Method, apparatus, device, and storage medium for obtaining call chain of third-party library

By relocating the objc_msgSend method using hook function in iOS system, obtaining the call chain of the third-party library, the problem of difficult to obtain the call chain in the static library is solved, and the analysis efficiency is improved and application security is enhanced.

CN112612555BActive Publication Date: 2025-07-08SAI ANDY TECHNOLOGY (HONG KONG) CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202011551786.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-12-24
Publication Date
2025-07-08
Estimated Expiration
2040-12-24

AI Technical Summary

Technical Problem

It is difficult for the existing technology to efficiently obtain call chains in third-party libraries built on static libraries, resulting in cumbersome and inefficient analysis.

Method used

By obtaining the system architecture symbol table of the target application, using the hook function to relocate the objc_msgSend method, point its call request to the hook function, obtain and output the call chain, and detect key interface calls, generate alarm information or disable the call method.

Benefits of technology

It realizes the rapid acquisition of call chains in static libraries, improves analysis efficiency, enhances the security and memory management of target applications, and reduces manual analysis costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN112612555B_ABST
    Figure CN112612555B_ABST
Patent Text Reader

Abstract

The present application relates to the technical field of R & D management, and discloses a method for obtaining a call chain of a third-party library, including: obtaining a symbol table provided by a system architecture corresponding to a target application; querying all objc_msgSend methods in the symbol table, and using a hook function to suspend the obtained objc_msgSend methods, so as to direct a call request of the objc_msgSend method in the symbol table to the hook function; executing a call request task corresponding to the symbol table to call the hook function, wherein when the hook function is called, the objc_msgSend method suspended by the hook function is executed, and a call chain of the calling method corresponding to the objc_msgSend method is obtained; outputting the call chains obtained by all the hook functions. The present application also relates to the technical field of blockchain. The present application also discloses a device for obtaining a call chain of a third-party library, a computer device, and a computer-readable storage medium. The present application improves the efficiency of obtaining a call chain corresponding to a calling method in a static library.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field of R & D management, and particularly to a method for obtaining a call chain of a third-party library, an apparatus for obtaining a call chain of a third-party library, a computer device, and a computer-readable storage medium. Background Art

[0002] Currently, some application software supports the invocation of functions of third-party applications. To achieve this process, the SDK (Software Development Kit) corresponding to the third-party application needs to be used as a third-party library and integrated into the application that needs to invoke the functions of the third-party application. At this time, when the engineer of this application needs to analyze the method calls in the third-party library accessed from the outside due to application security considerations or other test requirements, the specific call chain of these methods needs to be obtained to carry out the analysis work.

[0003] However, for a third-party library built based on a static library, since the static library is integrated into the host project after participating in the compilation in the project, it is difficult to query the method calls provided by the static library, and it is also difficult to obtain the call chain of these methods. Currently, generally, the function exchange method is used to export all the function declarations in the static library one by one, and then the relevant information of the method calls in the static library is obtained, but this process is quite cumbersome and inefficient.

[0004] The above content is only used to assist in understanding the technical solution of the present application, and does not represent an admission that the above content is prior art. Summary of the Invention

[0005] The main purpose of the present application is to provide a method for obtaining a call chain of a third-party library, an apparatus for obtaining a call chain of a third-party library, a computer device, and a computer-readable storage medium, aiming to solve the problem of how to improve the efficiency of obtaining the call chain corresponding to the call method in the static library accessed by the target application.

[0006] To achieve the above object, the present application provides a method for obtaining a call chain of a third-party library, including the following steps:

[0007] Obtain a symbol table provided by the system architecture corresponding to the target application, where the symbol table is used to record the call methods in the third-party library accessed by the target application as objc_msgSend methods;

[0008] Query all objc_msgSend methods in the symbol table, and use a hook function to suspend the queried objc_msgSend methods, so that the call requests of the objc_msgSend methods in the symbol table point to the hook function;

[0009] Execute the call request task corresponding to the symbol table to call the hook function. When the hook function is called, execute the objc_msgSend method suspended by the hook function and obtain the call chain of the calling method corresponding to the objc_msgSend method;

[0010] Output all the call chains obtained by the hook functions.

