforced; the anti-attack logic is used to decrypt the encrypted relocation table after the reinforced SO file is loaded.

[0044] Optionally, the encryption and decryption keys are generated based on the package name of the application containing the hardened SO file and / or the MD5 value of the signature file; the anti-attack logic is also used to prevent the interface for obtaining the application package name and / or signature file from being hooked.

[0045] Optionally, the fusion unit is adapted to generate a new related segment according to the merged segment; and merge the generated new related segment and the merged segment into a new PT_LOAD segment.

[0046] Optionally, the fusion unit is suitable for erasing the ELF header information and segment table information of the SO file to be reinforced, and writing the information into the target SO file in the following order to obtain the reinforced SO file: new ELF header information, new segment table information, null bytes, the SO file to be reinforced and all the contents of the preset SO file, new PT_LOAD segment, new section header and section.

[0047] According to another aspect of the present invention, an electronic device is provided, comprising: a processor; and a memory arranged to store computer executable instructions, wherein when the executable instructions are executed, the processor executes any of the above methods.

[0048] According to another aspect of the present invention, a computer-readable storage medium is provided, wherein the computer-readable storage medium stores one or more programs, and when the one or more programs are executed by a processor, the one or more programs implement any of the methods described above.

[0049] From the above, it can be seen that the technical solution of the present invention, after obtaining the SO file to be reinforced, merges the SO file to be reinforced with the preset SO file based on the dynamic view of the SO file to obtain the reinforced SO file; wherein the preset SO file includes anti-attack logic. The beneficial effect of this technical solution is that for many SO files to be reinforced, only one or more SO files that protect the anti-attack logic need to be preset, and reinforcement is achieved through the fusion of SO files, providing a SO file protection method that is independent of the development process, and is relatively convenient to implement and can also achieve good protection effects.

[0050] The above description is only an overview of the technical solution of the present invention. In order to more clearly understand the technical means of the present invention, it can be implemented according to the contents of the specification. In order to make the above and other purposes, features and advantages of the present invention more obvious and easy to understand, the specific implementation methods of the present invention are listed below. BRIEF DESCRIPTION OF THE DRAWINGS

[0051] Various other advantages and benefits will become apparent to those of ordinary skill in the art by reading the detailed description of the preferred embodiments below. The accompanying drawings are only for the purpose of illustrating the preferred embodiments and are not to be considered as limiting the present invention. Moreover, the same reference symbols are used throughout the accompanying drawings to represent the same components. In the accompanying drawings:

[0052] Figure 1 A schematic flow chart of a method for reinforcing a dynamic link library SO file according to an embodiment of the present invention is shown;

[0053] Figure 2 A schematic diagram of the structure of a device for reinforcing a dynamic link library SO file according to an embodiment of the present invention is shown;

[0054] Figure 3 A schematic diagram of the structure of an electronic device according to an embodiment of the present invention is shown;

[0055] Figure 4 A schematic diagram of the structure of a computer-readable storage medium according to an embodiment of the present invention is shown. DETAILED DESCRIPTION

[0056] The exemplary embodiments of the present invention will be described in more detail below with reference to the accompanying drawings. Although the exemplary embodiments of the present invention are shown in the accompanying drawings, it should be understood that the present invention can be implemented in various forms and should not be limited by the embodiments set forth herein. On the contrary, these embodiments are provided in order to enable a more thorough understanding of the present invention and to enable the scope of the present invention to be fully communicated to those skilled in the art.

[0057] Figure 1FIG. 1 is a flow chart showing a method for reinforcing a dynamic link library SO file according to an embodiment of the present invention. Figure 1 As shown, the method includes:

[0058] Step S110, obtaining the SO file to be reinforced, wherein the SO file may be contained in an Android application installation package (.apk format) and obtained by decompression.

[0059] Step S120, based on the dynamic view of the SO file, the SO file to be reinforced is merged with the preset SO file to obtain a reinforced SO file; wherein the preset SO file includes anti-attack logic.

[0060] There can be one or more preset SO files, and the anti-attack logic and other functions they contain may be different. During the specific implementation, just select one that meets the requirements. Finally, based on the dynamic view of the SO file, the selected SO file is merged with the SO file to be reinforced, thereby achieving protection for the SO file to be reinforced.

[0061] SO file is a specific ELF file format, and ELF file can be divided into static view and dynamic view. From the static view, ELF file consists of multiple sections, and different sections have different names, permissions, etc. From the dynamic view, ELF file consists of multiple segments, and each segment has different permissions and names. As shown in the following table, the left side of Table 1 is the static view of ELF file, and the right side is the dynamic view of ELF file. It can be seen that a segment is a collection of multiple sections with the same permissions.

