Symbol obfuscation methods, apparatuses, media, and computing devices
Patent Information
- Application Number
- CN202210157072.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-02-21
- Publication Date
- 2026-09-29
- Estimated Expiration
- 2042-02-21
AI Technical Summary
[0019]采用上述方式,通过对与上述原始iOS应用程序对应的可重定位目标文件进行符号混淆,并基于符号混淆后的可重定位目标文件生成加固iOS应用程序,可以使该加固iOS应用程序与该原始iOS应用程序提供相同的功能,同时避免与这些功能对应的逻辑被破解,提高该原始iOS应用程序的安全性。此外,由于无需对与该原始iOS应用程序对应的源代码进行修改,因此,还可以保证与该原始iOS应用程序对应的源代码的完整性和可靠性,避免对原始iOS应用程序的源代码造成侵入。
Smart Images

Figure CN114547559B_ABST
Abstract
Description
Technical Field
[0001] The embodiments of this disclosure relate to the field of computer application technology, and more specifically, the embodiments of this disclosure relate to a symbol obfuscation method, apparatus, medium, and computing device. Background Technology
[0002] This section is intended to provide background or context for the embodiments of this disclosure as set forth in the claims. The description herein is not intended to be a prior art simply because it is included in this section.
[0003] Nowadays, applications (APPs) are becoming increasingly diverse in type and functionality. For any application, the functions it provides are typically implemented by running corresponding code to execute the logic instructed by that code. In this context, to prevent the logic corresponding to the application's functions from being compromised and to enhance the application's security, it is necessary to perform certain processing on the corresponding code. Summary of the Invention
[0004] In this context, embodiments of the present disclosure are intended to provide a symbol obfuscation method, apparatus, medium, and computing device.
[0005] In a first aspect of this disclosure, a symbol obfuscation method is provided, the method comprising:
[0006] The source files corresponding to the original iOS application are compiled to generate a dSYM file and a relocatable target file corresponding to the original iOS application; wherein, the dSYM file includes a mapping relationship between a first memory address and a primitive symbol, the primitive symbol corresponds to the source code in the source file, the first memory address is used to indicate the memory space corresponding to the source code, and the relocatable target file includes the primitive symbol;
[0007] The relocatable target file is parsed, the original symbols to be obfuscated are determined from the original symbols included in the relocatable target file, and the original symbols to be obfuscated are obfuscated to obtain the obfuscated relocatable target file.
[0008] Based on the relocatable target file after symbol obfuscation, a hardened iOS application corresponding to the original iOS application is generated.
[0009] In a second aspect of this disclosure, a symbol confusion apparatus is provided, the apparatus comprising:
[0010] The first generation module is used to compile the source file corresponding to the original iOS application to generate a dSYM file and a relocatable target file corresponding to the original iOS application; wherein, the dSYM file includes a mapping relationship between a first memory address and a primitive symbol, the primitive symbol corresponds to the source code in the source file, the first memory address is used to indicate the memory space corresponding to the source code, and the relocatable target file includes the primitive symbol;
[0011] The obfuscation module is used to parse the relocatable target file, determine the original symbols to be obfuscated from the original symbols included in the relocatable target file, and perform symbol obfuscation on the original symbols to be obfuscated to obtain the symbol-obfuscated relocatable target file.
[0012] The second generation module is used to generate a hardened iOS application corresponding to the original iOS application based on the relocatable target file after symbol obfuscation.
[0013] In a third aspect of the present disclosure, a medium is provided having a computer program stored thereon, which, when executed by a processor, implements any of the above-described image processing methods.
[0014] In a fourth aspect of this disclosure, a computing device is provided, comprising:
[0015] processor;
[0016] Memory used to store processor-executable programs;
[0017] The processor implements any of the above image processing methods by running the executable program.
[0018] According to the embodiments of this disclosure, a dSYM file and a relocatable target file corresponding to the original iOS application can be generated first based on the source file corresponding to the original iOS application. Then, the original symbols to be obfuscated are determined from the original symbols included in the relocatable target file, and these original symbols to be obfuscated are obfuscated to obtain the obfuscated relocatable target file. Finally, a hardened iOS application corresponding to the original iOS application is generated based on the obfuscated relocatable target file.
[0019] By employing the above method, through symbol obfuscation of the relocatable target file corresponding to the original iOS application, and generating a hardened iOS application based on the symbol-obfuscated relocatable target file, the hardened iOS application can provide the same functionality as the original iOS application while preventing the corresponding logic from being cracked, thus improving the security of the original iOS application. Furthermore, since no modification to the source code corresponding to the original iOS application is required, the integrity and reliability of the source code can be guaranteed, preventing intrusion into the original iOS application's source code. Attached Figure Description
[0020] The above and other objects, features, and advantages of this disclosure will become readily apparent from the following detailed description of exemplary embodiments, taken in conjunction with the accompanying drawings. Several embodiments of this disclosure are illustrated in the drawings by way of example and not limitation, in which:
[0021] Figure 1 A schematic diagram illustrating a symbol confusion scenario according to an embodiment of the present disclosure is shown.
[0022] Figure 2 A flowchart illustrating a symbol confusion method according to an embodiment of the present disclosure is shown schematically;
[0023] Figure 3 A flowchart illustrating a symbol collection library generation method according to an embodiment of the present disclosure is shown schematically.
[0024] Figure 4 A flowchart illustrating a method for restoring a crash stack according to an embodiment of the present disclosure is shown schematically;
[0025] Figure 5 A schematic diagram of a medium according to an embodiment of the present disclosure is shown;
[0026] Figure 6 A block diagram of a symbol confusion device according to an embodiment of the present disclosure is shown schematically;
[0027] Figure 7 A schematic diagram of a computing device according to an embodiment of the present disclosure is shown.