[0011] Further, after the step of outputting all the call chains obtained by the hook functions, it further includes:

[0012] Detect whether the call chain involves a call to a key interface of the target application;

[0013] When it is detected that the call chain involves a call to the key interface, generate an alarm message according to the call chain and the key interface, and / or disable the calling method corresponding to the call chain.

[0014] Further, the step of generating an alarm message according to the call chain and the key interface, and / or disabling the calling method corresponding to the call chain includes:

[0015] Detect whether the third-party library corresponding to the call chain has the call permission for the key interface;

[0016] If not, generate an alarm message according to the call chain and the key interface, and / or disable the calling method corresponding to the call chain.

[0017] Further, after the step of generating an alarm message according to the call chain and the key interface, it further includes:

[0018] Output the alarm message to the associated device, and the alarm message includes the acquisition request corresponding to the call permission;

[0019] When receiving the confirmation response sent by the associated device based on the alarm message, grant the call permission to the third-party library corresponding to the call chain;

[0020] When receiving the negative response sent by the associated device based on the alarm message, disable the calling method corresponding to the call chain.

[0021] Further, after the step of disabling the calling method corresponding to the call chain, it further includes:

[0022] Detect whether there are any calling methods in the third-party library that have not been disabled;

[0023] If not, delete the third-party library.

[0024] Further, after the step of executing the call request task corresponding to the symbol table to call the hook function, the method further includes:

[0025] Generating a call linked list based on the call chain obtained from all the hook functions;

[0026] Sending the call linked list to a storage server for storage in a block-chain ledger.

[0027] Further, the step of querying all objc_msgSend methods in the symbol table includes:

[0028] Querying all objc_msgSend methods in the symbol table by using the MachOView tool; or,

[0029] Querying all objc_msgSend methods in the symbol table by using a crawler script.

[0030] To achieve the above object, the present application further provides an apparatus for obtaining a call chain of a third-party library, the apparatus for obtaining a call chain of a third-party library includes:

[0031] An obtaining module, configured to obtain a symbol table provided by a system architecture corresponding to a target application, where the symbol table is used to record call methods in a third-party library accessed by the target application as objc_msgSend methods;

[0032] A processing module, configured to query all objc_msgSend methods in the symbol table, and suspend the queried objc_msgSend methods by using hook functions, so that a call request of the objc_msgSend method in the symbol table points to the hook functions;

[0033] An execution module, configured to execute a call request task corresponding to the symbol table to call the hook functions, where when the hook functions are called, the objc_msgSend methods suspended by the hook functions are executed, and a call chain of the call methods corresponding to the objc_msgSend methods is obtained;

[0034] An output module, configured to output the call chains obtained from all the hook functions.

[0035] To achieve the above object, the present application further provides a computer device, the computer device includes:

[0036] The computer device includes a memory, a processor, and a call chain acquisition program of a third-party library stored on the memory and operable on the processor. When the call chain acquisition program of the third-party library is executed by the processor, the steps of the call chain acquisition method of the third-party library as described above are implemented.

[0037] To achieve the above object, the present application further provides a computer-readable storage medium on which a call chain acquisition program of a third-party library is stored. When the call chain acquisition program of the third-party library is executed by a processor, the steps of the call chain acquisition method of the third-party library as described above are implemented.

[0038] The call chain acquisition method, call chain acquisition device, computer device, and computer-readable storage medium of the third-party library provided by the present application relocate the call of the objc_msgSend method to a corresponding hook function, so as to quickly obtain the call chain corresponding to the call method of the third-party library mapped by the objc_msgSend method by using the hook function, and can be applied to the third-party library built based on the static library, thereby improving the efficiency of obtaining the call chain corresponding to the call method in the static library accessed by the target application. BRIEF DESCRIPTION OF THE DRAWINGS

[0039] Figure 1 It is a schematic diagram of the steps of the call chain acquisition method of the third-party library in an embodiment of the present application;

[0040] Figure 2 It is a schematic block diagram of the call chain acquisition device of the third-party library in an embodiment of the present application;

[0041] Figure 3 It is a schematic block diagram of the structure of the computer device in an embodiment of the present application.

[0042] The implementation, functional features, and advantages of the object of the present application will be further described with reference to the embodiments and the accompanying drawings. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0043] In order to make the object, technical solution, and advantages of the present application clearer, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.

