A method, device, medium and equipment for improving the security of machine code

By using basic classes and template classes in the writing of shellcode, combined with asynchronous operation interfaces and mesh protection of security instances, the problems of insufficient security performance and low writing efficiency in the existing technology are solved, and high security and efficient writing are achieved.

CN114153448BActive Publication Date: 2025-07-01JIANGXI YINFURONG DIGITAL TECHNOLOGY CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202010933443.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-09-08
Publication Date
2025-07-01
Estimated Expiration
2040-09-08

AI Technical Summary

Technical Problem

In the prior art, when running shellcode, the security performance of shellcode is difficult to ensure, and writing a security policy requires writing a large amount of code, resulting in low writing efficiency.

Method used

By creating basic classes and template classes, defining common class parameters and asynchronous operation interfaces, adding subclasses to the template classes according to preset security policies, implementing mesh protection for each security instance, and improving the security of shellcode.

Benefits of technology

It realizes high security for shellcode operation, and through the combination of multiple security instances, it improves writing efficiency and reduces the need for writing auxiliary code.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114153448B_ABST
    Figure CN114153448B_ABST
Patent Text Reader

Abstract

The present invention provides a method, device, medium and equipment for improving the security of machine code, including: creating a base class; creating a template class based on the base class; adding at least one subclass in the template class and determining the inheritance class of at least one subclass; each subclass corresponds to a security instance, and the security instance includes: an instance of secure memory for executing machine code, an instance for preventing the machine code from being hooked, an instance for detecting the integrity of the machine code, and an instance for preventing the machine code from being single-stepped; setting a pointer to the next subclass of the current subclass in the current subclass based on a preset execution order of the security instances; executing the security instances in the corresponding subclasses based on each pointer; since the base class is equivalent to a general framework and the template class is created based on the base class, subclasses corresponding to each security instance can be added to the template class, so that the machine code is protected by a variety of security instances, improving the security of the machine code operation.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of software development, and particularly relates to a method, device, medium and equipment for improving the security of machine code. Background Art

[0002] Machine code shellcode plays an important role in software development. For example, when the client needs to update patches, perform hot updates and vulnerability repairs, the server will send the corresponding shellcode to the client.

[0003] Since shellcode itself is written in assembly code, in order to prevent unauthorized users from easily cracking the shellcode, security performance must be considered when writing shellcode. In the prior art, the shellcode is generally encrypted and then decrypted when the shellcode is executed to achieve the protection of the shellcode. However, once the password is cracked by an unauthorized user in this way, it is easy to cause the shellcode to be tampered with, and the security performance is relatively low.

[0004] Moreover, in the prior art, if you want to add new security policies to the shellcode, a large amount of code needs to be written, resulting in a relatively low writing efficiency of the entire shellcode. Summary of the Invention

[0005] In view of the problems existing in the prior art, the embodiments of the present invention provide a method, device, medium and equipment for improving the security of machine code, which are used to solve the technical problem that the security performance of shellcode cannot be ensured when the shellcode is running in the prior art.

[0006] In the first aspect of the present invention, a method for improving the security of machine code is provided, and the method includes:

[0007] Create a base class; the base class is used to define general class parameters, and the general class parameters include: an asynchronous operation interface, an input template parameter, and an output template parameter;

[0008] Create a template class based on the general class parameters in the base class, and the template class is a general template class that can add any subclass;

[0009] Add at least one subclass to the template class according to a preset security policy, and determine the inheritance class of the at least one subclass; each of the subclasses corresponds to a security instance, and the security instance includes: an instance of secure memory for executing the machine code shellcode, an instance for preventing the shellcode from being hooked, an instance for detecting the integrity of the shellcode, and an instance for preventing the shellcode from being single-stepped.

[0010] For any current subclass, set a pointer to the next subclass of the current subclass in the current subclass based on a preset execution order of security instances.

[0011] Execute the security instances in the corresponding subclasses based on the respective pointers.

[0012] Optionally, the determining the inheritance class of the at least one subclass includes:

[0013] Obtain the execution order of the security instances set in the security policy;

[0014] For any current subclass, if the execution order of the security instance corresponding to the current subclass is to be executed first, then determine the inheritance class of the current subclass as the base class;

[0015] If the execution order of the security instance corresponding to the current subclass is not to be executed first, then determine the inheritance class of the current subclass as the template class.

[0016] Optionally, when the security instance is an instance of secure memory for executing the machine code shellcode, the adding at least one subclass to the template class according to a preset security policy includes:

[0017] Create a structure for obtaining the memory address and memory length of the security instance;

[0018] Create a first subclass corresponding to the security instance;

[0019] Create an asynchronous operation object, a Promise object, in the first subclass, and the asynchronous operation object is used to execute an asynchronous operation;

[0020] Based on the memory address and memory length of the security instance, use the memory allocation function BYTE* pMem = MyVirtualAlloc(NULL, nSize, MEM_COMMIT, PAGE_EXECUTE_READWRITE); to allocate a memory address pMem for the security instance; where MyVirtualAlloc is the allocation function, NULL is the null byte, nSize is the allocated memory length, MEM_COMMIT is the allocated memory type, and PAGE_EXECUTE_READWRITE is the attribute parameter for modifying the memory to be executable and readable / writable;

[0021] Based on the allocated memory address, use the obfuscation function Hash = md5.create(pMem) to obtain obfuscated data, and initialize the allocated memory address based on the obfuscated data;

[0022] Copy the shellcode to the initialized memory address;

[0023] Use the Promise object to return the result.