[0028] In the accompanying drawings, the same or corresponding reference numerals indicate the same or corresponding parts. Detailed Implementation
[0029] The principles and spirit of this disclosure will now be described with reference to several exemplary embodiments. It should be understood that these embodiments are given merely to enable those skilled in the art to better understand and implement this disclosure, and are not intended to limit the scope of this disclosure in any way. Rather, these embodiments are provided to make this disclosure more thorough and complete, and to fully convey the scope of this disclosure to those skilled in the art.
[0030] Those skilled in the art will recognize that embodiments of this disclosure can be implemented as a system, apparatus, device, method, or computer program product. Therefore, this disclosure can be specifically implemented in the following forms: entirely hardware, entirely software (including firmware, resident software, microcode, etc.), or a combination of hardware and software.
[0031] According to embodiments of this disclosure, a symbol confusion method, medium, apparatus, medium, and computing device are proposed.
[0032] In this article, it is important to understand that any number of elements in the accompanying figures is for illustrative purposes and not for limitation, and any naming is for distinction only and has no limiting meaning.
[0033] The principles and spirit of this disclosure will be explained in detail below with reference to several representative embodiments. Invention Overview
[0035] In practical applications, by using different programming languages to write the source code corresponding to the application, the application can run on different operating systems. For example, an application written in Java can run on the Android operating system; an application written in Objective-C can run on the iOS operating system.
[0036] In this disclosure, applications running on iOS are referred to as iOS applications.
[0037] Objective-C is an object-oriented programming language that extends C. This type of programming language is dynamic, mainly including dynamic typing, dynamic binding, and dynamic loading. This dynamism is reflected in the notation.
[0038] When developing iOS applications, engineers define symbols related to the application's logic, such as class names, method names, property names, and variable names. These symbols typically have clear semantic meaning to facilitate writing, reading, understanding, and maintaining the source code. For example, the method name "getOSVer" indicates a method to retrieve the operating system version, and the method name "getPhoneName" indicates a method to retrieve the phone name. After compiling the source code, these symbols are stored in binary files such as relocatable object files (DSYM files) and also in dSYM files. The dSYM file is an object file containing debugging information; it's a mapping table of memory addresses to function names, file names, and line numbers, used for crash stack reconstruction.
[0039] Because symbols in iOS applications have clear semantic meaning, hackers can easily analyze the logic of an iOS application based on the meaning of these symbols after obtaining them using decompilation tools, thus exposing the iOS application to huge security problems.
[0040] To prevent the logic corresponding to the functions provided by the application from being cracked and to enhance the security of the application, it is necessary to obfuscate the symbols in the iOS application, turning these symbols into strings with no obvious meaning or representing other meanings.
[0041] In related technologies, the common approach is to directly modify the source code corresponding to the iOS application to obfuscate the symbols in that application. However, this can lead to some degree of damage to the source code, and the symbols in the dSYM file corresponding to the iOS application are also obfuscated. When using this dSYM file to reconstruct the crash stack, it becomes impossible to directly determine the symbol corresponding to the exception code that caused the crash.
[0042] To address the aforementioned issues, this disclosure provides a technical solution for symbol obfuscation. In this solution, a dSYM file and a relocatable target file corresponding to the original iOS application are first generated based on the source file corresponding to the original iOS application. Then, the original symbols to be obfuscated are identified from the original symbols included in the relocatable target file, and these symbols are obfuscated to obtain the obfuscated relocatable target file. Finally, a hardened iOS application corresponding to the original iOS application is generated based on the obfuscated relocatable target file.
[0043] By employing the above method, through symbol obfuscation of the relocatable target file corresponding to the original iOS application, and generating a hardened iOS application based on the symbol-obfuscated relocatable target file, the hardened iOS application can provide the same functionality as the original iOS application while preventing the corresponding logic from being cracked, thus improving the security of the original iOS application. Furthermore, since no modification to the source code corresponding to the original iOS application is required, the integrity and reliability of the source code can be guaranteed, preventing intrusion into the original iOS application's source code.
[0044] After introducing the basic principles of this disclosure, various non-limiting embodiments of this disclosure will be described in detail below.
[0045] Application Scenarios Overview
[0046] First refer to Figure 1 , Figure 1 This is a schematic diagram of a symbol confusion scenario according to an embodiment of the present disclosure.
[0047] like Figure 1 As shown, in a symbol confusion scenario, it may include a server and at least one client (e.g., client 1-N) that accesses the server.
[0048] The aforementioned server can be deployed on a single server or server cluster; alternatively, the server can be built on cloud computing services.
[0049] Users can install a client corresponding to a certain application on their devices; specifically, the device can be a smartphone, tablet, PDA, laptop, PC (Personal Computer), smart wearable device, smart in-vehicle device, or game console, etc.
[0050] Technicians can write the corresponding source code for an iOS application based on the desired functionality and save this source code as a source file. In this case, the iOS application can be generated on the server based on this source file and installed on the user's terminal device, allowing the user to use the functions provided by the iOS application through the corresponding client.
[0051] The symbol obfuscation method disclosed herein can be applied to the aforementioned server; the server stores source files corresponding to the iOS application to be generated, and the server can generate the iOS application based on the source files.
[0052] It should be noted that the symbol obfuscation method disclosed herein can be applied to any electronic device that provides the function of generating corresponding iOS applications based on source files, and this disclosure does not impose any restrictions on it.
[0053] Exemplary methods
[0054] The following is combined Figure 1 Application scenarios, refer to Figures 2-4 This document describes a method for symbol obfuscation according to exemplary embodiments of the present disclosure. It should be noted that the above application scenarios are shown only to facilitate understanding of the spirit and principles of the present disclosure, and the embodiments of the present disclosure are not limited in any way. Rather, the embodiments of the present disclosure can be applied to any applicable scenario.
[0055] refer to Figure 2 , Figure 2 A flowchart illustrating a symbol obfuscation method according to an embodiment of the present disclosure is shown schematically.