[0062] Table 1

[0063]

[0064] The present invention adopts the method of SO file dynamic view to merge SO files, because when SO files are used, they are based on the properties of their dynamic link library, and after being reinforced, it is necessary to ensure that the application that calls the SO file to be reinforced can still successfully call the reinforced SO file. Since the data in each segment of the SO file can be obtained under the dynamic view, and these data are also related to the dynamic link library, it is possible to accurately ensure that data is not lost while ensuring the efficiency of fusion, and achieve successful fusion and complete the protection of the SO file to be reinforced.

[0065] visible, Figure 1The method shown, after obtaining the SO file to be reinforced, merges the SO file to be reinforced with the preset SO file based on the dynamic view of the SO file to obtain the reinforced SO file; wherein the preset SO file includes anti-attack logic. The beneficial effect of this technical solution is that for many SO files to be reinforced, only one or more SO files that protect the anti-attack logic need to be preset, and reinforcement is achieved through the fusion of SO files, providing a SO file protection method that is independent of the development process, and is relatively convenient to implement and can also achieve good protection effects.

[0066] In one embodiment of the present invention, in the above method, based on the dynamic view of the SO file, the SO file to be reinforced is merged with the preset SO file to obtain the reinforced SO file, including: parsing the SO file to be reinforced and the preset SO file respectively, and merging the specified type of segments based on the parsing results.

[0067] There are many types of segments in SO files. Here is a brief description of some segments used in dynamic linking:

[0068] .dynamic segment: records the type, address or value of the segment related to dynamic linking.

[0069] .rel.plt segment: is the relocation table, which records the symbol table index and relocation address.

[0070] .rel.dyn segment: Similar to the .rel.plt segment, .rel.dyn relocates data references.

[0071] .dynsym segment: dynamic link symbol table, which stores symbols related to dynamic linking.

[0072] .hash section: Improves the efficiency of symbol retrieval.

[0073] .init / .init_array segments: The dynamic linker will first execute the code in these two segments before executing the program main function.

[0074] .fini / .fini_array segments: Similarly, the dynamic linker will eventually execute the code in these two segments.

[0075] In an embodiment of the present invention, one or more of the above segments can be merged. During parsing, the parsing result can be obtained by referring to the processing when Android Linker loads the SO file. Specifically, in one embodiment of the present invention, in the above method, the parsing result includes one or more of the following information: the loading address of the SO file, the ELF header information of the SO file, the segment table information of the SO, the starting address of each segment in the SO file, and the size of each segment in the SO file.

[0076] The above analysis results can be saved in a custom soinfo structure.

[0077] In one embodiment of the present invention, in the above method, the specified type of segments includes: PT_LOAD type segments; merging the specified type of segments includes: adding the segment table information of type PT_LOAD parsed from the preset SO file to the segment table information parsed from the SO file to be consolidated to obtain new segment table information.

[0078] Taking the Android system as an example, when loading an SO file, all segments of type PT_LOAD in the SO file will be loaded into the memory, and segments of other types will not be loaded. Therefore, when merging two SO files, all segments of type PT_LOAD in the two SO files need to be merged, and then the segments related to dynamic links can also be merged, such as .dynamic, .dynsym, etc. That is, in one embodiment of the present invention, in the above method, the segments of the specified type include: segments related to dynamic links.

[0079] The following describes processing examples of different segments related to dynamic linking provided by the present invention.

[0080] In one embodiment of the present invention, in the above method, the segments related to dynamic linking include: segments corresponding to the symbol table and segments corresponding to the string table; merging the segments of the specified type includes: removing duplicate symbols and strings. The specific related segments include .dynsym segments. The symbols and strings correspond to functions used by the application in the process of calling the SO file, etc.

[0081] In one embodiment of the present invention, in the above method, removing duplicate symbols and strings includes: if JNI_Onload exists in the SO file to be hardened, its name is replaced and the address of the JNI_Onload is saved, so that after the hardened SO file is loaded, the saved address of the JNI_Onload is called according to the anti-attack logic.

[0082] JNI_Onload is a function related to SO file loading, and there should be only one for one SO file. The application needs to call the SO file to be reinforced, but actually calls the reinforced SO file, so the functions in the SO file to be reinforced cannot be used directly. Therefore, during the fusion process, the JNI_Onload name in the SO file to be reinforced is first replaced and the address of the JNI_Onload is saved. When the application needs the SO file to be reinforced, the anti-attack logic in the preset SO file calls the saved JNI_Onload address, and the loading is completed.