[0024] Optionally, when the security instance is an instance for preventing the shellcode from being hooked, an instance for detecting the integrity of the shellcode, or an instance for preventing the shellcode from being single-stepped, add at least one subclass in the template class according to the preset security policy, including:

[0025] Create a second subclass corresponding to the security instance using the constructor;

[0026] Pass in the execution parameters of the constructor, where the execution parameters are used to execute the execution logic of the security instance;

[0027] Associate the execution parameters with the asynchronous operation interface in the base class.

[0028] Optionally, when the security instance is an instance for preventing the shellcode from being hooked, the method further includes:

[0029] Use the execution parameters to find whether there is a jump instruction in the shellcode. If there is such a jump instruction, determine whether the jump destination address of the jump instruction is within the code space of the shellcode;

[0030] If it is determined that the jump destination address of the jump instruction exists within the code space of the shellcode, determine that the jump instruction is a normal instruction;

[0031] If it is determined that the jump destination address of the jump instruction does not belong to the code space of the shellcode, it is determined that the jump instruction is an abnormal hook instruction.

[0032] Optionally, when the security instance is an instance for preventing the shellcode from being single-stepped, the method further includes:

[0033] Scanning the shellcode using the execution parameter to determine whether there is an interrupt instruction for debugging code in the shellcode;

[0034] If it is determined that there is the interrupt instruction in the shellcode, it is determined that the shellcode is abnormal, and the abnormal information is reported.

[0035] Optionally, when the security instance is an instance for detecting the integrity of the shellcode, the method further includes:

[0036] Obtaining the entire code corresponding to the shellcode;

[0037] Performing a hash calculation on the entire code to obtain a current hash result value;

[0038] Determining whether the current hash result value is consistent with a pre-obtained reference hash result value. If not, it is determined that the shellcode is incomplete;

[0039] Reporting the detection result.

[0040] In a second aspect of the present invention, there is provided a device for improving the security of machine code, the device including:

[0041] A creation unit, configured to create a base class; the base class is used to define general class parameters, and the general class parameters include: an asynchronous operation interface, an input template parameter, and an output template parameter;

[0042] Creating a template class based on the general class parameters in the base class;

[0043] An adding unit, configured to add at least one subclass to the template class according to a preset security policy, and determine the inheritance class of the at least one subclass; each subclass corresponds to a security instance, and the security instance includes: an instance of a secure memory for executing the machine code shellcode, an instance for preventing the shellcode from being hooked, an instance for detecting the integrity of the shellcode, and an instance for preventing the shellcode from being single-stepped;

[0044] A setting unit, configured to set, for any current subclass, a pointer to the next subclass of the current subclass in the current subclass based on a preset execution order of security instances;

[0045] An execution unit, configured to execute security instances in corresponding subclasses based on the respective pointers.

[0046] In a third aspect of the present invention, there is provided a computer-readable storage medium, on which a computer program is stored, and when the program is executed by a processor, the method described in any one of the first aspects is implemented.

[0047] In a third aspect of the present invention, there is provided a computer device, including a memory, a processor, and a computer program stored on the memory and executable on the processor, and when the processor executes the program, the method described in any one of the first aspects is implemented.

[0048] The present invention provides a method, device, medium, and device for improving the security of machine code. The method includes: creating a base class; the base class is used to define general class parameters, and the general class parameters include: an asynchronous operation interface, an input template parameter, and an output template parameter; creating a template class based on the general class parameters in the base class; adding at least one subclass to the template class according to a preset security policy, and determining the inheritance class of the at least one subclass; each subclass corresponds to a security instance, and the security instance includes: an instance of secure memory for executing the machine code shellcode, an instance for preventing the shellcode from being hooked, an instance for detecting the integrity of the shellcode, and an instance for preventing the shellcode from being single-stepped; for any current subclass, setting a pointer to the next subclass of the current subclass in the current subclass based on a preset execution order of security instances; executing security instances in corresponding subclasses based on the respective pointers; thus, since there are general class parameters in the base class, the base class is equivalent to a general framework, and the template class is created based on the base class, and the template class is a general template class to which any subclass can be added, so subclasses corresponding to various security instances can be added to the template class at will, so that the shellcode is protected by multiple security instances, thereby improving the security of the shellcode during operation; at the same time, since adding subclasses corresponding to various security instances is implemented based on a general template class, when writing the code corresponding to any one security instance, only functional code needs to be added to the template class, and there is no need to write a large amount of auxiliary code, so the overall writing efficiency can be improved. Description of the Drawings

[0049] Figure 1 It is a schematic flowchart of a method for improving the security of machine code provided by an embodiment of the present invention;

[0050] Figure 2 Schematic structural diagram of a device for improving the security of machine code provided by an embodiment of the present invention;

[0051] Figure 3 Schematic structural diagram of a computer device for improving the security of machine code provided by an embodiment of the present invention;

[0052] Figure 4 Schematic structural diagram of a computer-readable storage medium for improving the security of machine code provided by an embodiment of the present invention. Detailed implementation manners

[0053] In order to solve the technical problem that the security performance of shellcode cannot be ensured when running shellcode in the prior art, the present invention provides a method, device, medium and device for improving the security of machine code.

[0054] The technical solution of the present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments.

[0055] Embodiment 1

[0056] This embodiment provides a method for improving the security of machine code shellcode, as Figure 1 shown, the method includes:

[0057] S110, create a base class; the base class is used to define general class parameters, and the general class parameters include: an asynchronous operation interface, an input template parameter, and an output template parameter;

[0058] Since there may be multiple security instances written for shellcode code, which may include multiple data types and multiple operations (such as synchronous operations or asynchronous operations), in order to efficiently write security instances, a base class is created, and the base class is used to define general class parameters, and the general class parameters include: an asynchronous operation interface, an input template parameter, and an output template parameter.