[0056] It should be noted that, for the source file corresponding to the iOS application to be generated, if the symbols in the source code contained in the source file are not obfuscated, the iOS application corresponding to the source file can be called the original iOS application, that is, the original iOS application is generated directly based on the source file.
[0057] Typically, generating an iOS application from source files involves two main processes. First, the source file (usually a .c file, i.e., a file with the .c extension) is compiled to generate a relocatable object file (usually a .o file, i.e., a file with the .o extension) corresponding to the iOS application. Next, this generated relocatable object file is linked with the corresponding static library file (usually a .a file, i.e., a file with the .a extension) of the iOS application. The linked relocatable object file is usually considered an executable file. Since an iOS application typically includes multiple executable files and multiple dynamic library files necessary for its proper functioning, these executable files and dynamic library files can be packaged to generate the iOS application.
[0058] The above symbol obfuscation method may include the following steps:
[0059] Step 201: Compile the source file corresponding to the original iOS application to generate a dSYM file and a relocatable target file corresponding to the original iOS application; wherein, the dSYM file includes a mapping relationship between a first memory address and a primitive symbol, the primitive symbol corresponds to the source code in the source file, the first memory address is used to indicate the memory space corresponding to the source code, and the relocatable target file includes the primitive symbol.
[0060] In this embodiment, the source files can be compiled first to generate a dSYM file and a relocatable target file corresponding to the original iOS application.
[0061] For the dSYM file corresponding to an iOS application, the dSYM file typically records the mapping relationship between memory addresses and symbols. The symbol corresponds to the source code in the iOS application's source file; that is, the symbol can be a class name, method name, property name, or some variables in the source code. The memory address indicates the memory space corresponding to that source code, specifically a memory address offset. After the iOS application is installed on the mobile device, the memory space where the source code indicated by the symbol is located can be determined based on the memory space occupied by the iOS application and the memory address offsets corresponding to each symbol, so that the source code stored in that memory space can be run.
[0062] In other words, the dSYM file corresponding to the original iOS application can include a mapping between a first memory address and a primitive symbol. The primitive symbol corresponds to the source code in the source file of the original iOS application, and the first memory address indicates the memory space corresponding to that source code.
[0063] Since the relocatable target file corresponding to the original iOS application is obtained by compiling the source file of the original iOS application, the relocatable target file includes the original symbols mentioned above, that is, the symbols in the relocatable target file are the original symbols mentioned above.
[0064] Step 202: Parse the relocatable target file, determine the original symbols to be obfuscated from the original symbols included in the relocatable target file, and obfuscate the original symbols to be obfuscated to obtain the obfuscated relocatable target file.
[0065] In this embodiment, after generating a dSYM file and a relocatable target file corresponding to the original iOS application, the relocatable target file can be parsed first, and the original symbols to be obfuscated can be determined from the original symbols included in the relocatable target file.
[0066] For relocatable target files corresponding to iOS applications, the number of symbols included in the relocatable target file is usually large. To facilitate the identification of the original symbols to be obfuscated from the original symbols included in the relocatable target file corresponding to the original iOS application, and to reduce the workload required, a database for symbol obfuscation can be pre-set.
[0067] It should be noted that the aforementioned database can be used to collect obfuscated original symbols from the original iOS application. Therefore, this database can be called a symbol collection library, and the original symbols in the database can be called sample symbols.
[0068] In the above-described case, in one embodiment shown, when determining the original symbol to be obfuscated from the original symbols included in the relocatable target file corresponding to the original iOS application, the original symbol to be obfuscated can be determined specifically based on the matching of the original symbols included in the relocatable target file with the sample symbols in the symbol collection library.
[0069] For example, suppose the sample symbols in the aforementioned symbol collection library include symbols A, B, and C, and the original symbols in the relocatable target file corresponding to the original iOS application include symbols A, B, C, and D. Since symbol A in the relocatable target file matches symbol A in the sample symbols, symbol B in the relocatable target file matches symbol B in the sample symbols, and symbol C in the relocatable target file matches symbol C in the sample symbols, it can be determined that the original symbols to be obfuscated in the original symbols included in the relocatable target file are symbols A, B, and C, while symbol D is the original symbol that does not need to be obfuscated.
[0070] Subsequently, the original symbols to be obfuscated identified from the original symbols included in the above relocatable target file can be automatically obfuscated to obtain the obfuscated relocatable target file, thus eliminating the need for developers to manually add the original symbols to be obfuscated that are newly generated due to version iterations and are already included in the symbol collection library.
[0071] For example, suppose the original symbols to be obfuscated identified from the original symbols included in the above relocatable target file are symbols A, B, and C. By obfuscating these three original symbols, we can obtain symbols A', B', and C'. Then, we can replace symbol A in the relocatable target file with symbol A', replace symbol B in the relocatable target file with symbol B', and replace symbol C in the relocatable target file with symbol C'. The file obtained after the replacement is the obfuscated relocatable target file.
[0072] In practical applications, the original symbols to be confused can be confused according to certain rules.
[0073] Specifically, in one embodiment shown, the original symbols to be obfuscated can be obfuscated based on preset symbol obfuscation rules. These symbol obfuscation rules can be preset by a technician according to actual needs, and this disclosure does not impose any restrictions on them.
[0074] In one example, the aforementioned symbol obfuscation rule may include: selecting a preset number of characters from the original symbol to be obfuscated, and then transforming the selected characters into random characters. This number can be preset by a technician according to actual needs, and this disclosure does not impose any restrictions on it. Using this symbol obfuscation rule ensures the randomness of the obfuscation, increasing the difficulty of cracking the obfuscated symbol.
[0075] For example, suppose the original symbol to be obfuscated is "getOSVer" and the preset quantity is 3. Then, 3 characters can be randomly selected from the 8 characters included in the original symbol and the selected characters can be transformed into random characters. For example, the original symbol can be transformed into "AetOmVey".
