Method and apparatus for automatically bypassing the anti-debugging mechanism of a target program

By traversing the module and registering new signal processing functions, the problem of interference from the target program anti-debugging mechanism is solved, and the difficulty of restoring the calling process and analyzing is reduced.

CN113946803BActive Publication Date: 2025-06-13XIAMEN ANSCEN NETWORK TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111255594.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-10-27
Publication Date
2025-06-13
Estimated Expiration
2041-10-27

AI Technical Summary

Technical Problem

It is difficult for the existing technology to effectively eliminate the interference of the anti-debug mechanism in the target program, reduce the difficulty of analysis, and restore the real call process relationship.

Method used

By traversing all modules loaded in the computer system, determining whether the module belongs to the target program, registering a new general signal processing function to replace the original signal processing function, saving the context and dynamically/statically modifying the code to restore the call flow.

Benefits of technology

Effectively bypass the anti-debug mechanism of the target program, eliminate interference, reduce analysis difficulty, and realize the restoration of the real call process relationship.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113946803B_ABST
    Figure CN113946803B_ABST
Patent Text Reader

Abstract

The embodiments of the present application disclose a method and device for automatically bypassing the anti-debugging mechanism of a target program. The method includes: traversing all modules loaded in the system, determining whether a module belongs to the target program, and if it is determined to belong, recording the module information of the module belonging to the target program; calling a signal processing function, traversing all signal values of the system to obtain the registered functions related to signal processing, determining whether the signal processing function signal belongs to the target program module, and if it is determined to belong, registering a new general signal processing function to replace the original signal processing function signal and saving the original signal processing function; after the target program receives a signal, starting the new general signal processing function, saving the context value, and calling the corresponding original signal processing function signal according to the signal value; after the original signal processing function signal returns, determining whether the key register values in the context value are the same, and if they are determined to be different, dynamically modifying and / or statically modifying the code.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the technical field of computer software reverse analysis, and specifically relates to a method and device for automatically bypassing the anti-debugging mechanism of a target program. Background Art

[0002] Debugging is one of the most commonly used techniques in software reverse analysis and reverse engineering, especially playing a very important role in security fields such as virus analysis and vulnerability analysis. However, some software authors, especially malware authors, usually apply some technical means to prevent others from analyzing their software. Among these technical means, anti-debugging can be said to be the most widely used technique. Currently, the popular anti-debugging techniques can be mainly divided into two categories. One category is based on debugger detection techniques, and the other category is based on debugger interference techniques.

[0003] During the process of program analysis, it is necessary to perform reverse analysis and dynamic debugging on programs (Linux, Android ELF files) without source code, but these programs will use anti-analysis and anti-debugging mechanisms to interfere. During the running process of the target program, some signal handling functions are actively registered, and then at certain times (such as key code flows), certain signals (such as SIGILL) are actively triggered, and then the register values (such as PC) are modified in the handling function to achieve the purpose of dynamically modifying the program flow execution, thereby interfering with the purposes of static analysis and dynamic debugging.

[0004] In order to increase the analysis difficulty, ELF files usually dynamically modify the execution path to interfere with dynamic and static analysis and increase the analysis difficulty. Among them, using the Linux signal mechanism as an anti-debugging method is a common means.

[0005] Therefore, it can be seen that how to eliminate interference, reduce the analysis difficulty, and restore the true call flow relationship is an urgent problem to be solved in this field. Summary of the Invention

[0006] Embodiments of this application propose a method and device for automatically bypassing the anti-debugging mechanism of a target program to solve the technical problems mentioned in the above background art section.

[0007] In a first aspect, embodiments of this application provide a method for automatically bypassing the anti-debugging mechanism of a target program, and the method includes the following steps:

[0008] S1. Traverse all modules loaded in the current computer system, determine whether the module belongs to the target program, and in response to determining that the template belongs to the target program, record the module information of the module belonging to the target program, where the module information includes the base address and size of the executable code loaded in the module;

[0009] S2. By calling the signal processing function, traverse all signal values of the computer system to obtain the registered functions related to signal processing, and determine whether the signal processing function signal in the functions related to signal processing belongs to the module of the target program. In response to determining that the signal processing function signal belongs, register a new general signal processing function to replace the original signal processing function signal, and save the original signal processing function at the same time;

[0010] S3. After the target program receives a signal, start the new general signal processing function. First, save the context value, and then call the corresponding original signal processing function signal according to the signal value;

[0011] S4. After the original signal processing function signal returns, determine whether the key register values in the context value are the same. In response to determining that the key register values are different, perform dynamic modification and / or static modification of the code. In response to determining that the key register values are the same, do nothing.