[0059] Specifically, first set two template parameters template<typename in,typename out>, where typename in is the input template parameter and typename out is the output template parameter, so as to be applicable to different data types. For example, the input template parameter can be a memory address and a memory length, and then the output can be the code after initializing and obfuscating this section of memory.

[0060] Then create a base class Protect based on the two template parameters, and the code implementation is as follows:

[0061] class Protect{

[0062] virtual ~Protect() = default;

[0063] virtual Future <out>operator(in src) = 0;

[0064] }

[0065] Here, when creating the base class, the base class is declared as virtual using the destructor to avoid memory leaks in the base class.

[0066] The base class provides an asynchronous operation interface. The input parameter in src of the asynchronous operation interface is an input template parameter, and the output parameter out of the asynchronous operation interface is an output template parameter. The output parameter out is of the same data type as the output template parameter. Operator is the execution logic corresponding to the specific security instance.

[0067] Here, by using the Future parameter in the base class, the execution logic can be carried out asynchronously. For some time-consuming operations, they can be dispatched to an asynchronous thread to complete. After the asynchronous thread finishes execution, the returned std::Future will become signaled to enable subsequent operations.

[0068] S111. Create a template class based on the generic class parameters in the base class. The template class is a general template class that can add any subclass;

[0069] Since there may be multiple security instances used to protect the shellcode, in order to enable multiple security instances to be infinitely stacked to form a mesh protection and improve the writing efficiency, after creating the base class, create a template class based on the generic class parameters in the base class. The template class is a general template class that can add any subclass.

[0070] For example, if two security instances need to be written, then set the template parameters in the general template class: template<typename inA,typename outA,typename inB,typename outB>; where inA and outA are the template parameters in the base class, equivalent to the template parameters corresponding to the first security instance; inB is the input template parameter of the second security instance, and outB is the output template parameter of the second security instance.

[0071] Then create the template class ProtectChain based on the template parameters. The code implementation is as follows:

[0072] class ProtectChain:public Protect<inA,outA>{

[0073] ~ProtectChain() = default;

[0074] private: shared_ptr<Protect<ReqB, RespB>> protect1_;

[0075] explicit ProtectChain(shared_ptr<Protect<ReqB, RespB>> protect) : protect2_(protect) {}

[0076] }

[0077] Here, in order to protect the written code, a privately accessible member variable Protect1_ is defined in the template class to prevent external access; the life cycle of this variable is managed by the smart pointer shared_ptr. When this variable is not in use, the smart pointer shared_ptr will release itself. Among them, ReqB is equivalent to inB, and RespB is equivalent to outB.

[0078] explicit ProtectChain(shared_ptr<Protect<ReqB, RespB>> protect) is a constructor. Since the constructor has only one parameter, the explicit keyword is used to declare this constructor, and the parameter of the constructor can be saved to the member variable protect2_(protect) {}; therefore, the template class ProtectChain can accept a member variable of any data type and store it.

[0079] S112. Add at least one subclass to the template class according to a preset security policy, and determine the inheritance class of the at least one subclass;

[0080] To improve the running security of the shellcode code, at least one subclass can be added to the template class according to a preset security policy here. Each of the subclasses corresponds to a security instance, and the security instance can include: an instance of secure memory for executing the shellcode, an instance for preventing the shellcode from being hooked, an instance for detecting the integrity of the shellcode, and an instance for preventing the shellcode from being single-stepped. In this way, each security instance can form a mesh protection to ensure the security of the shellcode operation.

[0081] After the addition of the subclasses is completed, determine the inheritance class of the at least one subclass.

[0082] As an optional embodiment, when the security instance is an instance of secure memory for executing the machine code shellcode, the adding at least one subclass to the template class according to the preset security policy includes:

[0083] Create a structure struct Data, which is used to obtain the memory address Uint64_t* address and memory length Uint32_t size of the security instance;

[0084] Create a first subclass MemoryProtect corresponding to the security instance. The first subclass inherits from the base class Protect; the first subclass is used to obfuscate the memory address to increase the complexity of reverse engineering.

[0085] Use the creation function to create an asynchronous operation object, a Promise object, in the first subclass. The asynchronous operation object is used to perform asynchronous operations;

[0086] Based on the memory address and memory length of the security instance, use the memory allocation function BYTE* pMem = MyVirtualAlloc(NULL, nSize, MEM_COMMIT, PAGE_EXECUTE_READWRITE); to allocate a memory address pMem for the security instance; MyVirtualAlloc is the allocation function, NULL is the null byte, nSize is the allocated memory length, MEM_COMMIT is the allocated memory type, and PAGE_EXECUTE_READWRITE is the property parameter used to modify the executable and readable / writable properties of the memory;

[0087] Based on the allocated memory address, use the obfuscation function Hash = md5.create(pMem) to obtain obfuscated data, and initialize the allocated memory address based on the obfuscated data;

[0088] Use the copy function Memcpy(pMem, in.address, in.size) to copy the shellcode code to the initialized memory address; where in.size is the length of the written code.

[0089] Use the Promise object to return the result.