[0076] It should be noted that when transforming the selected characters into random characters, the case of the resulting random characters can also be random.
[0077] In another example, the above symbol obfuscation rule may include: calculating the hash value of the original symbol to be obfuscated, and determining the calculated hash value as the obfuscated symbol. By employing this symbol obfuscation rule, since hash calculations on different data yield different hash values, the uniqueness of the obfuscation can be guaranteed, avoiding the situation where obfuscating two different original symbols results in the same obfuscated symbol.
[0078] For relocatable object files corresponding to iOS applications, the file type is typically a Mach-O file. Furthermore, since the purpose of compiling source files is to translate source code written in a programming language by engineers into machine language code that can be directly understood by the machine, the content of the relocatable object file is usually binary encoded.
[0079] In the above scenario, in one embodiment shown, the relocatable target file can be parsed based on the Mach-O file format and binary file read / write operations.
[0080] Step 203: Generate a hardened iOS application corresponding to the original iOS application based on the relocatable target file after symbol obfuscation.
[0081] In this embodiment, given the aforementioned symbol-obfuscated relocatable target file, an iOS application can be generated based on this symbol-obfuscated relocatable target file.
[0082] It should be noted that since the symbols in the relocatable target file after symbol obfuscation are no longer the original symbols, but rather obfuscated symbols, it is usually difficult to analyze the logic of the original iOS application through these obfuscated symbols. However, the generated iOS application provides the same functionality as the original iOS application. Therefore, this iOS application can be called a hardened iOS application corresponding to the original iOS application. Furthermore, the security of this hardened iOS application is stronger than that of the original iOS application.
[0083] In addition, it should be noted that since the symbol obfuscation is performed on the relocatable target file of the binary file type, and the binary encoding in the binary file is usually highly incomprehensible to software developers, the hardened iOS application generated based on the above symbol obfuscated relocatable target file can provide the same functions as the original iOS application, but the difficulty of cracking the logic corresponding to these functions is also increased.
[0084] In conjunction with the aforementioned process of generating an iOS application based on source files, in one embodiment shown, when generating the hardened iOS application based on the aforementioned symbol-obfuscated relocatable target file, the symbol-obfuscated relocatable target file can be linked with the static library file corresponding to the original iOS application, and the linked relocatable target file can be packaged to generate the hardened iOS application.
[0085] It should be noted that generating an iOS application from source files is typically a complete process. However, in this embodiment, based on Hook technology, when compiling the source files corresponding to the original iOS application to generate the corresponding dSYM file and relocatable target file, the process can be interrupted to obfuscate the original symbols to be obfuscated in the original symbols included in the relocatable target file, resulting in the obfuscated relocatable target file. Then, the process can continue to generate the hardened iOS application based on the obfuscated relocatable target file.
[0086] In practical applications, iOS applications can be developed using the Xcode Integrated Development Environment (IDE).
[0087] Specifically, in one embodiment shown, the source files corresponding to the original iOS application can be compiled based on the Xcode integrated development environment to generate a dSYM file and a relocatable target file corresponding to the original iOS application.
[0088] Accordingly, the aforementioned hardened iOS application can be generated based on the Xcode integrated development environment and the aforementioned relocatable target file after symbol obfuscation.
[0089] Furthermore, in one embodiment shown, an iOS application hardening tool can be used to parse the relocatable target file corresponding to the original iOS application, identify the original symbols to be obfuscated from the original symbols included in the relocatable target file, and perform symbol obfuscation on these original symbols to obtain the symbol-obfuscated relocatable target file.
[0090] It should be noted that the aforementioned iOS application hardening tool is independent of the Xcode integrated development environment (IDE). This decouples the symbol obfuscation process from the Xcode IDE, avoiding the need to modify the Xcode IDE.
[0091] According to the embodiments of this disclosure, a dSYM file and a relocatable target file corresponding to the original iOS application can be generated first based on the source file corresponding to the original iOS application. Then, the original symbols to be obfuscated are determined from the original symbols included in the relocatable target file, and these original symbols to be obfuscated are obfuscated to obtain the obfuscated relocatable target file. Finally, a hardened iOS application corresponding to the original iOS application is generated based on the obfuscated relocatable target file.
[0092] By employing the above method, through symbol obfuscation of the relocatable target file corresponding to the original iOS application, and generating a hardened iOS application based on the symbol-obfuscated relocatable target file, the hardened iOS application can provide the same functionality as the original iOS application while preventing the corresponding logic from being cracked, thus improving the security of the original iOS application. Furthermore, since no modification to the source code corresponding to the original iOS application is required, the integrity and reliability of the source code can be guaranteed, preventing intrusion into the original iOS application's source code.
[0093] The process of obtaining the above symbol collection library is explained below.
[0094] refer to Figure 3 , Figure 3 A flowchart illustrating a symbol collection library generation method according to an embodiment of the present disclosure is shown schematically.
[0095] The above method for generating a symbol collection library may include the following steps:
[0096] Step 301: Generate the original iOS application based on the source files before compiling the source files corresponding to the original iOS application.
[0097] Step 302: Decompile the original iOS application to obtain the original symbols in the original iOS application, and filter out the unobfuscated original symbols from the obtained original symbols to obtain obfuscated original symbols.
[0098] Step 303: Generate the symbol collection library based on the obfuscated original symbols.
[0099] In one example, technicians can pre-set some obfuscated original symbols according to actual needs, and generate the above-mentioned symbol collection library based on these obfuscated original symbols.
[0100] In another example, the original iOS application can be generated based on the source file before compiling the source file corresponding to the original iOS application mentioned above.
[0101] Subsequently, the original iOS application can be decompiled to obtain its original symbols. These symbols can then be filtered to remove those that should not be obfuscated, resulting in obfuscated symbols. Based on these filtered obfuscated symbols, the aforementioned symbol collection library can then be generated.