[0012] In steps S1 - S4, use the module base address and the signal processing function address to locate the signal processing function customized by the program, and register a new general signal processing function to change the program flow, so as to restore the true call flow relationship.

[0013] In some embodiments, steps S1 - S4 are all executed in the dynamic link library file, and the method further includes:

[0014] Create a dynamic link library file, inject the dynamic link library file into the target program running in the computer system. After the dynamic link library file is loaded, perform the operations of S1 - S4 in the constructor of the dynamic link library file.

[0015] The purpose of performing the above operations in the constructor is that after the dynamic link library file is loaded, it can automatically execute the code with the above functions.

[0016] In some embodiments, for traversing all modules loaded in the current computer system in step S1 and determining whether the module belongs to the target program, it specifically further includes:

[0017] Traverse all modules loaded in the current computer system through the / proc / self / maps file;

[0018] Determine whether the module belongs to the target program by comparing the path where the module is located;

[0019] If the module belongs to the target program, record the module information of the module belonging to the target program, where the module information includes the base address and size of the executable code loaded in the module, and record it into the map with the path as the key and the base address and size as the value; if the module does not belong to the target program, no processing is performed.

[0020] By this method, first filter out the modules belonging to the target program and record the module information, while the modules that do not belong to the target program are not processed, which can effectively improve the processing speed.

[0021] In some embodiments, determining whether the signal handling function signal in the judgment processing signal-related function in step S2 belongs to the module belonging to the target program specifically further includes:

[0022] Determine whether the address of the signal handling function signal is within the range of the base address of the module or the base address of the module plus the size;

[0023] In response to determining that it is within the range of the base address of the module or the base address of the module plus the size, determine that the signal handling function signal belongs to the module of the target program.

[0024] By this method, it is convenient and fast to determine and identify that the signal handling function belongs to the module of the target program for the next operation, while if the signal handling function belongs to the default of the computer system or registered by other non-target program's own modules, no processing is performed.

[0025] In some embodiments, in response to determining that the signal handling function signal in the judgment processing signal-related function in step S2 belongs to the module belonging to the target program, register a new general signal handling function to replace the original signal handling function signal, and at the same time save the original signal handling function to the map, where the key of the map is the signal number and the value of the map is the signal handling function of the original signal.

[0026] In some embodiments, in response to determining that the key register values are different in step S4, perform dynamic modification and / or static modification of the code, specifically further including:

[0027] Calculate the real jump address according to the key register values in the context values before and after the modification;

[0028] Dynamically modify the code pointed to by the register to change the indirect jump to a direct jump;

[0029] Record and save the data of the register to the database for use by the static analysis tool to eliminate the interference code of the static analysis.

[0030] This operation can simplify the process and achieve dynamic or static code modification.

[0031] In a second aspect, an embodiment of the present application provides a device for automatically bypassing an anti-debugging mechanism for a target program. The device includes:

[0032] A determination module, configured to traverse all modules loaded in the current computer system, determine whether a module belongs to the target program, and in response to determining that the template belongs to the target program, record the module information of the module belonging to the target program, where the module information includes the base address and size of the executable code loaded in the module;

[0033] A replacement module, configured to traverse all signal values of the computer system by calling a signal processing function to obtain the registered functions related to signal processing, determine whether the signal processing function signal in the functions related to signal processing belongs to the module belonging to the target program, and in response to determining that the signal processing function signal belongs, register a new general signal processing function to replace the original signal processing function signal, and save the original signal processing function at the same time;

[0034] A start module, configured to start a new general signal processing function after the target program receives a signal, first save the context value, and then call the corresponding original signal processing function signal according to the signal value;

[0035] A modification module, configured to determine whether the key register values in the context value are the same after the original signal processing function signal returns. In response to determining that the key register values are different, perform dynamic and / or static code modification. In response to determining that the key register values are the same, do nothing.