[0044] Referring to Figure 1 , in an embodiment, the call chain acquisition method of the third-party library includes:

[0045] Step S10: Obtain a symbol table provided by the system architecture corresponding to the target application, where the symbol table is used to record the call method in the third-party library accessed by the target application as the objc_msgSend method;

[0046] Step S20: Query all objc_msgSend methods in the symbol table, and use a hook function to suspend the queried objc_msgSend methods, so that the call requests for the objc_msgSend methods in the symbol table point to the hook function;

[0047] Step S30: Execute the call request task corresponding to the symbol table to call the hook function. When the hook function is called, execute the objc_msgSend method suspended by the hook function and obtain the call chain of the calling method corresponding to the objc_msgSend method;

[0048] Step S40: Output all the call chains obtained by the hook functions.

[0049] In this embodiment, the execution terminal of the embodiment can be a computer device or a call chain acquisition device for a third-party library.

[0050] As described in step S10: The target application is an application that accesses a third-party library (i.e., the SDK software development kit corresponding to the third-party application), where the third-party library is a static library. It should be noted that the library files provided by the system architecture corresponding to the operating system for running the target application are the first-party libraries, and the library files in the software engineering project of the target application itself are the second-party libraries. Therefore, the SDK (or library files) corresponding to the third-party application accessed by the target application is the third-party library; a static library refers to a library in a software engineering project where common code is compiled into a library file, and then in the linking step, the linker retrieves the required code from the library file and copies it into the generated executable file.

[0051] Optionally, the target application can be installed on the terminal or on a device that is communicatively connected to the terminal and is used for the terminal to test or debug. The system architecture corresponding to the target application is the system architecture of the operating system of the terminal or device on which the target application is installed. Hereinafter, an example will be given with the operating system being the iOS system.

[0052] Optionally, the symbol table provided by the system architecture of the iOS system is the iOS symbol table. It should be noted that the symbol table is a mapping table of memory addresses and method names (or function names), file names, and line numbers.

[0053] On the iOS system, all Objective-C function calls in an APP (Application) written in the Objective-C language are ultimately converted into calls to the objc_msgSend method (a type of C method) at the lowest level. In the iOS system, any runnable program (including static libraries, dynamic libraries, redirected files, etc.) is in the Mach-O file format (this format is mainly used to define what a file is and how it is executed by the system, etc.). In the Mach-O file format, any method that is not implemented in this file, such as the objc_msgSend method (the specific implementation of this method is in the system library), will be recorded in the iOS symbol table. Therefore, when the target application and the third-party library are written in the Objective-C language, all the call methods in the third-party library will be mapped to the corresponding objc_msgSend method and recorded in the iOS symbol table in the form of the objc_msgSend method.

[0054] Optionally, when the terminal receives a call chain acquisition instruction for a call method in the third-party library accessed by the target application, it can obtain the symbol table provided by the system architecture corresponding to the target application. At this time, the obtained symbol table already records the call methods in the third-party library in the form of the objc_msgSend method.

[0055] As described in step S20: Since the obtained symbol table records not only the objc_msgSend method but also some other methods, it is necessary to first perform a query operation on the objc_msgSend method in the symbol table.

[0056] Optionally, the terminal can use a pre-written crawler script to query all the objc_msgSend methods in the symbol table and the positions where the objc_msgSend methods are recorded in the symbol table by capturing the method name "objc_msgSend" corresponding to the objc_msgSend method in the symbol table.

[0057] Optionally, since the executable programs (including the objc_msgSend method) in the iOS system belong to the Mach-O file format, the terminal can use the MachOView tool to query the Mach-O file format information, and then obtain the Mach-O file corresponding to the objc_msgSend method, that is, to know all the objc_msgSend methods recorded in the symbol table and the positions where the objc_msgSend methods are recorded in the symbol table.

[0058] Optionally, the terminal is pre-written with a hook function. When the terminal queries and obtains the objc_msgSend method in the symbol table, according to the position of the method name corresponding to the objc_msgSend method in the symbol table, the method name corresponding to the objc_msgSend method at that position is replaced with the method name (or function name) corresponding to the hook function, and the objc_msgSend method it replaces is suspended using the hook function. In this way, the call request corresponding to the objc_msgSend method in the symbol table is directed to the hook function. Thus, the original call request in the symbol table for the objc_msgSend method is transformed into a call request for the hook function (equivalent to intercepting the original objc_msgSend method and executing the corresponding hook function).