[0090] Specifically, when the security instance is an instance of a secure memory for executing the machine code shellcode, the code for adding at least one subclass in the template class according to the preset security policy is as follows:

[0091] class MemoryProtect:public Protect<Data,Data>{

[0092] Future <data>operator(Data in)override{

[0093] Promise <data>p;

[0094] BYTE* pMem = MyVirtualAlloc(NULL, nSize, MEM_COMMIT, PAGE_EXECUTE_READWRITE);

[0095] Hash = md5.create(pMem); memset(pMem, Hash);

[0096] Memcpy(pMem, in.address, in.size);

[0097] p.setvalue(in);

[0098] return f;}}

[0099] As an optional embodiment, when the security instance is an instance for preventing shellcode from being hooked, an instance for detecting the integrity of shellcode, or an instance for preventing shellcode from being single-stepped, at least one subclass is added to the template class according to a preset security policy, including:

[0100] Create a second subclass corresponding to the security instance using the constructor;

[0101] Pass in the execution parameters of the constructor, and the execution parameters are used to execute the execution logic of the security instance;

[0102] Associate the execution parameters with the asynchronous operation interface in the base class.

[0103] Here, as an optional embodiment, determining the inheritance class of at least one subclass includes:

[0104] Obtain the execution order of the security instance set in the security policy;

[0105] For any current subclass, if the execution order of the security instance corresponding to the current subclass is to be executed first, then determine the inheritance class of the current subclass as the base class;

[0106] If the execution order of the security instance corresponding to the current subclass is not to be executed first, then determine the inheritance class of the current subclass as the template class.

[0107] For example, if the security instances include: an instance of secure memory for executing shellcode and an instance for preventing the shellcode from being hooked, and the instance of secure memory for executing shellcode is the first executed security instance and the instance for preventing the shellcode from being hooked is the second executed security instance, then the inheritance class of the subclass corresponding to the instance of secure memory for executing shellcode is the base class, and the inheritance class of the subclass corresponding to the instance for preventing the shellcode from being hooked is the template class.

[0108] S113. For any current subclass, set a pointer to the next subclass of the current subclass in the current subclass based on a preset execution order of security instances;

[0109] To support the mesh execution (serial execution) of each security instance and improve the security of shellcode operation, for any current subclass, set a pointer to the next subclass of the current subclass in the current subclass based on a preset execution order of security instances.

[0110] For example, if the security instances are executed in the following order: an instance of secure memory for executing shellcode, an instance for preventing the shellcode from being hooked, an instance for preventing the shellcode from being single-stepped, and an instance for detecting the integrity of the shellcode, the specific implementation is as follows:

[0111] First, use the creation function Mem = make_shared <memoryprotect>(); Create a pointer to an instance of secure memory for executing shellcode;

[0112] Then, pass the pointer to the instance that prevents the shellcode from being hooked into the subclass corresponding to the secure memory instance. The code implementation is as follows:

[0113] Unhook = make_shared <unhookprotect>(Mem);

[0114] Pass the pointer of the instance used to prevent the shellcode from being single-stepped debugged into the corresponding subclass of the instance that prevents the shellcode from being hooked. The code implementation is as follows:

[0115] Debug = make_shared <debugprotect>(Unhook)

[0116] Pass the pointer of the instance used to detect the integrity of the shellcode into the subclass corresponding to the instance used to prevent the shellcode from being single-stepped debugged. The code implementation is as follows:

[0117] Check = make_shared <integrityprotect>(Debug);

[0118] That is, when the security instance includes three instances A, B, and C and is executed in the order of A, B, and C, then the pointer of B needs to be passed into the subclass corresponding to A, and the pointer of C needs to be passed into the subclass corresponding to B.

[0119] S114, execute the security instance in the corresponding subclass based on each of the pointers.

[0120] After setting the pointer of the next subclass of the current subclass in the current subclass based on the preset execution order of the security instances, the security instance in the corresponding subclass can be executed based on each pointer.

[0121] As an optional embodiment, when the security instance is an instance for preventing shellcode from being hooked, the method further includes:

[0122] Use the execution parameter to find whether there is a jump instruction in the shellcode. If there is a jump instruction, determine whether the jump destination address of the jump instruction is within the code space of the shellcode;

[0123] If it is determined that the jump destination address of the jump instruction exists in the code space of the shellcode, determine that the jump instruction is a normal instruction;

[0124] If it is determined that the jump destination address of the jump instruction does not belong to the code space of the shellcode, determine that the jump instruction is an abnormal hook instruction.

[0125] Specifically, when the security instance is an instance for preventing shellcode from being hooked, adding at least one subclass to the template class and implementing the code for executing the logic of this subclass is as follows:

[0126] class UnhookProtect:public ProtectChain<Data,Data,Data,Data>{

[0127] explicit UnhookProtect(std::shared_ptr<Protect<Data,Data>>protect): the execution parameter Protect passed into the constructor;

[0128] ProtectChain<Data,Data,Data,Data>(protect){}

[0129] Future <data>operator(Data in) { The Protect parameter is associated with the asynchronous operation interface;

[0130] return protect_.operateor(in).thenValue([](Data in) { Use.thenValue to indicate that the operation protect_.operateor(in) with the passed-in parameter is completed;

[0131] For(int i = 0; i < size; i++) { Traverse the shellcode;

[0132] If(i == jump address)

[0133] If(address > (shellcode.start + shellcode.len) || address < shellcode.start

[0134] }}}}

[0135] When the security instance is an instance for preventing shellcode from being single-stepped debugged, the method further includes:

[0136] Use the execution parameter to scan the shellcode to determine whether there is an interrupt instruction for debugging code in the shellcode;

[0137] If it is determined that there is the interrupt instruction in the shellcode, it is determined that the shellcode has an exception, and the exception information is reported.

