A PA signature context analysis method based on dynamic and static analysis

Through dynamic and static analysis method, the operands and types of PA signature context in the XNU kernel are extracted, which solves the problem of PA signature context analysis in the existing technology, realizes efficient reverse engineering analysis, and improves the security of the operating system.

CN116127532BActive Publication Date: 2025-05-16ZJU HANGZHOU GLOBAL SCI & TECH INNOVATION CENT
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202310075297.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-02-07
Publication Date
2025-05-16
Estimated Expiration
2043-02-07

AI Technical Summary

Technical Problem

The prior art is difficult to effectively analyze and understand the PA signature context used by Apple in the XNU kernel, especially when facing complex data flow propagation and hard-coded constant generation processes, there is a lack of effective reverse engineering analysis methods.

Method used

A PA signature context analysis method based on dynamic and static analysis is proposed. Through binary substitution and hypervisor exception processing, the operands of the pac instruction are extracted, and the PA signature context type is divided and analyzed based on shared features.

Benefits of technology

It realizes efficiently obtaining operands of pac instructions and accurately inferring the PA signature context type, fills the gap in reverse engineering analysis of PA signature context in the prior art, reduces labor costs, and improves the security of the operating system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116127532B_ABST
    Figure CN116127532B_ABST
Patent Text Reader

Abstract

The present invention discloses a PA signature context analysis method based on dynamic and static analysis. The method converts the instruction before the PAC instruction into an HVC exception instruction by binary replacement, adopts an exception handling function to receive the exception information corresponding to the HVC exception instruction, and updates the value of the register in the CPU while simulating the instruction before the corresponding PAC instruction, so as to efficiently obtain the operand of the PAC instruction; classifies the PAC instruction according to the PA signature context type, extracts the shared features of the PAC instruction set of the same type, and uses the shared features as the basis for judging the PA signature context type, so as to realize the reverse analysis of the PA signature context type.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The invention belongs to the field of operating system kernel security, and in particular relates to a PA signature context analysis method based on dynamic and static analysis. Background Art

[0002] Pointer Authentication (PA) is a hardware security feature introduced by the ARMv8.3 architecture in 2016 to protect pointer integrity. The basic idea is to sign the pointer and verify the signature to detect the integrity of the pointer before the pointer is used. In the program, pointers are used to access code or data, so PA can protect the integrity of code pointers and data pointers. Based on this hardware primitive, researchers can achieve fine-grained control flow integrity (CFI: Control Flow Integrity) and data flow integrity (DFI: Data Flow Integrity).

[0003] Although PA can effectively protect the integrity of pointers, how to implement PA and use it reasonably to improve system security is still a difficult problem. Therefore, among the processor vendors that follow the ARM specification, only Apple has implemented PA and deployed it on a large scale in commercial devices.

[0004] Apple implemented the operating system kernel CFI / DFI based on PA. When generating pac instructions, the software-defined PA signature context has a huge impact on the security of CFI / DFI. Previously, although researchers conducted security research on PA-based CFI in the XNU kernel, they did not analyze how the PA signature context is generated. At the same time, although Apple disclosed some information about PA signature context generation in 2019, most of the content is outdated for the latest CFI / DFI implementation. So far, researchers have not conducted in-depth reverse engineering analysis of the PA signature context in the latest XNU kernel.

[0005] Due to the huge impact of PA signature context on CFI / DFI security, it is crucial to analyze the PA signature context in the XNU kernel in order to evaluate the security of PA usage strategy in the XNU kernel. In the binary file, there are many hard-coded constants that are directly or indirectly used as PA signature context of pac instructions, but how these hard-coded constants are generated is very critical to analyzing the PA signature context.

[0006] In order to analyze the semantics of these hard-coded constants, it is necessary to extract the operands of all PAC instructions from the binary. However, it is very difficult to extract these details from the binary because the operands of some PAC instructions will pass through complex data propagation, that is, data flow propagation between functions. In addition, it is also very difficult to analyze the semantics of these hard-coded constants at the binary level because most of the hard-coded constants are generated by the compiler, but there is no information about the generation of these constants in the binary file.

[0007] Therefore, a method is needed to effectively extract the operands of the PAC instruction from the binary file and accurately infer the type of the PA signature context type based on this information. Summary of the invention

[0008] The present invention provides a PA signature context analysis method based on dynamic and static analysis, through which the operands of the PAC instruction can be obtained more efficiently and the type of the PA signature context can be inferred more accurately.

[0009] In order to achieve the above objectives, the present application embodiment proposes a PA signature context analysis method based on dynamic and static analysis, including:

[0010] Obtain multiple PAC instructions in a binary file. If the operand of the PAC instruction is propagated through the data flow between functions, replace the instruction before the PAC instruction with the HVC instruction by binary replacement. Execute the HVC instruction by the macOS operating system to obtain exception information, and pass the exception information to the hypervisor. Simulate the operation process of the instruction before the corresponding PAC instruction by the exception handling function of the hypervisor, update the value of the register in the CPU at the same time, and call the updated register value by the hook function of the hypervisor to obtain the operand of the PAC instruction. The operand of the PAC instruction includes the pointer value and the hard-coded constant value of the PAC instruction.