[0059] Among them, the field length of the method name corresponding to the hook function needs to be the same as that of the method name corresponding to the objc_msgSend method. For example, if the method name corresponding to the objc_msgSend method is "objc_msgSend", the method name corresponding to the hook function can be defined as "dyna_msgSend".

[0060] It should be noted that the hook function belongs to a message processing mechanism. A "hook" is actually a program segment for processing messages, which is hooked into the system through a system call. An application program can intercept and process some specific messages or other specific events through the hook function. In the hook function, whenever a specific message is sent, before it reaches the destination window, the hook program captures the message first, that is, the hook function gets control first.

[0061] Therefore, by suspending the objc_msgSend method using the hook function, the specific information targeted by the hook function (i.e., the information to be intercepted by the hook function) can be specified as the message passing process involved during the execution of the objc_msgSend method.

[0062] As described in step S30: When the terminal replaces all the objc_msgSend methods recorded in the symbol table with hook functions, the software project corresponding to the target application can be run to execute the call request task corresponding to the symbol table.

[0063] When the target application's operating system invokes the method recorded in this symbol table during the call request task execution. Since the method names of all the objc_msgSend methods recorded in the symbol table are replaced with the method names corresponding to the hook functions, the original call request used to call the objc_msgSend method will be changed to call the hook function used to suspend the objc_msgSend method.

[0064] Furthermore, when the hook function is called, the information interception task will be started, and the objc_msgSend method suspended by it will be executed. In this way, the call method of the third-party library mapped by the objc_msgSend method (i.e., the call method corresponding to the objc_msgSend method) will be called (or executed). Then, during the period when the call method is called, the message passing process involved (including nodes involved in the message passing process (such as application programming interfaces), the results feedback by the involved application programming interfaces, the time when the message is passed to each node, etc.) will be intercepted by the hook function. Based on the relevant data intercepted, the hook function can obtain the call chain (or call path) involved when the call method is called.

[0065] As described in step S40: when the terminal uses the hook function to obtain the call chain corresponding to the call method of the third-party library, the hook function will also obtain the specific method name of the call method, and then associate and output the method name and call chain of the call method to the terminal.

[0066] Optionally, when the terminal obtains the call chains corresponding to the call methods output by all hook functions, it can generate a call list based on all the call chains and the method names of the call methods associated with the call chains. Then the terminal outputs and displays the call list, or outputs the call list to the associated devices of relevant engineers to uniformly output all the call chains, enabling relevant engineers to analyze the method calls in the third-party library based on this.

[0067] In one embodiment, by redirecting the call of the objc_msgSend method to the corresponding hook function, it is possible to quickly obtain the call chain corresponding to the call method of the third-party library mapped by the objc_msgSend method using the hook function, and it is applicable to third-party libraries built based on static libraries, thereby improving the efficiency of obtaining the call chain corresponding to the call method in the static library accessed by the target application.

[0068] In one embodiment, based on the above embodiment, after the step of outputting all the call chains obtained by the hook functions, it further includes:

[0069] Step S50, detect whether the call chain involves calling a key interface of the target application;

[0070] Step S51, when it is detected that the call chain involves calling the key interface, generate an alarm message according to the call chain and the key interface, and / or disable the call method corresponding to the call chain.

[0071] In this embodiment, after the terminal obtains the call chains corresponding to all call methods in the third-party library, it can further detect whether the call processes corresponding to these call chains involve calling a key interface of the target application. Among them, the key interface can be an application program interface predefined by relevant developers of the target application.

[0072] Optionally, the terminal can also pre-detect whether there are interfaces involving sensitive data in the application program interfaces of the target application, and use the application program interfaces involving sensitive data as key interfaces. Among them, the sensitive data can be some user-sensitive information such as the user's name, mobile phone number, ID card, loan product, home address, etc., or key system data with a high security level.

[0073] Optionally, when the terminal detects that the call process corresponding to a call chain involves calling a key interface, it means that the call chain may involve a call risk. Then, the terminal can generate an alarm message according to the call chain and the key interface involved in the call chain, and output the alarm message to the associated device of the relevant engineer for the relevant engineer to perform further risk analysis on the call chain, so that the engineer can take relevant risk control operations in time to ensure the security of the target application and avoid the occurrence of data leakage.