[0138] Specifically, when the security instance is an instance for preventing shellcode from being single-stepped debugged, at least one subclass is added to the template class, and the code implementation for executing the logic of this subclass is as follows:

[0139] class DebugProtect: public ProtectChain<Data, Data, Data, Data> {

[0140] explicit DebugProtect(std::shared_ptr<Protect<Data, Data>> protect):

[0141] ProtectChain<Data, Data, Data, Data>(protect) {}

[0142] Future <data>operator(Data in){

[0143] return protect_.operateor(in).thenValue([](Data in){Scan whether the shellcode has the int3 assembly instruction;

[0144] }

[0145] As an alternative embodiment, when the security instance is an instance for detecting the integrity of the shellcode, the method further includes:

[0146] Obtain the entire code corresponding to the shellcode;

[0147] Perform a hash calculation on the entire code to obtain the current hash result value;

[0148] Determine whether the current hash result value is consistent with the previously obtained reference hash result value. If not, determine that the shellcode is incomplete;

[0149] Report the detection result.

[0150] In this way, subclasses corresponding to each security instance can be added to the template class at will, and the corresponding subclasses are executed in sequence. The shellcode is protected by multiple security instances, thereby improving the security of the shellcode during operation. At the same time, since the addition of subclasses corresponding to each security instance is implemented based on a general template class, when writing the code corresponding to any security instance, only functional code needs to be added to the template class, and there is no need to write a large amount of auxiliary code, so the overall writing efficiency can be improved.

[0151] Based on the same inventive concept, the present invention also provides a device for improving the security of machine code, as detailed in Embodiment 2.

[0152] Embodiment 2

[0153] This embodiment provides a device for improving the security of machine code, as Figure 2 shown. The device includes: a creation unit 21, an addition unit 22, a setting unit 23, and an execution unit 24; wherein,

[0154] The creation unit 21 is used to create a base class; the base class is used to define general class parameters, and the general class parameters include: an asynchronous operation interface, an input template parameter, and an output template parameter;

[0155] Create a template class based on the general class parameters in the base class;

[0156] An adding unit 22 is configured to add at least one subclass to the template class according to a preset security policy and determine an inheritance class of the at least one subclass; each of the subclasses corresponds to a security instance, and the security instance includes: an instance of a secure memory for executing the machine code shellcode, an instance for preventing the shellcode from being hooked, an instance for detecting the integrity of the shellcode, and an instance for preventing the shellcode from being single-stepped.

[0157] A setting unit 23 is configured to set a pointer to the next subclass of the current subclass in the current subclass based on a preset execution order of the security instances for any current subclass.

[0158] An execution unit 24 is configured to execute the security instances in the corresponding subclasses based on the pointers.

[0159] Since the security instances written for the shellcode code may include multiple types, may include multiple data types, and multiple operations (such as synchronous operations or asynchronous operations), in order to be able to write security instances efficiently, a creation unit 21 is configured to create a base class, and the base class is used to define general class parameters, and the general class parameters include: an asynchronous operation interface, an input template parameter, and an output template parameter.

[0160] Specifically, first, two template parameters template<typename in,typename out> are set, where typename in is the input template parameter and typename out is the output template parameter, so as to be applicable to different data types. For example, the input template parameter can be a memory address and a memory length, and then the output can be the code after initializing and obfuscating the memory segment.

[0161] Then, a base class Protect is created based on the two template parameters, and the code implementation is as follows:

[0162] class Protect{

[0163] virtual~Protect()=default;

[0164] virtual Future <out>operator(in src) = 0;

[0165] }

[0166] Here, when creating the base class, the base class is declared as virtual using the destructor to avoid memory leakage of the base class.

[0167] The base class provides an asynchronous operation interface. The input parameter in src of the asynchronous operation interface is an input template parameter, and the output parameter out of the asynchronous operation interface is an output template parameter. The output parameter out is of the same data type as the output template parameter. Operator is the execution logic corresponding to the specific security instance.

[0168] Here, by using the Future parameter in the base class, the execution logic can be carried out asynchronously. For some time-consuming operations, they can be dispatched to an asynchronous thread to complete. After the asynchronous thread finishes execution, the returned std::Future will become signaled to enable subsequent operations.

[0169] Since there may be multiple security instances used to protect the shellcode, in order to enable multiple security instances to be stacked infinitely to form a mesh protection and improve the writing efficiency, after the creation unit 21 creates the base class, a template class is created based on the general class parameters in the base class. The template class is a general template class that can add any subclass.

[0170] For example, if two security instances need to be written, then set the template parameters in the general template class: template<typename inA,typename outA,typename inB,typename outB>; where, inA and outA are the template parameters in the base class, which are equivalent to the template parameters corresponding to the first security instance; inB is the input template parameter of the second security instance, and outB is the output template parameter of the second security instance.

[0171] Then create the template class ProtectChain based on the template parameters. The code implementation is as follows:

[0172] class ProtectChain:public Protect<inA,outA>{

[0173] ~ProtectChain() = default;

[0174] private: shared_ptr<Protect<ReqB,RespB>> protect1_;

[0175] explicit ProtectChain(shared_ptr<Protect<ReqB,RespB>> protect) : protect2_(protect) {}

[0176] }

[0177] Here, to protect the written code, a privately accessible member variable Protect1_ is defined in the template class to prevent external access; this variable uses the smart pointer shared_ptr to manage its lifecycle, and when the variable is no longer in use, the smart pointer shared_ptr will release it automatically. Among them, ReqB is equivalent to inB, and RespB is equivalent to outB.

[0178] explicit ProtectChain(shared_ptr<Protect<ReqB,RespB>> protect) is a constructor. Since the constructor has only one parameter, the explicit keyword is used to declare this constructor, and the constructor parameter can be saved to the member variable protect2_(protect) {}; thus, the template class ProtectChain can accept a member variable of any data type and store it.

[0179] To improve the running security of the shellcode code, Unit 22 can add at least one subclass to the template class according to the preset security policy. After the subclass addition is completed, the inheritance class of at least one subclass is determined.