[0036] In some embodiments, the device further includes:

[0037] A creation module, configured to create a dynamic link library file and inject the dynamic link library file into the target program running in the computer system. The above determination module, replacement module, start module, and modification module are all stored in the dynamic link library file.

[0038] In a third aspect, an embodiment of the present application provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the method described in any one of the above is implemented.

[0039] The method and device provided by the embodiments of the present application for automatically bypassing the anti-debugging mechanism for the target program use the module base address and the address of the signal processing function to locate the original signal processing function signal customized by the program, and use signal processing to change the program flow, which can effectively eliminate interference, reduce the analysis difficulty, and restore the true call flow relationship. Description of the Drawings

[0040] By reading the detailed description of the non-restrictive embodiments with reference to the following drawings, other features, objectives, and advantages of the present application will become more apparent:

[0041] Figure 1 is a flowchart of an embodiment of the method for automatically bypassing the anti-debugging mechanism for the target program according to the present application;

[0042] Figure 2 is a schematic flowchart of another specific embodiment of the method for automatically bypassing the anti-debugging mechanism for the target program according to the present application;

[0043] Figure 3 is a schematic structural diagram of an embodiment of the device for automatically bypassing the anti-debugging mechanism for the target program according to the present application;

[0044] Figure 4 is a schematic structural diagram of a computer system of a terminal device or a server suitable for implementing the embodiments of the present application. Detailed Embodiments

[0045] The present application will be further described in detail below with reference to the drawings and embodiments. It can be understood that the specific embodiments described herein are only used to explain the related invention, rather than limiting the invention. Additionally, it should be noted that for the convenience of description, only the parts related to the invention are shown in the drawings.

[0046] It should be noted that, without conflict, the embodiments in the present application and the features in the embodiments can be combined with each other. The present application will be described in detail below with reference to the drawings and embodiments.

[0047] Figure 1 FIG. 100 shows a flowchart of an embodiment of the method for automatically bypassing the anti-debugging mechanism for the target program according to the present application, Figure 2 is a schematic flowchart of another specific embodiment, with reference to Figure 1 and Figure 2 , the method for automatic bypassing includes the following steps:

[0048] Step 101: Create a dynamic link library file and inject the dynamic link library file into the target program that is running on the computer system. After the dynamic link library file is loaded, perform the operations in steps 102 - 105 in the constructor of the dynamic link library file.

[0049] In this embodiment, the injection method of injecting the dynamic link library file into the target program that is running on the computer system can adopt LD_PRELOAD or other injection methods. All functions are completed in this dynamic link library file, and the purpose of placing the subsequent operations in the constructor is that after the dynamic link library file is loaded, the function codes in steps 102 - 105 can be automatically executed.

[0050] Step 102: Traverse all the modules loaded in the current computer system, determine whether the module belongs to the target program, and in response to determining that the template belongs to the target program, record the module information of the module belonging to the target program, where the module information includes the base address and size of the executable code loaded in the module. Here, the computer system is a Linux system.

[0051] In this embodiment, traversing all the modules loaded in the current computer system and determining whether the module belongs to the target program specifically further includes:

[0052] After the dynamic link library file is loaded, first traverse all the modules loaded in the current computer system through the / proc / self / maps file;

[0053] Determine whether the module belongs to the target program by comparing the path where the module is located;

[0054] If the module belongs to the target program, record the module information of the module belonging to the target program, where the module information includes the base address and size of the executable code loaded in the module, and record it in the map with the path as the key and the base address and size as the value; if the module does not belong to the target program, no processing is performed.

[0055] By making a preliminary judgment in this way, filtering out the modules that belong to the target program itself and recording the module information, while not processing the modules that do not belong to the target program, can effectively improve the processing speed.

[0056] Step 103: By calling the signal handling function, traverse all signal values of the computer system to obtain the registered signal handling related function (struct sigaction), and determine whether the signal handling function signal in the signal handling related function belongs to the module of the target program. In response to determining that the signal handling function signal belongs to it, register a new general signal handling function to replace the original signal handling function signal, and save the original signal handling function at the same time.

[0057] Among them, the signal handling related function (struct sigaction) includes signal, sigprocmask, sigpending, sigsuspend, and sigemptyset, and the computer system is a Linux system.