[0074] And / or, when the terminal detects that the call process corresponding to a call chain involves calling a key interface, it can directly disable the call method corresponding to the call connection to ensure the security of the target application and avoid the occurrence of data leakage.

[0075] Optionally, when the terminal does not detect that the call process corresponding to the call chain involves calling a key interface, the terminal can do nothing.

[0076] In this way, it realizes automatic risk analysis of the obtained call chains and takes corresponding risk control operations, which improves the security of the target application calling the third-party library while saving the cost of manual call chain analysis to a certain extent and improving the efficiency of risk analysis of call chains.

[0077] In one embodiment, based on the above embodiment, the step of generating an alarm message according to the call chain and the key interface, and / or disabling the call method corresponding to the call chain includes:

[0078] Step S60: Detect whether the third-party library corresponding to the call chain has the call permission for the critical interface;

[0079] Step S61: If not, generate an alarm message based on the call chain and the critical interface, and / or disable the call method corresponding to the call chain.

[0080] In this embodiment, when the terminal detects that a call process corresponding to a call chain involves a call to a critical interface, it can first further detect whether the third-party library to which the call method corresponding to the call chain belongs has the call permission for the critical interface.

[0081] Optionally, when the terminal detects that the call permission associated with the third-party library has the call permission for the critical interface, the terminal may not take any action; when the terminal detects that the third-party library does not have the call permission for the critical interface, it means that the third-party library calls the critical interface without permission, for example, by exploiting a system vulnerability to call the critical interface. In this case, the terminal may execute the step of generating an alarm message based on the call chain and the critical interface, and / or execute the step of disabling the call method corresponding to the call chain.

[0082] In this way, the risk of illegal intrusion when the target application allows the call of the third-party library can be reduced.

[0083] In one embodiment, based on the above embodiment, after the step of generating an alarm message according to the call chain and the critical interface, the following steps are further included:

[0084] Step S70: Output the alarm message to the associated device, where the alarm message includes the acquisition request corresponding to the call permission;

[0085] Step S71: When receiving the confirmation response sent by the associated device based on the alarm message, grant the call permission to the third-party library corresponding to the call chain;

[0086] Step S72: When receiving the negative response sent by the associated device based on the alarm message, disable the call method corresponding to the call chain.

[0087] In this embodiment, when the terminal detects that a call process corresponding to a call chain involves a call to a critical interface and detects that the third-party library corresponding to the call chain does not have the call permission for the critical interface, it means that the call chain involves a call risk. Then the terminal can generate an alarm message according to the call chain and the critical interface involved in the call chain (without disabling the call method corresponding to the call chain at this time). Moreover, the alarm message generated by the terminal may also include the acquisition request corresponding to the call permission of the critical interface.

[0088] Furthermore, the terminal outputs the generated alarm information to the associated devices of relevant engineers for the relevant engineers to conduct further risk analysis on the call chain.

[0089] When an engineer receives the alarm information through the associated device, if it is considered that the call chain described in the alarm information is of low risk (or has no risk), and the third-party library to which the call method corresponding to the call chain belongs is granted the call permission for the key interface, then a confirmation response to the alarm information can be fed back to the terminal through the associated device; if the engineer believes that the call chain described in the alarm information is of high risk, then a negative response to the alarm information can be fed back to the terminal through the associated device.

[0090] Optionally, when the terminal receives the confirmation response sent by the associated device based on the alarm information, the call permission corresponding to the key interface described in the alarm information can be associated with the third-party library to which the call method corresponding to the call chain belongs, so as to grant the call permission to the third-party library.

[0091] Optionally, when the terminal receives the negative response sent by the associated device based on the alarm information, or when the terminal does not receive the positive response sent by the associated device based on the alarm information within the preset duration, the terminal can directly disable the call method corresponding to the call connection to ensure the security of the target application and avoid data leakage. Among them, the value of the preset duration can be set according to actual needs, and this embodiment does not limit it.

[0092] In this way, while improving the efficiency of the target application in conducting risk analysis on the call chain of the third-party library, the security of the target application in calling the third-party library is also ensured.