[0180] As an optional embodiment, when the security instance is an instance of the secure memory for executing the machine code shellcode, the adding of at least one subclass to the template class according to the preset security policy includes:

[0181] Create a structure struct Data, which is used to obtain the memory address Uint64_t* address and the memory length Uint32_t size of the security instance;

[0182] Create the first subclass MemoryProtect corresponding to the security instance, and the first subclass inherits from the base class Protect; the first subclass is used to obfuscate the memory address to increase the complexity of reverse engineering.

[0183] Use the creation function to create an asynchronous operation object, a Promise object, in the first subclass, and the asynchronous operation object is used to perform asynchronous operations;

[0184] Based on the memory address and memory length of the security instance, use the memory allocation function BYTE* pMem = MyVirtualAlloc(NULL, nSize, MEM_COMMIT, PAGE_EXECUTE_READWRITE); to allocate a memory address pMem for the security instance; MyVirtualAlloc is the said allocation function, the NULL is a null byte, the nSize is the allocated memory length, MEM_COMMIT is the allocated memory type, and PAGE_EXECUTE_READWRITE is the property parameter used to modify the executable and readable / writable properties of the memory;

[0185] Based on the allocated memory address, use the obfuscation function Hash = md5.create(pMem) to obtain obfuscated data, and initialize the allocated memory address based on the obfuscated data;

[0186] Use the copy function Memcpy(pMem, in.address, in.size) to copy the shellcode code to the initialized memory address; where in.size is the length of the written code.

[0187] Use the said Promise object to return the result.

[0188] Specifically, when the security instance is an instance of the secure memory for executing the machine code shellcode, the code for adding at least one subclass in the template class according to the preset security policy is implemented as follows:

[0189] class MemoryProtect:public Protect<Data,Data>{

[0190] Future <data>operator(Data in)override{

[0191] Promise <data>p;

[0192] BYTE* pMem = MyVirtualAlloc(NULL, nSize, MEM_COMMIT, PAGE_EXECUTE_READWRITE);

[0193] Hash = md5.create(pMem); memset(pMem, Hash);

[0194] Memcpy(pMem, in.address, in.size);

[0195] p.setvalue(in);

[0196] return f;}}}

[0197] As an optional embodiment, when the security instance is an instance for preventing shellcode from being hooked, an instance for detecting the integrity of shellcode, or an instance for preventing shellcode from being single-stepped, at least one subclass is added to the template class according to a preset security policy, including:

[0198] Create a second subclass corresponding to the security instance using the constructor;

[0199] Pass in the execution parameters of the constructor, and the execution parameters are used to execute the execution logic of the security instance;

[0200] Associate the execution parameters with the asynchronous operation interface in the base class.

[0201] Here, as an optional embodiment, determining the inheritance class of at least one subclass includes:

[0202] Obtain the execution order of the security instance set in the security policy;

[0203] For any current subclass, if the execution order of the security instance corresponding to the current subclass is to be executed first, then determine the inheritance class of the current subclass as the base class;

[0204] If the execution order of the security instance corresponding to the current subclass is not to be executed first, then determine the inheritance class of the current subclass as the template class.

[0205] For example, if the security instances include: an instance of secure memory for executing shellcode and an instance for preventing the shellcode from being hooked, and the instance of secure memory for executing shellcode is the first executed security instance, and the instance for preventing the shellcode from being hooked is the second executed security instance, then the inheritance class of the subclass corresponding to the instance of secure memory for executing shellcode is the base class, and the inheritance class of the subclass corresponding to the instance for preventing the shellcode from being hooked is the template class.

[0206] To support the mesh execution (serial execution) of each security instance and improve the security of shellcode operation, for any current subclass, the unit 23 is configured to set a pointer to the next subclass of the current subclass in the current subclass based on a preset security instance execution order.

[0207] For example, when the security instances are executed in the following order: an instance of secure memory for executing shellcode, an instance for preventing the shellcode from being hooked, an instance for preventing the shellcode from being single-stepped, and an instance for detecting the integrity of the shellcode, the specific implementation is as follows:

[0208] First, use the creation function Mem = make_shared <memoryprotect>(); Create a pointer to an instance of secure memory for executing shellcode;

[0209] Then, pass the pointer to the instance that prevents the shellcode from being hooked into the subclass corresponding to the secure memory instance. The code implementation is as follows:

[0210] Unhook = make_shared <unhookprotect>(Mem);

[0211] Pass the pointer of the instance used to prevent the shellcode from being single-stepped debugged into the subclass corresponding to the instance that prevents the shellcode from being hooked. The code implementation is as follows:

[0212] Debug = make_shared <debugprotect>(Unhook)

[0213] Pass the pointer of the instance used to detect the integrity of the shellcode into the subclass corresponding to the instance used to prevent the shellcode from being single-stepped debugged. The code implementation is as follows:

[0214] Check=make_shared <integrityprotect>(Debug);

[0215] That is, when the security instance includes three instances A, B, and C, and they are executed in the order of A, B, and C, then the pointer of B needs to be passed into the subclass corresponding to A, and the pointer of C needs to be passed into the subclass corresponding to B.

[0216] After setting the pointer of the next subclass of the current subclass in the current subclass based on the preset execution order of the security instances, the execution unit 24 can execute the security instances in the corresponding subclasses based on each pointer.