[0083] In one embodiment of the present invention, in the above method, the segments related to dynamic linking include: segments corresponding to the relocation table; merging the segments of the specified type includes: correcting the offset of the relocation table, and encrypting the relocation table of the SO file to be reinforced; the anti-attack logic is used to decrypt the encrypted relocation table after the reinforced SO file is loaded.

[0084] Specifically, the .rel.plt segment and the .rel.dyn segment may be involved. The contents of these two segments are important and are also the focus of SO file cracking. Therefore, in the embodiment of the present invention, they can also be encrypted, and when used, they are decrypted to ensure the normal implementation of the function. In addition, since the starting virtual address of the preset SO file is changed, the offset of the relocation table needs to be corrected when merging the relocation table.

[0085] In one embodiment of the present invention, in the above method, the encryption and decryption keys are generated based on the package name of the application containing the hardened SO file and / or the MD5 value of the signature file; the anti-attack logic is also used to prevent the interface for obtaining the application package name and / or signature file from being hooked.

[0086] The key generated by using the package name of the application containing the hardened SO file and / or the MD5 value of the signature file can ensure that the caller of the hardened SO file must be the original application, not other crackers. If an illegal application calls the SO file, it will obtain the wrong package name or signature file, resulting in decryption failure and application crash. To further strengthen prevention, anti-attack logic is also used to prevent the interface for obtaining the application package name and / or signature file from being hooked.

[0087] It should also be noted that the specific details of the anti-attack logic introduced in the above embodiment are only some introductions to relevant application scenarios. It is easy to understand that more anti-attack logic can be added according to needs in specific implementation.

[0088] In one embodiment of the present invention, in the above method, merging the SO file to be reinforced with the preset SO file further includes: generating new related segments according to the merged segments; merging the generated new related segments and the merged segments into a new PT_LOAD segment. This also ensures that all the required information is loaded into the memory when the reinforced SO file is loaded. The related segments may include .dynamic segments, .hash segments, etc.

[0089] In addition, you can also extract and merge dependent SO files, remove duplicate dependent SO file names, and merge the names of other SO files that two SO files depend on.

[0090] In one embodiment of the present invention, in the above method, merging the SO file to be reinforced with the preset SO file further includes: erasing the ELF header information and segment table information of the SO file to be reinforced, and writing the information into the target SO file in the following order to obtain the reinforced SO file: new ELF header information, new segment table information, null bytes, the entire contents of the SO file to be reinforced and the preset SO file, new PT_LOAD segment, new section header and section. The ELF header information and segment table information of the original SO file are erased, and null bytes are filled in the new file, which will result in the new SO file in the memory having no ELF header information. If the attacker dumps the memory, it will increase the difficulty of the attacker's analysis.

[0091] The following is a specific example:

[0092] First, obtain the installation package of the Android application through the front-end page, unpack it to obtain the SO file to be reinforced, select a preset SO file from the library, and merge the two.

[0093] Step a) Parsing SO file: Following the process of Linker loading SO file, parse the SO file and store the parsed result in a custom soinfo structure, which contains the loading address of the SO file, the ELF header information of the SO file, the segment table information, and the starting address and size of each segment.

[0094] Step b) merge so files, specifically:

[0095] i. Copy the ELF header information and merge the segment table information. Copy the ELF header and segment table information of A.so (the SO file to be hardened), and add the segment table information of type PT_LOAD of B.so (the SO file with the preset protection and anti-attack logic) to the copied segment table information, that is, add several segment tables and fill them with the segment table of type PT_LOAD in B.so.

[0096] ii. Extract and merge the symbol table and string table. Merge the symbol table and string table in the two SO files, remove duplicate symbols and strings, and form a new symbol table and string table. If A.so has JNI_OnLoad, change its name to JNI_OnLaad, and then save the address of A.so's JNI_OnLoad, in order to keep only B.so's JNI_OnLoad.

[0097] iii. Extract and merge the relocation table. Merge the relocation tables in the two SO files, including .rel.plt and .rel.dyn. Since the starting virtual address of the second SO file has been changed, the offset of the relocation table needs to be corrected when merging the relocation table.

[0098] iv. Extract and merge .init / .init_array and .fini / .fini_array.

[0099] v. Extract and merge dependent SO files. Remove the names of duplicate dependent SO files and merge the names of other SO files that the two SO files depend on.

[0100] Step c) Generate a new so file, specifically:

[0101] i. Generate a new Hash table based on the new symbol table and string table.

[0102] ii. Generate a new .dynamic section.

[0103] iii. Encrypt the .rel.plt of A.so.