[0102] For example, the aforementioned obfuscated original symbols may include one or more of the following: symbols corresponding to the code used to obtain the IDFV; symbols corresponding to the code used to obtain the operating system version; symbols corresponding to the code used to obtain the device name; symbols corresponding to the code used to obtain the language; and symbols corresponding to the code used to obtain the CPU model.
[0103] In practical applications, the class-dump tool can be used to decompile the original iOS application and obtain the original symbols in the original iOS application.
[0104] Specifically, in one embodiment shown, the original iOS application can be decompiled using a class-dump tool to obtain executable files corresponding to the original iOS application, and the original symbols in the original iOS application can be extracted from these obtained executable files.
[0105] In one embodiment shown, the aforementioned obfuscated original symbols may include one or more of the following: symbols corresponding to operating system code; symbols corresponding to code used for rendering the user interface (UI); symbols corresponding to code used for generating interactive controls; symbols corresponding to code used for reflection calls; and symbols from a preset symbol blacklist. The symbols in this blacklist may be preset by a technician according to actual needs, and this disclosure does not impose any restrictions on this.
[0106] For iOS applications, the symbols that should not be obfuscated are usually clearly known to technical personnel, while the symbols that can be obfuscated are often numerous and varied, making it difficult for technical personnel to enumerate them all. Therefore, filtering out the obfuscated original symbols from the original symbols in the aforementioned original iOS application can ensure the comprehensiveness of the obfuscated original symbols obtained.
[0107] In addition, the source code corresponding to the original iOS application may also contain some referenced third-party code, which may contain obfuscated symbols. In this case, by identifying obfuscated original symbols from the original symbols in the original iOS application, obfuscated original symbols can also be identified from the third-party code, thereby further ensuring the comprehensiveness of the obtained obfuscated original symbols.
[0108] The following describes the process of restoring the crash stack using the dSYM file corresponding to the original iOS application described above.
[0109] refer to Figure 4 , Figure 4 A flowchart illustrating a method for restoring a crash stack according to an embodiment of the present disclosure is shown schematically.
[0110] The method for restoring the crash stack described above may include the following steps:
[0111] Step 401: In response to the crash of the hardened iOS application, obtain the crash log corresponding to the hardened iOS application; wherein the crash log includes a second memory address corresponding to the exception code.
[0112] Step 402: Determine the first memory address in the dSYM file that matches the second memory address, and based on the mapping relationship in the dSYM file, determine the original symbol corresponding to the second memory address.
[0113] When an iOS application runs, the methods and functions that instruct the application's logic are loaded onto the stack for execution. Typically, these methods and functions are logged.
[0114] In the event of a crash in the hardened iOS application mentioned above, the second memory address corresponding to the exception code that caused the crash will be recorded in the crash log corresponding to that hardened iOS application. In this case, the crash log corresponding to that hardened iOS application can be retrieved first.
[0115] Subsequently, the second memory address can be matched with the first memory address in the dSYM file corresponding to the original iOS application to determine the first memory address in the dSYM file that matches the second memory address. Based on the mapping relationship between the first memory address in the dSYM file and the original symbol, the original symbol corresponding to the second memory address, i.e., the original symbol corresponding to the above-mentioned exception code, can be determined.
[0116] In other words, since the source code corresponding to the original iOS application was not modified, the symbols in the dSYM file generated by compilation (i.e., the dSYM file corresponding to the hardened iOS application) are the original symbols from the original iOS application, not obfuscated symbols. In the event of a crash in the hardened iOS application, this dSYM file can be used directly to determine the original symbols corresponding to the exception code that caused the crash.
[0117] For example, suppose the source code corresponding to the original iOS application defines a class (class name NTDevice Info) for obtaining device information. This class includes methods for obtaining the IDFV (method name getIDFV), obtaining the operating system version (method name getOSVer), obtaining the device name (method name getPhoneName), and obtaining the language (method name getLangCode).
[0118] Further assume that the class name "NTDeviceInfo" is obfuscated as "MacronScythe", the method name "getIDFV" is obfuscated as "Thrusts", the method name "getOSVer" is obfuscated as "Commovea", the method name "getPhoneName" is obfuscated as "ShrubsCachet", and the method name "getLangCode" is obfuscated as "VetchNerves".
[0119] In the above situation, decompiling the hardened iOS application obtained through symbol obfuscation yields obfuscated class and method names such as "MacronScythe", "Commovea", "Thrusts", "VetchNerves", and "ShrubsCachet", instead of the original class and method names.
[0120] Suppose that the method described above for obtaining the operating system version contains a piece of exception code, and the memory address corresponding to this method is 0x104ac5f10. In the event that the hardened iOS application crashes, the crash log corresponding to the hardened iOS application will record the memory address 0x104ac5f10 corresponding to the exception code.
[0121] The dSYM file corresponding to both the original iOS application and the hardened iOS application can include a mapping between memory addresses and primitive symbols. For example, if the memory address corresponding to the method name "getOSVer" in the dSYM file is 0x104ac5f10, then the primitive symbol corresponding to the exception code that caused the crash can be determined to be "getOSVer".
[0122] Exemplary media
[0123] After introducing the methods of exemplary embodiments of this disclosure, the following references are made. Figure 5 The medium for symbol obfuscation, as exemplarily described in this disclosure, is explained.
[0124] In this exemplary embodiment, the above method can be implemented by a program product, such as a portable compact disc read-only memory (CD-ROM) containing program code, which can run on a device, such as a personal computer. However, the program product disclosed herein is not limited thereto. In this document, a readable storage medium can be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device.
[0125] This program product can be produced using any combination of one or more readable media. The readable media can be a readable signal medium or a readable storage medium.
[0126] A readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples (a non-exhaustive list) of readable storage media include: an electrical connection having one or more wires, a portable disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination thereof.