[0093] In one embodiment, on the basis of the above embodiment, after the step of disabling the call method corresponding to the call chain, the following steps are further included:

[0094] Step S80: Detect whether there is an undisabled call method in the third-party library;

[0095] Step S81: If not, delete the third-party library.

[0096] In this embodiment, after the terminal disables the call method corresponding to the call chain, it can further detect whether there is still an undisabled call method in the third-party library to which the call method belongs.

[0097] Optionally, when the terminal detects that there is still an undisabled call method in the third-party library, the terminal can do nothing; when the terminal detects that there is no undisabled call method in the third-party library, the terminal can directly delete the third-party library, thereby reducing the memory occupation of the third-party library and improving the security of the target application.

[0098] Of course, before deleting the third-party library, the terminal can output a prompt message to prompt the user that there are no un-disabled call methods in the third-party library, and the third-party library can be deleted to save memory. When the terminal receives the confirmation response to the prompt message, it deletes the third-party library that has no un-disabled call methods.

[0099] In this way, while ensuring the security of the target application, the purpose of effectively saving memory can also be achieved.

[0100] In one embodiment, based on the above embodiment, after the step of executing the call request task corresponding to the symbol table to call the hook function, the method further includes:

[0101] Step S90: Generate a call linked list according to the call chains obtained from all the hook functions;

[0102] Step S91: Send the call linked list to the storage server for storage in a block-chain ledger.

[0103] In this embodiment, the terminal is communicatively connected to a storage server constructed based on blockchain technology.

[0104] When the terminal obtains the call chains corresponding to the call methods output by all the hook functions, it can generate a call linked list according to all the call chains and the method names of the call methods associated with the call chains, and send the call linked list to the storage server.

[0105] Optionally, when the storage server receives the call linked list sent by the terminal, it stores the call linked list in the blockchain network in the form of a block-chain ledger. A ledger is a collective term for a blockchain (also known as ledger data) and a state database synchronized with the blockchain. Among them, the blockchain records transactions in the form of files in the file system; the state database records the transactions in the blockchain in the form of different types of key-value pairs, which is used to support the rapid query of transactions in the blockchain.

[0106] Blockchain is a new application mode of computer technologies such as distributed data storage, peer-to-peer transmission, consensus mechanism, and encryption algorithms. A blockchain, essentially a decentralized database, is a string of data blocks generated by using cryptographic methods. Each data block contains information about a batch of network transactions, which is used to verify the validity (anti-counterfeiting) of the information and generate the next block. A blockchain can include a blockchain underlying platform, a platform product service layer, and an application service layer.

[0107] The underlying blockchain platform may include processing modules such as user management, basic services, smart contracts, and operation monitoring. Among them, the user management module is responsible for managing the identity information of all blockchain participants, including maintaining the generation of public and private keys (account management), key management, and maintaining the correspondence between the real identity of the user and the blockchain address (permission management). And under authorization, it supervises and audits the transaction situations of certain real identities, and provides rule configuration for risk control (risk control and auditing); the basic service module is deployed on all blockchain node devices to verify the validity of business requests, and after reaching a consensus on valid requests, records them on the storage. For a new business request, the basic service first performs interface adaptation parsing and authentication processing (interface adaptation), then encrypts the business information through a consensus algorithm (consensus management), transmits it intact and consistently to the shared ledger after encryption (network communication), and performs record storage; the smart contract module is responsible for the registration and issuance of contracts, as well as contract triggering and contract execution. Developers can define contract logic through a certain programming language, publish it to the blockchain (contract registration), and trigger the execution by calling keys or other events according to the logic of the contract terms to complete the contract logic. At the same time, it also provides functions for contract upgrade and cancellation; the operation monitoring module is mainly responsible for the deployment, configuration modification, contract setting, cloud adaptation during the product release process, and visual output of the real-time state during product operation, such as: alarming, monitoring network conditions, monitoring the health status of node devices, etc.

[0108] Optionally, when the terminal receives a call chain acquisition instruction sent by an associated device, it forwards the call chain acquisition instruction to the storage server. After the storage server receives the call chain acquisition instruction, it feeds back the call chain to the terminal, which then forwards it to the associated device. Or, after the storage server receives the call chain acquisition instruction, it can also directly send the call chain to the associated device.

[0109] In this way, the security of storing the call chain corresponding to the call method in the third-party library is improved, the security vulnerability of the target application caused by call chain leakage is avoided, and thus the security of the target application is improved.