[0058] In this embodiment, determining whether the signal handling function signal in the signal handling related function belongs to the module of the target program specifically further includes:

[0059] Determine whether the address of the signal handling function signal is within the range of the base address of the module or the base address of the module plus the size;

[0060] In response to determining that it is within the range of the base address of the module or the base address of the module plus the size, determine that the signal handling function signal belongs to the module of the target program.

[0061] In this way, it is convenient and fast to determine and identify that the signal handling function belongs to the module of the target program for the next operation. If it does not belong, it means that the signal handling function is registered by the computer system default or other non-target program's own modules, so no processing is performed.

[0062] Furthermore, in this embodiment, the original signal handling function can be saved to the map. Among them, the key of the map is the signal number, and the value (value) of the map is the signal handling function of the original signal.

[0063] After completing the above steps, when the target program receives a signal, it no longer enters the signal handling function set by the program, but enters the new general signal handling function set by the dynamic link library file.

[0064] Step 104: After the target program receives a signal, start the new general signal handling function. First, save the context value, and then obtain the corresponding original signal handling function signal from the map according to the signal value for calling.

[0065] Step 105, after the original signal processing function signal returns, determine whether the key register values in the context value are the same. In response to determining that the key register values are different, perform dynamic modification and / or static modification of the code. In response to determining that the key register values are the same, do not perform any processing.

[0066] In this embodiment, by comparing whether the key register values (such as PC) in the context value are the same, if they are the same, it means that the code flow has not changed; if they are different, it means that the code flow has changed in this signal processing function.

[0067] Furthermore, in this embodiment, in response to determining that the key register values are different, perform dynamic modification and / or static modification of the code, which specifically further includes:

[0068] According to the key register values in the context value before and after modification, such as the PC register value, calculate the actual jump address;

[0069] Wherein, the actual jump address = PC register value - module base address, and the module base address can be obtained through / proc / self / maps in the system or through an interface provided by the system (such as dl_iterate_phdr).

[0070] Then, perform dynamic modification of the code pointed to by the PC register to change the indirect jump to a direct jump, which can simplify the process;

[0071] Alternatively, record and save the data of the PC register in the database for use by the static analysis tool during static analysis. The static analysis tool can eliminate the interfering code in the static analysis based on the relevant information.

[0072] The method provided in this application locates the original signal processing function signal customized by the program using the module base address and the signal processing function address, uses signal processing to change the program flow, can effectively eliminate interference, reduce the analysis difficulty, and restore the true call flow relationship.

[0073] For further reference Figure 3 As an implementation of the method shown above, this application provides an embodiment of a device for automatically bypassing the anti-debugging mechanism of a target program. This device embodiment corresponds to the method embodiment shown in Figure 1 and this device can be specifically applied to various electronic devices. Figure 1 As shown in

[0074] As Figure 3 shown, the device 200 for automatically bypassing the anti-debugging mechanism of a target program in this embodiment includes:

[0075] A creation module 201 is used to create a dynamic link library file and inject the dynamic link library file into a target program running on a computer system. The determination module 202, replacement module 203, startup module 204, and modification module 205 mentioned below are all stored in the dynamic link library file.

[0076] A determination module 202 is used to traverse all modules loaded in the current computer system, determine whether a module belongs to the target program, and in response to determining that the template belongs to the target program, record the module information of the module belonging to the target program, where the module information includes the base address and size of the executable code loaded in the module.

[0077] A replacement module 203 is used to call a signal processing function to traverse all signal values of the computer system to obtain registered functions related to signal handling, determine whether the signal handling function signal in the functions related to signal handling belongs to the module belonging to the target program, and in response to determining that the signal handling function signal belongs, register a new general signal handling function to replace the original signal handling function signal, and save the original signal handling function at the same time.

[0078] A startup module 204 is used to start a new general signal handling function after the target program receives a signal, first save the context value, and then call the corresponding original signal handling function signal according to the signal value.

[0079] A modification module 205 is used to determine whether the key register values in the context value are the same after the original signal handling function signal returns. In response to determining that the key register values are different, perform dynamic modification and / or static modification of the code. In response to determining that the key register values are the same, do nothing.

[0080] The following refers to Figure 4 which shows a schematic structural diagram of a computer system 300 of a terminal device or a server suitable for implementing the embodiments of the present application. Figure 4 The terminal device or server shown is only an example and should not impose any limitation on the functions and usage scope of the embodiments of the present application.