[0104] iv. Merge the newly generated .dynamic segment, symbol table, .hash segment, .init / .init_array segment, .fini / .fini_array segment, and relocation table into a PT_LOAD segment, which is a newly added segment.

[0105] v. Generate new section header and section;

[0106] vi. Erase the ELF header information and segment table information of the original so, and modify the copied ELF header information and segment table information.

[0107] vii. Write the file. The writing order is: new ELF header -> new segment table -> (...fill with null bytes to 4096 bytes) -> A.so -> B.so -> new PT_LOAD segment -> new section header and section.

[0108] Since the ELF headers and segment tables of A.so and B.so are erased, there is a lot of extra space that can be used to save the address of JNI_OnLoad of A.so.

[0109] Figure 2 FIG. 2 is a schematic diagram showing a structure of a device for reinforcing a dynamic link library SO file according to an embodiment of the present invention. Figure 2 As shown, the reinforcement device 200 for the dynamic link library SO file includes:

[0110] The acquisition unit 210 is adapted to acquire the SO file to be reinforced, wherein the SO file may be contained in an Android application installation package (.apk format) and obtained by decompression.

[0111] The fusion unit 220 is adapted to fuse the SO file to be reinforced with the preset SO file based on the dynamic view of the SO file to obtain the reinforced SO file; wherein the preset SO file includes anti-attack logic. There may be one or more preset SO files, and the anti-attack logic and other functions included may be different. In the specific implementation, one that meets the requirements can be selected from them. Finally, based on the dynamic view of the SO file, the selected SO file is merged with the SO file to be reinforced, thereby realizing the protection of the SO file to be reinforced.

[0112] visible, Figure 2 The device shown, through the mutual cooperation of each unit, after obtaining the SO file to be reinforced, merges the SO file to be reinforced with the preset SO file based on the dynamic view of the SO file to obtain the reinforced SO file; wherein the preset SO file includes anti-attack logic. The beneficial effect of this technical solution is that for many SO files to be reinforced, only one or more SO files that protect the anti-attack logic need to be preset, and reinforcement is achieved through the fusion of SO files, providing a SO file protection method that is independent of the development process, and is relatively convenient to implement and can also achieve good protection effects.

[0113] In one embodiment of the present invention, in the above device, the fusion unit 220 is adapted to parse the SO file to be reinforced and the preset SO file respectively, and merge the segments of the specified type based on the parsing results.

[0114] In one embodiment of the present invention, in the above-mentioned device, the parsing result includes one or more of the following information: the loading address of the SO file, the ELF header information of the SO file, the segment table information of the SO, the starting address of each segment in the SO file, and the size of each segment in the SO file.

[0115] In one embodiment of the present invention, in the above-mentioned device, the specified type of segment includes: a PT_LOAD type segment; the fusion unit 220 is suitable for adding the segment table information of type PT_LOAD parsed from the preset SO file to the segment table information parsed from the SO file to be reinforced to obtain new segment table information.

[0116] In one embodiment of the present invention, in the above-mentioned apparatus, the segments of the specified type include: segments related to dynamic links.

[0117] In one embodiment of the present invention, in the above device, the segments related to dynamic linking include: segments corresponding to the symbol table and segments corresponding to the string table; and the fusion unit 220 is adapted to remove duplicate symbols and strings.

[0118] In one embodiment of the present invention, in the above-mentioned device, the fusion unit 220 is suitable for replacing the name of JNI_Onload and saving the address of the JNI_Onload if there is JNI_Onload in the SO file to be hardened, so that after the hardened SO file is loaded, the saved address of the JNI_Onload is called according to the anti-attack logic.

[0119] In one embodiment of the present invention, in the above-mentioned device, the segments related to dynamic linking include: segments corresponding to the relocation table; a fusion unit 220, suitable for correcting the offset of the relocation table and encrypting the relocation table of the SO file to be reinforced; and the anti-attack logic is used to decrypt the encrypted relocation table after the reinforced SO file is loaded.

[0120] In one embodiment of the present invention, in the above-mentioned device, the encryption and decryption keys are generated based on the package name of the application containing the hardened SO file and / or the MD5 value of the signature file; the anti-attack logic is also used to prevent the interface for obtaining the application package name and / or signature file from being hooked.

[0121] In one embodiment of the present invention, in the above device, the fusion unit 220 is adapted to generate a new related segment according to the merged segment; and merge the generated new related segment and the merged segment into a new PT_LOAD segment.