[0110] In one embodiment, based on the above embodiment, the step of querying all objc_msgSend methods in the symbol table includes:

[0111] Step 21, use the MachOView tool to query all objc_msgSend methods in the symbol table; or,

[0112] Step S22, use a crawler script to query all objc_msgSend methods in the symbol table.

[0113] In this embodiment, since the executable programs (including the objc_msgSend method) in the iOS system belong to the Mach-O file format, the terminal can use the MachOView tool to query the Mach-O file format information, and then obtain the Mach-O file corresponding to the objc_msgSend method, so as to know all the objc_msgSend methods recorded in the symbol table and the positions of the objc_msgSend methods recorded in the symbol table.

[0114] Alternatively, the terminal can also use a pre-written crawler script to query all the objc_msgSend methods in the symbol table by capturing the method name "objc_msgSend" corresponding to the objc_msgSend method in the symbol table, as well as the positions of the objc_msgSend methods recorded in the symbol table.

[0115] In this way, while improving the efficiency of querying the objc_msgSend methods in the symbol table, it can also effectively save the cost of manual query.

[0116] Refer to Figure 2 , in the embodiment of the present application, a device 10 for obtaining the call chain of a third-party library is further provided, including:

[0117] An obtaining module 11, configured to obtain a symbol table provided by the system architecture corresponding to a target application, where the symbol table is used to record the call methods in the third-party libraries accessed by the target application as objc_msgSend methods;

[0118] A processing module 12, configured to query all the objc_msgSend methods in the symbol table and use a hook function to suspend the queried objc_msgSend methods, so as to direct the call requests of the objc_msgSend methods in the symbol table to the hook function;

[0119] An execution module 13, configured to execute the call request task corresponding to the symbol table to call the hook function, where when the hook function is called, the objc_msgSend method suspended by the hook function is executed, and the call chain of the call method corresponding to the objc_msgSend method is obtained;

[0120] An output module 14, configured to output all the call chains obtained by the hook functions.

[0121] Refer to Figure 3 , in the embodiment of the present application, a computer device is further provided. The computer device can be a server, and its internal structure can be as Figure 3As shown in the figure. The computer device includes a processor, a memory, a network interface, and a database connected through a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used for the program to obtain the call chain of the third-party library. The network interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, it realizes a method for obtaining the call chain of a third-party library.

[0122] Those skilled in the art can understand that Figure 3 the structure shown in the figure is only a block diagram of a part of the structure related to the solution of this application, and does not constitute a limitation on the computer device to which the solution of this application is applied.

[0123] In addition, this application also proposes a computer-readable storage medium. The computer-readable storage medium includes a program for obtaining the call chain of a third-party library. When the program for obtaining the call chain of the third-party library is executed by the processor, it realizes the steps of the method for obtaining the call chain of the third-party library as described in the above embodiments. It can be understood that the computer-readable storage medium in this embodiment can be a volatile readable storage medium or a non-volatile readable storage medium.

[0124] In summary, for the method for obtaining the call chain of a third-party library, the device for obtaining the call chain of a third-party library, the computer device, and the storage medium provided in the embodiments of this application, by relocating the call of the objc_msgSend method to a corresponding hook function, it is possible to quickly obtain the call chain corresponding to the third-party library call method mapped by the objc_msgSend method by using the hook function, and it can be applied to the third-party library built based on the static library, thereby improving the efficiency of obtaining the call chain corresponding to the call method in the static library accessed by the target application.

[0125] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, storage, database, or other medium provided in this application and used in the embodiments can include non-volatile and / or volatile memories. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in many forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (SSRSDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), Rambus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and Rambus dynamic RAM (RDRAM), etc.

[0126] It should be noted that in this document, the terms "include", "comprise", or any other variant thereof are intended to cover non-exclusive inclusion, such that a process, apparatus, article, or method that includes a series of elements includes not only those elements but also other elements not expressly listed, or elements that are inherent to such process, apparatus, article, or method. Without further limitation, an element defined by the phrase "including one..." does not exclude the existence of additional identical elements in the process, apparatus, article, or method that includes such element.