[0127] A readable signal medium may include a data signal propagated in baseband or as part of a carrier wave, carrying readable program code. This propagated data signal may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A readable signal medium may also be any readable medium other than a readable storage medium, capable of sending, propagating, or transmitting a program for use by or in conjunction with an instruction execution system, apparatus, or device.
[0128] The program code contained on the readable medium may be transmitted using any suitable medium, including but not limited to wireless, wired, optical fiber, RE, etc., or any suitable combination thereof.
[0129] Program code for performing the operations of this disclosure can be written in any combination of one or more programming languages, including object-oriented programming languages such as Java and C++, as well as conventional procedural programming languages such as C or similar languages. The program code can execute entirely on the user's computing device, partially on the user's computing device and partially on a remote computing device, or entirely on a remote computing device or server. In cases involving remote computing devices, the remote computing device can be connected to the user's computing device via any type of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computing device (e.g., via the Internet using an Internet service provider).
[0130] Exemplary device
[0131] Having introduced the medium of exemplary embodiments of this disclosure, the following references are made to... Figure 6 An apparatus for symbol confusion according to an exemplary embodiment of the present disclosure will be described.
[0132] The specific implementation process of the functions and roles of each module in the following apparatus is detailed in the implementation process of the corresponding steps in the above method, and will not be repeated here. For the apparatus embodiments, since they basically correspond to the method embodiments, relevant parts can be referred to in the description of the method embodiments.
[0133] refer to Figure 6 , Figure 6 A symbol confusion device according to an embodiment of the present disclosure is illustrated schematically.
[0134] The aforementioned symbol confusion device may include:
[0135] The first generation module 601 is used to compile the source file corresponding to the original iOS application to generate a dSYM file and a relocatable target file corresponding to the original iOS application; wherein, the dSYM file includes a mapping relationship between a first memory address and a primitive symbol, the primitive symbol corresponds to the source code in the source file, the first memory address is used to indicate the memory space corresponding to the source code, and the relocatable target file includes the primitive symbol;
[0136] The obfuscation module 602 is used to parse the relocatable target file, determine the original symbols to be obfuscated from the original symbols included in the relocatable target file, and perform symbol obfuscation on the original symbols to be obfuscated to obtain the symbol-obfuscated relocatable target file.
[0137] The second generation module 603 is used to generate a hardened iOS application corresponding to the original iOS application based on the relocatable target file after symbol obfuscation.
[0138] Optionally, the obfuscation module 602 is specifically used for:
[0139] Based on the matching between the original symbols and sample symbols included in the relocatable target file, the original symbols to be obfuscated are determined; wherein, the sample symbols are derived from a symbol collection library, which is used to collect obfuscable original symbols in the original iOS application.
[0140] Optionally, the device further includes:
[0141] The third generation module 604 is used to generate the original iOS application based on the source file before compiling the source file corresponding to the original iOS application.
[0142] The filtering module 605 is used to decompile the original iOS application, obtain the original symbols in the original iOS application, and filter out the original symbols that are not allowed to be obfuscated from the obtained original symbols to obtain obfuscated original symbols.
[0143] The fourth generation module 606 is used to generate the symbol collection library based on the obfuscated original symbols.
[0144] Optionally, the original symbols to be obfuscated include one or more of the following: symbols corresponding to operating system code; symbols corresponding to code used to render the user interface; symbols corresponding to code used to generate interactive controls; symbols corresponding to code used for reflection calls; and symbols in a preset symbol blacklist.
[0145] Optionally, the filtering module 605 is specifically used for:
[0146] Using the class-dump tool, the original iOS application is decompiled to obtain the executable file corresponding to the original iOS application, and the original symbols in the original iOS application are extracted from the executable file.
[0147] Optionally, the device further includes:
[0148] The acquisition module 607 is used to acquire the crash log corresponding to the hardened iOS application in response to the crash of the hardened iOS application; wherein the crash log includes a second memory address corresponding to the exception code;
[0149] The determining module 608 is used to determine the first memory address in the dSYM file that matches the second memory address, and to determine the original symbol corresponding to the second memory address based on the mapping relationship in the dSYM file.
[0150] Optionally, the obfuscation module 602 is specifically used for:
[0151] Based on preset symbol obfuscation rules, the original symbols to be obfuscated are obfuscated, wherein the symbol obfuscation rules include any of the following:
[0152] A predetermined number of characters are selected from the original symbols to be confused, and the selected characters are transformed into random characters;
[0153] Calculate the hash value of the original symbol to be obfuscated, and determine the obfuscated symbol based on the calculated hash value.
[0154] Optionally, the second generation module 603 is specifically used for:
[0155] The obfuscated relocatable target file is linked with the static library file corresponding to the original iOS application, and the linked relocatable target file is packaged to generate a hardened iOS application corresponding to the original iOS application.
[0156] Optionally, the first generation module 601 is specifically used for:
[0157] Based on the Xcode integrated development environment, the source files corresponding to the original iOS application are compiled to generate a dSYM file and a relocatable target file corresponding to the original iOS application.
[0158] The process of generating a hardened iOS application corresponding to the original iOS application based on the relocatable target file after symbol obfuscation includes:
[0159] Based on the Xcode integrated development environment and the obfuscated relocatable target file, a hardened iOS application corresponding to the original iOS application is generated.
[0160] Optionally, the obfuscation module 602 is specifically used for:
[0161] Based on the iOS application hardening tool, the relocatable target file is parsed, the original symbols to be obfuscated are determined from the original symbols included in the relocatable target file, and the original symbols to be obfuscated are obfuscated to obtain the obfuscated relocatable target file; wherein, the iOS application hardening tool is independent of the Xcode integrated development environment.
[0162] Optionally, the obfuscation module 602 is specifically used for:
[0163] Based on the Mach-O file format and binary file read / write operations, the relocatable target file is parsed.