[0081] As Figure 4As shown, computer system 300 includes a central processing unit (CPU) 301, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 302 or a program loaded from a storage section 308 into a random access memory (RAM) 303. In the RAM 303, various programs and data required for the operation of the system 300 are also stored. The CPU 301, ROM 302, and RAM 303 are connected to each other via a bus 304. An input / output (I / O) interface 305 is also connected to the bus 304.

[0082] The following components are connected to the I / O interface 305: an input section 306 including a keyboard, a mouse, etc.; an output section 307 including a liquid crystal display (LCD), etc. and a speaker, etc.; a storage section 308 including a hard disk, etc.; and a communication section 309 including a network interface card such as a LAN card, a modem, etc. The communication section 309 performs communication processing via a network such as the Internet. A drive 310 is also connected to the I / O interface 305 as required. A removable medium 311, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is installed on the drive 310 as required so that a computer program read from it can be installed into the storage section 308 as required.

[0083] In particular, according to embodiments of the present disclosure, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments of the present disclosure include a computer program product that includes a computer program carried on a computer-readable medium, and the computer program includes program code for performing the methods shown in the flowcharts. In such an embodiment, the computer program can be downloaded and installed from a network through the communication section 309, and / or installed from the removable medium 311. When the computer program is executed by the central processing unit (CPU) 301, the above-mentioned functions defined in the methods of the present application are performed. It should be noted that the computer-readable medium described in the present application can be a computer-readable signal medium or a computer-readable medium or any combination of the two. The computer-readable medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples of the computer-readable medium can include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present application, the computer-readable medium can be any tangible medium that contains or stores a program, and the program can be used by or in combination with an instruction execution system, apparatus, or device. In the present application, the computer-readable signal medium can include a data signal propagated in a baseband or as part of a carrier wave, in which the computer-readable program code is carried. Such a propagated data signal can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. The computer-readable signal medium can also be any computer-readable medium other than the computer-readable medium, and the computer-readable medium can send, propagate, or transmit a program for use by or in combination with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted by any suitable medium, including but not limited to: wireless, wire, optical cable, RF, etc., or any suitable combination of the above.

[0084] Computer program code for performing the operations of this application can be written in one or more programming languages or combinations thereof. The programming languages include object-oriented programming languages such as Java, Smalltalk, C++, and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, executed as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer can be connected to the user's computer through any kind of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computer (for example, by connecting through the Internet using an Internet service provider).

[0085] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of this application. In this regard, each block in the flowchart or block diagram can represent a module, a program segment, or a part of code that contains one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks can occur in a different order than marked in the accompanying drawings. For example, two consecutive blocks shown can actually be executed substantially in parallel, and they can sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, and combinations of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system for performing the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.

[0086] The modules described in the embodiments of this application can be implemented in software or in hardware. The described modules can also be provided in a processor. For example, it can be described as: a processor includes an acquisition module, an analysis module, and an output module. Among them, the names of these modules do not constitute a limitation on the module itself in some cases.

[0087] The above description is only a preferred embodiment of this application and an explanation of the applied technical principles. Those skilled in the art should understand that the scope of the invention involved in this application is not limited to the technical solutions formed by the specific combination of the above technical features, and should also cover other technical solutions formed by any combination of the above technical features or their equivalent features without departing from the above inventive concept. For example, technical solutions formed by mutually replacing the above features with (but not limited to) technical features having similar functions disclosed in this application.

Claims

1. A method for automatically bypassing the anti - debugging mechanism of a target program, characterized in that, the method comprises the following steps: S1. Traverse all modules loaded in the current computer system, determine whether the module belongs to the target program, and in response to determining that the template belongs to the target program, record the module information of the module belonging to the target program, where the module information includes the base address and size of the executable code loaded in the module; S2. By calling the signal - handling function, traverse all signal values of the computer system to obtain the registered functions related to handling signals, determine whether the signal - handling function signal in the functions related to handling signals belongs to the module of the target program, and in response to determining that the signal - handling function signal belongs, register a new general signal - handling function to replace the original signal - handling function signal, and at the same time save the original signal - handling function; S3. After the target program receives a signal, start the new general signal - handling function, first save the context value, and then call the corresponding original signal - handling function signal according to the signal value; S4. After the original signal - handling function signal returns, determine whether the critical register values in the context value are the same. In response to determining that the critical register values are not the same, perform dynamic modification and / or static modification of the code. In response to determining that the critical register values are the same, do nothing.