[0217] As an optional embodiment, when the security instance is an instance for preventing shellcode from being hooked, the execution unit 24 is used for:

[0218] Using the execution parameter to find out whether there is a jump instruction in the shellcode. If there is a jump instruction, it is determined whether the jump destination address of the jump instruction is within the code space of the shellcode;

[0219] If it is determined that the jump destination address of the jump instruction exists within the code space of the shellcode, it is determined that the jump instruction is a normal instruction;

[0220] If it is determined that the jump destination address of the jump instruction does not belong to the code space of the shellcode, it is determined that the jump instruction is an abnormal hook instruction.

[0221] Specifically, when the security instance is an instance for preventing shellcode from being hooked, adding at least one subclass to the template class and implementing the code for executing the logic of this subclass is as follows:

[0222] class UnhookProtect:public ProtectChain<Data,Data,Data,Data>{

[0223] explicit UnhookProtect(std::shared_ptr<Protect<Data,Data>>protect): the execution parameter Protect passed into the constructor;

[0224] ProtectChain<Data,Data,Data,Data>(protect){}

[0225] Future <data>operator(Data in) { The Protect parameter is associated with the asynchronous operation interface;

[0226] return protect_.operateor(in).thenValue([](Data in) { Use.thenValue to indicate that the operation protect_.operateor(in) with the passed-in parameter is completed;

[0227] For(int i = 0; i < size; i++) { Traverse the shellcode;

[0228] If(i == jump address)

[0229] If(address > (shellcode.start + shellcode.len) || address < shellcode.start

[0230] }}}}

[0231] When the security instance is an instance for preventing shellcode from being single-stepped debugged, the execution unit 24 is used for:

[0232] Use the execution parameter to scan the shellcode to determine whether there is an interrupt instruction for debugging code in the shellcode;

[0233] If it is determined that there is the interrupt instruction in the shellcode, it is determined that the shellcode has an exception, and the exception information is reported.

[0234] Specifically, when the security instance is an instance for preventing shellcode from being single-stepped debugged, at least one subclass is added to the template class, and the code implementation for executing the logic of this subclass is as follows:

[0235] class DebugProtect: public ProtectChain<Data, Data, Data, Data> {

[0236] explicit DebugProtect(std::shared_ptr<Protect<Data, Data>> protect):

[0237] ProtectChain<Data, Data, Data, Data>(protect) {}

[0238] Future <data>operator(Data in){

[0239] return protect_.operateor(in).thenValue([](Data in){Scan whether the shellcode has the int3 assembly instruction;

[0240] }

[0241] As an optional embodiment, when the security instance is an instance for detecting the integrity of the shellcode, the execution unit 24 is configured to:

[0242] Obtain the entire code corresponding to the shellcode;

[0243] Perform a hash calculation on the entire code to obtain the current hash result value;

[0244] Determine whether the current hash result value is consistent with the previously obtained reference hash result value. If not, determine that the shellcode is incomplete;

[0245] Report the detection result.

[0246] In this way, subclasses corresponding to each security instance can be added to the template class at will, and the corresponding subclasses are executed sequentially. The shellcode is protected by multiple security instances, thereby improving the security of the shellcode during operation; at the same time, since the addition of subclasses corresponding to each security instance is implemented based on a general template class, when writing the code corresponding to any security instance, only the functional code needs to be added to the template class, without having to write a large amount of auxiliary code, so the overall writing efficiency can be improved.

[0247] Embodiment 3

[0248] This embodiment provides a computer device, as Figure 3 shown, including a memory 310, a processor 320, and a computer program 311 stored in the memory 310 and executable on the processor 320. When the processor 320 executes the computer program 311, the following steps are implemented:

[0249] Create a base class; the base class is used to define general class parameters, and the general class parameters include: an asynchronous operation interface, an input template parameter, and an output template parameter;

[0250] Create a template class based on the general class parameters in the base class, and the template class is a general template class to which any subclass can be added;

[0251] Add at least one subclass to the template class according to a preset security policy, and determine the inheritance class of the at least one subclass; each of the subclasses corresponds to a security instance, and the security instance includes: an instance of secure memory for executing the machine code shellcode, an instance for preventing the shellcode from being hooked, an instance for detecting the integrity of the shellcode, and an instance for preventing the shellcode from being single-stepped debugged;

[0252] For any current subclass, set a pointer to the next subclass of the current subclass in the current subclass based on a preset execution order of the security instances;

[0253] Execute the security instances in the corresponding subclasses based on the pointers.

[0254] In a specific implementation process, when the processor 320 executes the computer program 311, any implementation manner in Embodiment 1 can be implemented.

[0255] Since the computer device introduced in this embodiment is the device used to implement a method for improving the security of machine code in Embodiment 1 of the present application, based on the method introduced in Embodiment 1 of the present application, those skilled in the art can understand the specific implementation manner of the computer device in this embodiment and its various variations. Therefore, the specific implementation of how this server implements the method in the embodiments of the present application will not be described in detail here. As long as the device used by those skilled in the art to implement the method in the embodiments of the present application belongs to the scope protected by the present application.

[0256] Based on the same inventive concept, the present application provides a storage medium corresponding to Embodiment 1, as detailed in Embodiment 4.

[0257] Embodiment 4

[0258] This embodiment provides a computer-readable storage medium 400, as Figure 4 shown, on which a computer program 411 is stored, and when the computer program 411 is executed by a processor, the following steps are implemented:

[0259] Create a base class; the base class is used to define general class parameters, and the general class parameters include: an asynchronous operation interface, input template parameters, and output template parameters;

[0260] Create a template class based on the general class parameters in the base class, and the template class is a general template class to which any subclass can be added;

[0261] Add at least one subclass to the template class according to a preset security policy, and determine the inheritance class of the at least one subclass; each of the subclasses corresponds to a security instance, and the security instance includes: an instance of secure memory for executing the machine code shellcode, an instance for preventing the shellcode from being hooked, an instance for detecting the integrity of the shellcode, and an instance for preventing the shellcode from being single-stepped.