[0127] The above are only the preferred embodiments of this application, and do not limit the patent scope of this application accordingly. Any equivalent structural or equivalent process transformation made by using the specification and drawings of this application, or directly or indirectly applied in other related technical fields, shall be equally included in the patent protection scope of this application.

Claims

1. A method for obtaining a call chain of a third-party library, characterized in that including: obtaining a symbol table provided by a system architecture corresponding to a target application, where the symbol table is used to record call methods in a third-party library accessed by the target application as objc_msgSend methods; querying all objc_msgSend methods in the symbol table, and suspending the queried objc_msgSend methods by using a hook function, so as to direct a call request of the objc_msgSend method in the symbol table to the hook function; executing a call request task corresponding to the symbol table to call the hook function, where when the hook function is called, the objc_msgSend method suspended by the hook function is executed, and a call chain of the call method corresponding to the objc_msgSend method is obtained; outputting all the call chains obtained by the hook functions.

2. The method for obtaining the call chain of the third-party library according to claim 1, wherein, After the step of outputting all the call chains obtained by the hook functions, it further includes: detecting whether the call chain involves a call to a key interface of the target application; when it is detected that the call chain involves a call to the key interface, generating an alarm message according to the call chain and the key interface, and / or disabling the call method corresponding to the call chain.

3. The method for obtaining the call chain of the third-party library according to claim 2, wherein The step of generating an alarm message according to the call chain and the key interface, and / or disabling the call method corresponding to the call chain includes: detecting whether the third-party library corresponding to the call chain has the call permission for the key interface; if not, generating an alarm message according to the call chain and the key interface, and / or disabling the call method corresponding to the call chain.

4. The method for obtaining the call chain of the third-party library according to claim 3, wherein, After the step of generating an alarm message according to the call chain and the key interface, it further includes: outputting the alarm message to an associated device, where the alarm message includes a acquisition request corresponding to the call permission; when receiving a confirmation response sent by the associated device based on the alarm message, granting the call permission to the third-party library corresponding to the call chain; when receiving a negative response sent by the associated device based on the alarm message, disabling the call method corresponding to the call chain.

5. The method for obtaining the call chain of a third-party library according to any one of claims 2-4, wherein After the step of disabling the call method corresponding to the call chain, it further includes: detecting whether there are any undisabled call methods in the third-party library; if not, deleting the third-party library.

6. The method for obtaining the call chain of a third-party library according to claim 1, wherein, After the step of executing the call request task corresponding to the symbol table to call the hook function, it further includes: generating a call link list according to all the call chains obtained by the hook functions; sending the call link list to a storage server for storage in a block-chain ledger.

7. The method for obtaining the call chain of the third-party library according to claim 1, wherein The step of querying all objc_msgSend methods in the symbol table includes: querying all objc_msgSend methods in the symbol table by using a MachOView tool; or, querying all objc_msgSend methods in the symbol table by using a crawler script.

8. A calling chain acquisition device for a third-party library, characterized in that including: An acquisition module, configured to acquire a symbol table provided by a system architecture corresponding to a target application, where the symbol table is used to record a calling method in a third-party library accessed by the target application as an objc_msgSend method; A processing module, configured to query all objc_msgSend methods in the symbol table and suspend the queried objc_msgSend methods by using a hook function, so as to direct a call request of the objc_msgSend method in the symbol table to the hook function; An execution module, configured to execute a call request task corresponding to the symbol table to call the hook function, where when the hook function is called, the objc_msgSend method suspended by the hook function is executed, and a call chain of the calling method corresponding to the objc_msgSend method is obtained; An output module, configured to output all the call chains obtained by the hook functions.

9. A computer device, characterized in that, The computer device includes a memory, a processor, and a call chain acquisition program of a third-party library stored on the memory and executable on the processor. When the call chain acquisition program of the third-party library is executed by the processor, the steps of the call chain acquisition method of the third-party library according to any one of claims 1 to 7 are implemented.

10. A computer-readable storage medium, characterized in that, A computer-readable storage medium stores a call chain acquisition program of a third-party library. When the call chain acquisition program of the third-party library is executed by a processor, the steps of the call chain acquisition method of the third-party library according to any one of claims 1 to 7 are implemented.

Citation Information

Patent Citations

  • Asynchronous message monitoring method and device

    CN108399120A

  • Test point acquisition method and device in program test, storage medium and equipment

    CN111290950A