[0122] In one embodiment of the present invention, in the above-mentioned device, the fusion unit 220 is suitable for erasing the ELF header information and segment table information of the SO file to be reinforced, and writing the information into the target SO file in the following order to obtain the reinforced SO file: new ELF header information, new segment table information, null bytes, the SO file to be reinforced and all the contents of the preset SO file, the new PT_LOAD segment, the new section header and the section.

[0123] It should be noted that the specific implementation of the above-mentioned device embodiments can be carried out with reference to the specific implementation of the above-mentioned corresponding method embodiments, which will not be repeated here.

[0124] In summary, the technical solution of the present invention, after obtaining the SO file to be reinforced, merges the SO file to be reinforced with the pre-set SO file based on the dynamic view of the SO file to obtain the reinforced SO file; wherein the pre-set SO file includes anti-attack logic. The beneficial effect of this technical solution is that for many SO files to be reinforced, only one or more SO files that protect the anti-attack logic need to be pre-set, and reinforcement is achieved through the fusion of SO files, providing a SO file protection method that is independent of the development process, and is relatively convenient to implement and can also achieve good protection effects.

[0125] It should be noted that:

[0126] The algorithm and display provided herein are not inherently related to any particular computer, virtual device or other equipment. Various general-purpose devices can also be used together with the teachings based on this. According to the above description, it is obvious to construct the structure required for this type of device. In addition, the present invention is not directed to any specific programming language either. It should be understood that various programming languages ​​can be utilized to realize the content of the present invention described herein, and the description of the above specific language is for the purpose of disclosing the best mode of the present invention.

[0127] In the description provided herein, a large number of specific details are described. However, it is understood that embodiments of the present invention can be practiced without these specific details. In some instances, well-known methods, structures and techniques are not shown in detail so as not to obscure the understanding of this description.

[0128] Similarly, it should be understood that in order to streamline the present invention and aid in understanding one or more of the various inventive aspects, in the above description of exemplary embodiments of the present invention, the various features of the present invention are sometimes grouped together into a single embodiment, figure, or description thereof. However, this disclosed method should not be interpreted as reflecting the following intention: that the claimed invention requires more features than the features explicitly recited in each claim. More specifically, as reflected in the claims below, inventive aspects lie in less than all the features of the individual embodiments disclosed above. Therefore, the claims that follow the specific embodiment are hereby expressly incorporated into the specific embodiment, with each claim itself serving as a separate embodiment of the present invention.

[0129] Those skilled in the art will appreciate that the modules in the devices in the embodiments may be adaptively changed and arranged in one or more devices different from the embodiments. The modules or units or components in the embodiments may be combined into one module or unit or component, and in addition they may be divided into a plurality of submodules or subunits or subcomponents. Except that at least some of such features and / or processes or units are mutually exclusive, all features disclosed in this specification (including the accompanying claims, abstracts and drawings) and all processes or units of any method or device disclosed in this manner may be combined in any combination. Unless otherwise expressly stated, each feature disclosed in this specification (including the accompanying claims, abstracts and drawings) may be replaced by an alternative feature providing the same, equivalent or similar purpose.

[0130] In addition, those skilled in the art will appreciate that, although some embodiments described herein include certain features included in other embodiments but not other features, the combination of features of different embodiments is meant to be within the scope of the present invention and form different embodiments. For example, in the claims below, any one of the claimed embodiments may be used in any combination.

[0131] The various component embodiments of the present invention may be implemented in hardware, or in software modules running on one or more processors, or in a combination thereof. Those skilled in the art will appreciate that a microprocessor or digital signal processor (DSP) may be used in practice to implement some or all of the functions of some or all of the components in the reinforcement device for the dynamic link library SO file according to an embodiment of the present invention. The present invention may also be implemented as a device or apparatus program (e.g., a computer program and a computer program product) for executing part or all of the methods described herein. Such a program for implementing the present invention may be stored on a computer-readable medium, or may be in the form of one or more signals. Such a signal may be downloaded from an Internet website, or provided on a carrier signal, or provided in any other form.

[0132] For example, Figure 3A schematic diagram of the structure of an electronic device according to an embodiment of the present invention is shown. The electronic device 300 includes a processor 310 and a memory 320 arranged to store computer executable instructions (computer readable program code). The memory 320 can be an electronic memory such as a flash memory, an EEPROM (electrically erasable programmable read-only memory), an EPROM, a hard disk or a ROM. The memory 320 has a storage space 330 for storing a computer readable program code 331 for executing any method step in the above method. For example, the storage space 330 for storing computer readable program code may include individual computer readable program codes 331 for implementing various steps in the above method respectively. The computer readable program code 331 can be read from or written into one or more computer program products. These computer program products include program code carriers such as a hard disk, a compact disk (CD), a memory card or a floppy disk. Such a computer program product is typically, for example Figure 4 The computer-readable storage medium. Figure 4 A schematic diagram of the structure of a computer-readable storage medium according to an embodiment of the present invention is shown. The computer-readable storage medium 400 stores a computer-readable program code 331 for executing the method steps according to the present invention, which can be read by the processor 310 of the electronic device 300. When the computer-readable program code 331 is executed by the electronic device 300, the electronic device 300 executes the various steps in the method described above. Specifically, the computer-readable program code 331 stored in the computer-readable storage medium can execute the method shown in any of the above embodiments. The computer-readable program code 331 can be compressed in an appropriate form.