[0164] Exemplary computing device
[0165] Having described the methods, media, and apparatus of exemplary embodiments of this disclosure, the following references... Figure 7 A computing device for symbol obfuscation, according to an exemplary embodiment of the present disclosure, will be described.
[0166] Figure 7 The computing device 700 shown is merely an example and should not be construed as limiting the functionality and scope of use of the embodiments disclosed herein.
[0167] like Figure 7As shown, the computing device 700 is presented in the form of a general-purpose computing device. The components of the computing device 700 may include, but are not limited to: at least one processing unit 701, at least one storage unit 702, and a bus 703 connecting different system components (including the processing unit 701 and the storage unit 702).
[0168] The 703 bus includes a data bus, a control bus, and an address bus.
[0169] Storage unit 702 may include readable media in the form of volatile memory, such as random access memory (RAM) 7021 and / or cache memory 7022, and may further include readable media in the form of non-volatile memory, such as read-only memory (ROM) 7023.
[0170] Storage unit 702 may also include a program / utility 7025 having a set (at least one) program module 7024, such program module 7024 including but not limited to: operating system, one or more application programs, other program modules and program data, each or some combination of these examples may include an implementation of a network environment.
[0171] The computing device 700 can also communicate with one or more external devices 704 (such as a keyboard, pointing device, etc.).
[0172] This communication can be performed via input / output (I / O) interface 705. Furthermore, the computing device 700 can also communicate with one or more networks (e.g., local area networks (LANs), wide area networks (WANs), and / or public networks, such as the Internet) via network adapter 706. Figure 7 As shown, network adapter 706 communicates with other modules of computing device 700 via bus 703. It should be understood that, although not shown in the figure, other hardware and / or software modules may be used in conjunction with computing device 700, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems.
[0173] It should be noted that although several units / modules or sub-units / modules of the symbol confusion device have been mentioned in the detailed description above, this division is merely exemplary and not mandatory. In fact, according to embodiments of this disclosure, the features and functions of two or more units / modules described above can be embodied in one unit / module. Conversely, the features and functions of one unit / module described above can be further divided and embodied by multiple units / modules.
[0174] Furthermore, although the operations of the methods disclosed herein are described in a specific order in the accompanying drawings, this does not require or imply that these operations must be performed in that specific order, or that all of the operations shown must be performed to achieve the desired result. Additionally or alternatively, certain steps may be omitted, multiple steps may be combined into one step, and / or one step may be broken down into multiple steps.
[0175] While the spirit and principles of this disclosure have been described with reference to several specific embodiments, it should be understood that this disclosure is not limited to the disclosed specific embodiments, and the division of aspects does not imply that features in these aspects cannot be combined for benefit; such division is merely for convenience of expression. This disclosure is intended to cover various modifications and equivalent arrangements included within the spirit and scope of the appended claims.
Claims
1. A symbol obfuscation method, the method comprising: The source files corresponding to the original iOS application are compiled to generate a dSYM file and a relocatable target file corresponding to the original iOS application; wherein, the dSYM file includes a mapping relationship between a first memory address and a primitive symbol, the primitive symbol corresponds to the source code in the source file, the first memory address is used to indicate the memory space corresponding to the source code, and the relocatable target file includes the primitive symbol; The relocatable target file is parsed, the original symbols to be obfuscated are determined from the original symbols included in the relocatable target file, and the original symbols to be obfuscated are obfuscated to obtain the obfuscated relocatable target file. Based on the relocatable target file after symbol obfuscation, a hardened iOS application corresponding to the original iOS application is generated. In response to the crash of the hardened iOS application, a crash log corresponding to the hardened iOS application is obtained; wherein, the crash log includes a second memory address corresponding to the exception code; Determine the first memory address in the dSYM file that matches the second memory address, and based on the mapping relationship in the dSYM file, determine the original symbol corresponding to the second memory address.
2. The method according to claim 1, wherein determining the original symbol to be obfuscated from the original symbols included in the relocatable target file comprises: Based on the matching between the original symbols and sample symbols included in the relocatable target file, the original symbols to be obfuscated are determined; wherein, the sample symbols are derived from a symbol collection library, which is used to collect obfuscable original symbols in the original iOS application.
3. The method according to claim 2, wherein before compiling the source files corresponding to the original iOS application, the method further comprises: The original iOS application is generated based on the source file; The original iOS application is decompiled to obtain the original symbols in the original iOS application, and the original symbols that are not to be obfuscated are filtered out from the obtained original symbols to obtain obfuscated original symbols. The symbol collection library is generated based on the obfuscated original symbols.
4. The method according to claim 3, wherein the obfuscated original symbols include one or more of the following: symbols corresponding to operating system code; Symbols corresponding to the code used to render the user interface; Symbols corresponding to the code used to generate interactive controls; symbols corresponding to the code used for reflection calls; symbols in a preset symbol blacklist.
5. The method according to claim 3, wherein decompiling the original iOS application to obtain the original symbols in the original iOS application includes: Using the class-dump tool, the original iOS application is decompiled to obtain the executable file corresponding to the original iOS application, and the original symbols in the original iOS application are extracted from the executable file.
6. The method according to claim 1, wherein obfuscating the original symbol to be obfuscated comprises: Based on preset symbol obfuscation rules, the original symbols to be obfuscated are obfuscated, wherein the symbol obfuscation rules include any of the following: A predetermined number of characters are selected from the original symbols to be confused, and the selected characters are transformed into random characters; Calculate the hash value of the original symbol to be obfuscated, and determine the obfuscated symbol based on the calculated hash value.
7. The method according to claim 1, wherein generating a hardened iOS application corresponding to the original iOS application based on the symbolically obfuscated relocatable target file comprises: The obfuscated relocatable target file is linked with the static library file corresponding to the original iOS application, and the linked relocatable target file is packaged to generate a hardened iOS application corresponding to the original iOS application.