2. The method for automatically bypassing the anti - debugging mechanism of a target program according to claim 1, characterized in that, the steps S1 - S4 are all executed in a dynamic - link library file, and the method further comprises: Create a dynamic - link library file, and inject the dynamic - link library file into the target program that is running in the computer system. After the dynamic - link library file is loaded, perform the operations of steps S1 - S4 in the constructor of the dynamic - link library file.

3. The method for automatically bypassing the anti - debugging mechanism of a target program according to claim 1, characterized in that, the traversing all modules loaded in the current computer system in step S1 and determining whether the module belongs to the target program specifically further comprises: Traverse all modules loaded in the current computer system through the / proc / self / maps file; Determine whether the module belongs to the target program by comparing the path of the module; If the module belongs to the target program, record the module information of the module belonging to the target program, where the module information includes the base address and size of the executable code loaded in the module, and record it into the map with the path as the key and the base address and size as the value; if the module does not belong to the target program, do nothing.

4. The method for automatically bypassing the anti - debugging mechanism of a target program according to claim 1, characterized in that, the determining whether the signal - handling function signal in the functions related to handling signals belongs to the module of the target program in step S2 specifically further comprises: Determine whether the address of the signal processing function signal is within the range of the base address of the module or the base address of the module plus the size; In response to determining that it is within the range of the base address of the module or within the range of the base address of the module plus a fixed size, determine that the signal processing function signal belongs to the module of the target program.

5. The method for automatically bypassing the anti-debugging mechanism for the target program according to claim 1, characterized in that, In the step S2, it is judged whether the signal processing function signal in the signal processing related function belongs to the module of the target program. In response to determining that the signal processing function signal belongs, a new general signal processing function is registered to replace the original signal processing function signal, and at the same time, the original signal processing function is saved to the map, where the key of the map is the signal number and the value of the map is the signal processing function of the original signal.

6. The method for automatically bypassing the anti-debugging mechanism for the target program according to claim 1, characterized in that, In the step S4, in response to determining that the key register values are different, dynamic modification and / or static modification of the code is performed. Specifically, it further includes: Calculate the true jump address according to the key register values in the context values before and after modification; Dynamically modify the code pointed to by the register to change the indirect jump to a direct jump; Record and save the data of the register to the database for use by the static analysis tool to eliminate the interference code of the static analysis.

7. An apparatus for automatically bypassing the anti-debugging mechanism for the target program, characterized in that, The apparatus includes: A determination module, configured to traverse all modules loaded in the current computer system, determine whether the module belongs to the target program, and in response to determining that the template belongs to the target program, record the module information of the module belonging to the target program, where the module information includes the base address and size of the executable code loaded in the module; A replacement module, configured to call the signal processing function, traverse all signal values of the computer system to obtain the registered signal processing related functions, determine whether the signal processing function signal in the signal processing related functions belongs to the module of the target program, and in response to determining that the signal processing function signal belongs, register a new general signal processing function to replace the original signal processing function signal, and at the same time save the original signal processing function; A start module, configured to start the new general signal processing function after the target program receives a signal, first save the context value, and then call the corresponding original signal processing function signal according to the signal value; A modification module, configured to, after the original signal processing function signal returns, determine whether the key register values in the context value are the same. In response to determining that the key register values are different, perform dynamic modification and / or static modification of the code. In response to determining that the key register values are the same, no processing is performed.

8. The device for automatically bypassing the anti-debugging mechanism for the target program according to claim 7, characterized in that, the device further comprises: a creation module, configured to create a dynamic link library file and inject the dynamic link library file into the target program being run by the computer system, wherein the determination module, the replacement module, the start module, and the modification module are all stored in the dynamic link library file.

9. A computer-readable storage medium, on which a computer program is stored, and the computer program, when executed by a processor, implements the method according to any one of claims 1-6.

Citation Information

Patent Citations

  • Program compiling method, device and system

    CN110147238A

  • IOS-bypassing system debugging detection method and device

    CN110287123A