[0133] It should be noted that the above embodiments illustrate the present invention rather than limit it, and that those skilled in the art may devise alternative embodiments without departing from the scope of the appended claims. In the claims, any reference symbol between brackets shall not be construed as a limitation on the claims. The word "comprising" does not exclude the presence of elements or steps not listed in the claims. The word "one" or "an" preceding an element does not exclude the presence of a plurality of such elements. The present invention may be implemented by means of hardware comprising a number of different elements and by means of a suitably programmed computer. In a unit claim enumerating a number of devices, several of these devices may be embodied by the same hardware item. The use of the words first, second, and third, etc., does not indicate any order. These words may be interpreted as names.

[0134] The embodiment of the present invention discloses A1, a method for reinforcing a dynamic link library SO file, comprising:

[0135] Get the SO file to be reinforced;

[0136] Based on the dynamic view of the SO file, the SO file to be reinforced is merged with the preset SO file to obtain a reinforced SO file;

[0137] Wherein, the preset SO file includes anti-attack logic.

[0138] A2. The method as described in A1, wherein the dynamic view based on the SO file, merging the SO file to be reinforced with the preset SO file to obtain the reinforced SO file comprises:

[0139] The SO file to be reinforced and the preset SO file are parsed respectively, and the segments of the specified type are merged based on the parsing results.

[0140] A3. The method as described in A2, wherein the analysis result includes one or more of the following information:

[0141] The loading address of the SO file, the ELF header information of the SO file, the segment table information of the SO, the starting address of each segment in the SO file, and the size of each segment in the SO file.

[0142] A4. The method as described in A2, wherein the specified type of segment includes: a PT_LOAD type segment;

[0143] The merging of the specified type of segments includes: adding the segment table information of type PT_LOAD parsed from the preset SO file to the segment table information parsed from the SO file to be consolidated to obtain new segment table information.

[0144] A5. The method as described in A2, wherein the segments of the specified type include: segments related to dynamic links.

[0145] A6. The method of A5, wherein the segments related to dynamic linking include: segments corresponding to a symbol table and segments corresponding to a string table;

[0146] The merging of the segments of the specified type includes: removing repeated symbols and character strings.

[0147] A7. The method as described in A6, wherein the removing of repeated symbols and character strings comprises:

[0148] If there is JNI_Onload in the SO file to be reinforced, its name is replaced and the address of the JNI_Onload is saved, so that after the reinforced SO file is loaded, the saved address of the JNI_Onload is called according to the anti-attack logic.

[0149] A8. The method as described in A5, wherein the segments related to dynamic linking include: segments corresponding to a relocation table;

[0150] The merging of the segments of the specified type includes: correcting the offset of the relocation table, and encrypting the relocation table of the SO file to be reinforced;

[0151] The anti-attack logic is used to decrypt the encrypted relocation table after the hardened SO file is loaded.

[0152] A9. The method as described in A8, wherein the encryption and decryption keys are generated according to the package name of the application containing the hardened SO file and / or the MD5 value of the signature file;

[0153] The anti-attack logic is also used to prevent the interface for obtaining the application package name and / or signature file from being hooked.

[0154] A10. The method as described in A2, wherein the step of fusing the SO file to be reinforced with the preset SO file further comprises:

[0155] Generate new related segments based on the merged segments;

[0156] New related segments and merged segments will be generated and merged into a new PT_LOAD segment.

[0157] A11. The method as described in A1, wherein the step of fusing the SO file to be reinforced with the preset SO file further comprises:

[0158] Erase the ELF header information and segment table information of the SO file to be reinforced, and write the information into the target SO file in the following order to obtain the reinforced SO file:

[0159] New ELF header information, new segment table information, null bytes, the SO file to be hardened, the entire content of the preset SO file, the new PT_LOAD segment, the new section header and section.