[0262] For any current subclass, set a pointer to the next subclass of the current subclass in the current subclass based on a preset execution order of the security instances.

[0263] Execute the security instances in the corresponding subclasses based on the pointers.

[0264] In a specific implementation process, when the computer program 411 is executed by a processor, any implementation manner in the first embodiment can be implemented.

[0265] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0266] The present application is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or block in the flowcharts and / or block diagrams, and the combination of processes and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate means for implementing the functions specified in Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks.

[0267] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured article including an instruction device, and the instruction device implements the functions specified in Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks.

[0268] These computer program instructions can also be loaded onto a computer or other programmable data processing apparatus, so that a series of operation steps are performed on the computer or other programmable apparatus to generate a computer-implemented process, thereby providing instructions for implementing the process on the computer or other programmable apparatus Figure 1 a process or processes and / or blocks Figure 1 steps for the functions specified in a block or blocks.

[0269] As described above, only the preferred embodiments of the present invention are given, and are not intended to limit the protection scope of the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.< / data> < / data> < / integrityprotect> < / debugprotect> < / unhookprotect> < / memoryprotect> < / data> < / data> < / out> < / data> < / data> < / integrityprotect> < / debugprotect> < / unhookprotect> < / memoryprotect> < / data> < / data> < / out>

Claims

1. A method for improving the security of machine code, characterized in that, The method includes: Create a base class; the base class is used to define general class parameters, and the general class parameters include: an asynchronous operation interface, input template parameters, and output template parameters; Create a template class based on the general class parameters in the base class, and the template class is a general template class that can add any subclass; Add at least one subclass to the template class according to a preset security policy, and determine the inheritance class of the at least one subclass; each subclass corresponds to a security instance, and the security instance includes: an instance of secure memory for executing the machine code shellcode, an instance for preventing the shellcode from being hooked, an instance for detecting the integrity of the shellcode, and an instance for preventing the shellcode from being single-stepped; For any current subclass, set the pointer to the next subclass of the current subclass in the current subclass based on a preset execution order of security instances; Execute the security instances in the corresponding subclasses based on each of the pointers; The determining the inheritance class of the at least one subclass includes: Obtain the execution order of the security instances set in the security policy; For any current subclass, if the execution order of the security instance corresponding to the current subclass is to be executed first, then determine the inheritance class of the current subclass as the base class; If the execution order of the security instance corresponding to the current subclass is not to be executed first, then determine the inheritance class of the current subclass as the template class; When the security instance is an instance of secure memory for executing the machine code shellcode, the adding at least one subclass to the template class according to a preset security policy includes: Create a structure for obtaining the memory address and memory length of the security instance; Create a first subclass corresponding to the security instance; Create an asynchronous operation object, a Promise object, in the first subclass, and the asynchronous operation object is used to perform an asynchronous operation; Based on the memory address and memory length of the security instance, use the memory allocation function BYTE* pMem = MyVirtualAlloc(NULL, nSize, MEM_COMMIT, PAGE_EXECUTE_READWRITE); to allocate a memory address pMem for the security instance; the MyVirtualAlloc is the allocation function, the NULL is a null byte, the nSize is the allocated memory length, the MEM_COMMIT is the allocated memory type, and the PAGE_EXECUTE_READWRITE is an attribute parameter for modifying the executable and readable / writable properties of the memory; Based on the allocated memory address, obtain obfuscated data using the obfuscation function Hash = md5.create(pMem), and initialize the allocated memory address based on the obfuscated data; Copy the shellcode code to the initialized memory address; Use the Promise object to return the result.

2. The method according to claim 1, wherein When the security instance is an instance for preventing the shellcode from being hooked, an instance for detecting the integrity of the shellcode, or an instance for preventing the shellcode from being single-stepped, adding at least one subclass to the template class according to a preset security policy includes: Creating a second subclass corresponding to the security instance using a constructor; Passing in execution parameters for the constructor, where the execution parameters are used to execute the execution logic of the security instance; Associating the execution parameters with the asynchronous operation interface in the base class.

3. The method according to claim 2, characterized in that, When the security instance is an instance for preventing the shellcode from being hooked, the method further includes: Using the execution parameters to find whether there is a jump instruction in the shellcode. If there is the jump instruction, determining whether the jump destination address of the jump instruction is within the code space of the shellcode; If it is determined that the jump destination address of the jump instruction exists within the code space of the shellcode, determining that the jump instruction is a normal instruction; If it is determined that the jump destination address of the jump instruction does not belong to the code space of the shellcode, determining that the jump instruction is an abnormal hook instruction.

4. The method according to claim 3, characterized in that, When the security instance is an instance for preventing the shellcode from being single-stepped, the method further includes: Scanning the shellcode using the execution parameters to determine whether there is an interrupt instruction for debugging code in the shellcode; If it is determined that there is the interrupt instruction in the shellcode, determining that the shellcode is abnormal and reporting the abnormal information.

5. The method according to claim 1, wherein When the security instance is an instance for detecting the integrity of the shellcode, the method further includes: Obtaining the entire code corresponding to the shellcode; Performing a hash calculation on the entire code to obtain a current hash result value; Determining whether the current hash result value is consistent with a previously obtained reference hash result value. If not, determining that the shellcode is incomplete; Reporting the detection result.

6. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the program is executed by a processor, it implements the method according to any one of claims 1 to 5.

7. A computer device, comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the method according to any one of claims 1 to 5.

Citation Information

Patent Citations

  • Handle management method, storage medium, electronic equipment and system

    CN110806867A