8. The method according to claim 1, wherein compiling the source file corresponding to the original iOS application to generate a dSYM file and a relocatable target file corresponding to the original iOS application comprises: Based on the Xcode integrated development environment, the source files corresponding to the original iOS application are compiled to generate a dSYM file and a relocatable target file corresponding to the original iOS application. The process of generating a hardened iOS application corresponding to the original iOS application based on the relocatable target file after symbol obfuscation includes: Based on the Xcode integrated development environment and the obfuscated relocatable target file, a hardened iOS application corresponding to the original iOS application is generated.
9. The method according to claim 8, wherein parsing the relocatable target file, determining the original symbols to be obfuscated from the original symbols included in the relocatable target file, and obfuscating the original symbols to be obfuscated to obtain the obfuscated relocatable target file, comprises: Based on the iOS application hardening tool, the relocatable target file is parsed, the original symbols to be obfuscated are determined from the original symbols included in the relocatable target file, and the original symbols to be obfuscated are obfuscated to obtain the obfuscated relocatable target file; wherein, the iOS application hardening tool is independent of the Xcode integrated development environment.
10. The method according to claim 1, wherein parsing the relocatable target file comprises: Based on the Mach-O file format and binary file read / write operations, the relocatable target file is parsed.
11. A symbol confusion device, the device comprising: The first generation module is used to compile the source file corresponding to the original iOS application to generate a dSYM file and a relocatable target file corresponding to the original iOS application; wherein, the dSYM file includes a mapping relationship between a first memory address and a primitive symbol, the primitive symbol corresponds to the source code in the source file, the first memory address is used to indicate the memory space corresponding to the source code, and the relocatable target file includes the primitive symbol; The obfuscation module is used to parse the relocatable target file, determine the original symbols to be obfuscated from the original symbols included in the relocatable target file, and perform symbol obfuscation on the original symbols to be obfuscated to obtain the symbol-obfuscated relocatable target file. The second generation module is used to generate a hardened iOS application corresponding to the original iOS application based on the relocatable target file after symbol obfuscation. The acquisition module is used to acquire the crash log corresponding to the hardened iOS application in response to the crash of the hardened iOS application; wherein the crash log includes a second memory address corresponding to the exception code; The determination module is used to determine the first memory address in the dSYM file that matches the second memory address, and to determine the original symbol corresponding to the second memory address based on the mapping relationship in the dSYM file.
12. The apparatus according to claim 11, wherein the obfuscation module is specifically used for: Based on the matching between the original symbols and sample symbols included in the relocatable target file, the original symbols to be obfuscated are determined; wherein, The sample symbols are sourced from a symbol collection library, which is used to collect obfuscated original symbols from the original iOS application.
13. The apparatus of claim 12, further comprising: The third generation module is used to generate the original iOS application based on the source files before compiling the source files corresponding to the original iOS application; The filtering module is used to decompile the original iOS application, obtain the original symbols in the original iOS application, and filter out the original symbols that are not allowed to be obfuscated from the obtained original symbols to obtain obfuscated original symbols. The fourth generation module is used to generate the symbol collection library based on the obfuscated original symbols.
14. The apparatus of claim 13, wherein the obfuscated original symbol comprises one or more of the following: a symbol corresponding to the code of the operating system; Symbols corresponding to the code used to render the user interface; Symbols corresponding to the code used to generate interactive controls; symbols corresponding to the code used for reflection calls; symbols in a preset symbol blacklist.
15. The apparatus according to claim 13, wherein the filtering module is specifically used for: Using the class-dump tool, the original iOS application is decompiled to obtain the executable file corresponding to the original iOS application, and the original symbols in the original iOS application are extracted from the executable file.
16. The apparatus according to claim 11, wherein the obfuscation module is specifically used for: Based on preset symbol obfuscation rules, the original symbols to be obfuscated are obfuscated, wherein the symbol obfuscation rules include any of the following: A predetermined number of characters are selected from the original symbols to be confused, and the selected characters are transformed into random characters; Calculate the hash value of the original symbol to be obfuscated, and determine the obfuscated symbol based on the calculated hash value.
17. The apparatus according to claim 11, wherein the second generating module is specifically used for: The obfuscated relocatable target file is linked with the static library file corresponding to the original iOS application, and the linked relocatable target file is packaged to generate a hardened iOS application corresponding to the original iOS application.
18. The apparatus according to claim 11, wherein the first generating module is specifically used for: Based on the Xcode integrated development environment, the source files corresponding to the original iOS application are compiled to generate a dSYM file and a relocatable target file corresponding to the original iOS application. The process of generating a hardened iOS application corresponding to the original iOS application based on the relocatable target file after symbol obfuscation includes: Based on the Xcode integrated development environment and the obfuscated relocatable target file, a hardened iOS application corresponding to the original iOS application is generated.
19. The apparatus according to claim 18, wherein the obfuscation module is specifically used for: Based on an iOS application hardening tool, the relocatable target file is parsed, the original symbols to be obfuscated are determined from the original symbols included in the relocatable target file, and the original symbols to be obfuscated are obfuscated to obtain the obfuscated relocatable target file; wherein, The iOS application hardening tool is independent of the Xcode integrated development environment.
20. The apparatus according to claim 11, wherein the obfuscation module is specifically used for: Based on the Mach-O file format and binary file read / write operations, the relocatable target file is parsed.
21. A medium having a computer program stored thereon, which, when executed by a processor, implements the method as described in any one of claims 1-10.
22. A computing device, comprising: processor; Memory used to store processor-executable programs; The processor implements the method as described in any one of claims 1-10 by running the executable program.
Citation Information
Patent Citations
Symbol confusion method and device
CN108416194A
Method and system for performing obfuscation protection on ios application program source code
CN110765425A