[0160] The embodiment of the present invention further discloses B12, a device for reinforcing a dynamic link library SO file, comprising:

[0161] An acquisition unit, adapted to acquire the SO file to be reinforced;

[0162] The fusion unit is adapted to fuse the SO file to be reinforced with a preset SO file based on a dynamic view of the SO file to obtain a reinforced SO file; wherein the preset SO file includes anti-attack logic.

[0163] B13. The device as described in B12, wherein:

[0164] The fusion unit is adapted to parse the SO file to be reinforced and the preset SO file respectively, and merge the segments of the specified type based on the parsing results.

[0165] B14. The device as described in B13, wherein the analysis result includes one or more of the following information:

[0166] The loading address of the SO file, the ELF header information of the SO file, the segment table information of the SO, the starting address of each segment in the SO file, and the size of each segment in the SO file.

[0167] B15. The apparatus of B13, wherein the segments of the specified type include: segments of PT_LOAD type;

[0168] The fusion unit is adapted to add the segment table information of type PT_LOAD parsed from the preset SO file to the segment table information parsed from the SO file to be reinforced, so as to obtain new segment table information.

[0169] B16. An apparatus as described in B13, wherein the specified type of segment includes: a segment related to dynamic linking.

[0170] B17, as described in B16, wherein, described segment related to dynamic link comprises: the segment corresponding to symbol table and the segment corresponding to string table;

[0171] The fusion unit is adapted to remove repeated symbols and character strings.

[0172] B18. The device as described in B17, wherein

[0173] The fusion unit is adapted to replace the name of JNI_Onload and save the address of the JNI_Onload if there is JNI_Onload in the SO file to be reinforced, so that after the reinforced SO file is loaded, the saved address of the JNI_Onload is called according to the anti-attack logic.

[0174] B19. The apparatus as described in B16, wherein the segment related to dynamic linking includes: a segment corresponding to a relocation table;

[0175] The fusion unit is suitable for correcting the offset of the relocation table and encrypting the relocation table of the SO file to be reinforced; the anti-attack logic is used to decrypt the encrypted relocation table after the reinforced SO file is loaded.

[0176] B20. A device as described in B19, wherein the encryption and decryption keys are generated based on the package name of the application containing the hardened SO file and / or the MD5 value of the signature file; and the anti-attack logic is also used to prevent the interface for obtaining the application package name and / or signature file from being hooked.

[0177] B21. The device as described in B14, wherein:

[0178] The fusion unit is adapted to generate a new related segment according to the merged segment; and merge the generated new related segment and the merged segment into a new PT_LOAD segment.

[0179] B22. The device as described in B13, wherein:

[0180] The fusion unit is suitable for erasing the ELF header information and segment table information of the SO file to be reinforced, and writing the information into the target SO file in the following order to obtain the reinforced SO file: new ELF header information, new segment table information, null bytes, the SO file to be reinforced and all the contents of the preset SO file, the new PT_LOAD segment, the new section header and the section.

[0181] An embodiment of the present invention also discloses C23, an electronic device, wherein the electronic device comprises: a processor; and a memory arranged to store computer executable instructions, wherein the executable instructions, when executed, cause the processor to execute a method as described in any one of A1-A11.

[0182] An embodiment of the present invention further discloses D24, a computer-readable storage medium, wherein the computer-readable storage medium stores one or more programs, and when the one or more programs are executed by a processor, implement the method as described in any one of A1-A11.

Claims

1. A method for reinforcing a dynamic link library SO file, comprising: Get the SO file to be reinforced; Based on the dynamic view of the SO file, the SO file to be reinforced is merged with the preset SO file to obtain a reinforced SO file; Wherein, the preset SO file includes anti-attack logic; The dynamic view based on the SO file merges the SO file to be reinforced with the preset SO file to obtain the reinforced SO file, including: The SO file to be reinforced and the preset SO file are parsed respectively, and segments of a specified type are merged based on the parsing results; The specified type of segments include: PT_LOAD type segments; The merging of the specified type of segments includes: adding the segment table information of type PT_LOAD parsed from the preset SO file to the segment table information parsed from the SO file to be consolidated to obtain new segment table information.

2. The method of claim 1, wherein: The analysis result includes one or more of the following information: The loading address of the SO file, the ELF header information of the SO file, the segment table information of the SO, the starting address of each segment in the SO file, and the size of each segment in the SO file.

3. The method of claim 1, wherein: The specified type of segments includes: segments related to dynamic links.

4. The method of claim 3, wherein: The segments related to dynamic linking include: segments corresponding to the symbol table and segments corresponding to the string table; The merging of the segments of the specified type includes: removing repeated symbols and character strings.

5. The method of claim 4, wherein: The removal of repeated symbols and strings includes: If there is JNI_Onload in the SO file to be reinforced, its name is replaced and the address of the JNI_Onload is saved, so that after the reinforced SO file is loaded, the saved address of the JNI_Onload is called according to the anti-attack logic.

6. The method of claim 3, wherein: The segments related to dynamic linking include: segments corresponding to the relocation table; The merging of the segments of the specified type includes: correcting the offset of the relocation table, and encrypting the relocation table of the SO file to be reinforced; The anti-attack logic is used to decrypt the encrypted relocation table after the hardened SO file is loaded.

7. The method of claim 6, wherein: The encryption and decryption keys are generated according to the package name of the application containing the reinforced SO file and / or the MD5 value of the signature file; The anti-attack logic is also used to prevent the interface for obtaining the application package name and / or signature file from being hooked.

8. The method of claim 1, wherein: The step of fusing the SO file to be reinforced with the preset SO file further includes: Generate new related segments based on the merged segments; New related segments and merged segments will be generated and merged into a new PT_LOAD segment.

9. The method of claim 1, wherein: The step of fusing the SO file to be reinforced with the preset SO file further includes: Erase the ELF header information and segment table information of the SO file to be reinforced, and write the information into the target SO file in the following order to obtain the reinforced SO file: New ELF header information, new segment table information, null bytes, the SO file to be hardened, the entire content of the preset SO file, the new PT_LOAD segment, the new section header and section.

10. A device for reinforcing a dynamic link library SO file, comprising: An acquisition unit, adapted to acquire the SO file to be reinforced; A fusion unit, adapted to fuse the SO file to be reinforced with a preset SO file based on a dynamic view of the SO file to obtain a reinforced SO file; wherein the preset SO file includes anti-attack logic; The fusion unit is adapted to parse the SO file to be reinforced and the preset SO file respectively, and merge the segments of the specified type based on the parsing results; The specified type of segments include: PT_LOAD type segments; The fusion unit is adapted to add the segment table information of type PT_LOAD parsed from the preset SO file to the segment table information parsed from the SO file to be reinforced, so as to obtain new segment table information.

11. The device of claim 10, wherein: The analysis result includes one or more of the following information: The loading address of the SO file, the ELF header information of the SO file, the segment table information of the SO, the starting address of each segment in the SO file, and the size of each segment in the SO file.

12. The device of claim 10, wherein: The specified type of segments includes: segments related to dynamic links.

13. The device of claim 12, wherein: The segments related to dynamic linking include: segments corresponding to the symbol table and segments corresponding to the string table; The fusion unit is adapted to remove repeated symbols and character strings.

14. The device of claim 13, wherein: The fusion unit is adapted to replace the name of JNI_Onload and save the address of the JNI_Onload if there is JNI_Onload in the SO file to be reinforced, so that after the reinforced SO file is loaded, the saved address of the JNI_Onload is called according to the anti-attack logic.

15. The device of claim 12, wherein: The segments related to dynamic linking include: segments corresponding to the relocation table; The fusion unit is suitable for correcting the offset of the relocation table and encrypting the relocation table of the SO file to be reinforced; the anti-attack logic is used to decrypt the encrypted relocation table after the reinforced SO file is loaded.

16. The device of claim 15, wherein: The encryption and decryption keys are generated based on the package name of the application containing the reinforced SO file and / or the MD5 value of the signature file; the anti-attack logic is also used to prevent the interface for obtaining the application package name and / or signature file from being hooked.

17. The device of claim 10, wherein: The fusion unit is adapted to generate a new related segment according to the merged segment; and merge the generated new related segment and the merged segment into a new PT_LOAD segment.

18. The device of claim 10, wherein: The fusion unit is suitable for erasing the ELF header information and segment table information of the SO file to be reinforced, and writing the information into the target SO file in the following order to obtain the reinforced SO file: new ELF header information, new segment table information, null bytes, the SO file to be reinforced and all the contents of the preset SO file, the new PT_LOAD segment, the new section header and the section.

19. An electronic device, wherein: The electronic device comprises: a processor; and a memory arranged to store computer executable instructions, wherein when the executable instructions are executed, the processor performs the method according to any one of claims 1 to 9.

20. A computer-readable storage medium, wherein: The computer-readable storage medium stores one or more programs, which, when executed by a processor, implement the method according to any one of claims 1 to 9.

Citation Information

Patent Citations

  • Calculation method and system for features of ELF files based on Linux kernel operation system

    CN106557692A

  • Reinforcement method, running method, reinforcement device and security system for dynamic link library

    CN107291485A