[0011] Obtaining a PA signature context type, wherein the PA signature context type is used to classify multiple PAC instructions into three types of PAC instruction sets, including a PAC instruction set containing only hard-coded constants, a PAC instruction set containing only addresses, and a PAC instruction set containing hard-coded constants and addresses;

[0012] The same pac instruction feature is extracted from each category pac instruction set as a shared feature, and the shared feature is used to infer the PA signature context type. The pac instruction feature is obtained through open source code based on the pointer value of the pac instruction.

[0013] The PA signature context analysis method based on dynamic and static analysis provided in the present application also includes dividing the PAC instruction set containing only hard-coded constants based on different hard-coded constant values ​​to obtain multiple PAC instruction subsets containing only coded constants, and extracting the same PAC instruction features in each PAC instruction subset containing only coded constants as the first shared feature, wherein the first shared feature is used to infer the hard-coded constant value and its generation method when the PA signature context type is a hard-coded constant type.

[0014] The PA signature context analysis method based on dynamic and static analysis provided in the present application also includes dividing the hard-coded constant plus address PAC instruction set based on different hard-coded constant values ​​to obtain multiple hard-coded constant plus address PAC instruction subsets, and extracting the same PAC instruction features in each hard-coded constant plus address PAC instruction subset as the second shared feature, and the second shared feature is used to infer the hard-coded constant value and its generation method when the PA signature context type is a hard-coded constant plus address type.

[0015] Optionally, the specific steps of inferring the PA signature context type based on the shared PAC instruction feature are:

[0016] The same PAC instruction feature extracted from the PAC instruction set containing only hard-coded constants is used as the third shared feature. Based on the third shared feature, it can be inferred that the PA signature context type is a hard-coded constant type.

[0017] The same pac instruction feature extracted from the pac instruction set containing only addresses is used as the fourth shared feature. Based on the fourth shared feature, it can be inferred that the PA signature context type is an address type.

[0018] The pac instruction feature extracted from the hard-coded constant plus address pac instruction set is used as the fifth shared feature. Based on the fifth shared feature, it can be inferred that the PA signature context type is a hard-coded constant plus address type.

[0019] Optionally, the specific steps of obtaining the PAC instruction feature from the PAC instruction are: extracting the corresponding function name from the XNU kernel binary file based on the pointer value of the PAC instruction, and obtaining the corresponding PAC instruction feature through the open source code based on the function name.

[0020] Optionally, the PAC instruction features include pointer definition, parameter and return address types, function name, and base class.

[0021] Optionally, the PA signature context type is used to divide multiple PAC instructions into three types of PAC instruction sets in the following specific steps:

[0022] Filter PAC instructions that match the hard-coded constant type from multiple PAC instructions to obtain a PAC instruction set that only contains hard-coded constants;

[0023] Filter the PAC instructions that match the address type from multiple PAC instructions to obtain a PAC instruction set that only contains addresses;

[0024] The PAC instructions that meet the hard-coded constant plus address type are screened from multiple PAC instructions to obtain a hard-coded constant plus address PAC instruction set.

[0025] The PA signature context analysis method based on dynamic and static analysis provided by the present application is characterized in that it also includes, if the operand of the pac instruction is propagated through the internal data flow of the function, extracting the operand of the pac instruction through an intra-process analysis method.

[0026] Optionally, the hypervisor runs at the EL2 exception level of the AppleM1 chip.

[0027] Optionally, the macOS operating system is macOS based on the ARM instruction set, running at the EL1 exception level of the AppleM1 chip.

[0028] Compared with the prior art, the present invention has the following beneficial effects:

[0029] (1) When faced with complex data flow propagation, the present application proposes to convert the instructions before the PAC instruction into the HVC exception instruction through binary replacement, adopt an exception handling function to receive the exception information corresponding to the HVC exception instruction, and simulate the instructions before the corresponding PAC instruction while updating the value of the register in the CPU, so as to efficiently obtain the operands of the PAC instruction; classify the PAC instruction according to the PA signature context type, and extract the shared features of the PAC instruction set of the same type, and use the shared features as the basis for judging the PA signature context type, so as to realize the reverse analysis of the PA signature context type.

[0030] (2) The present application also utilizes the hard-coded constant values ​​in the PAC operands to further subdivide the PAC instruction set containing only hard-coded constants and the PAC instruction set containing hard-coded constants plus addresses, respectively, extracts the shared features in the subdivided subsets, and uses the shared features as the hard-coded constant values ​​and their generation methods when judging whether the PA signature context type is a hard-coded constant plus address type or a hard-coded constant type, thereby realizing the reverse analysis of the semantics of the hard-coded constants in the PA signature context. BRIEF DESCRIPTION OF THE DRAWINGS

[0031] Figure 1 A flowchart of a PA signature context analysis method based on dynamic and static analysis provided in an embodiment of the present application;

[0032] Figure 2 A flowchart of a PA signature context analysis method based on dynamic and static analysis provided in an embodiment of the present application;

[0033] Figure 3 A flowchart of obtaining the operands of a PAC instruction when the operands are propagated through a complex stream data volume is provided for an embodiment of the present application. DETAILED DESCRIPTION

[0034] The following will be combined with the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. The components of the embodiments of the present application usually described and shown in the drawings here can be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of the present application provided in the drawings is not intended to limit the scope of the application claimed for protection, but merely represents the selected embodiments of the present application. Based on the embodiments of the present application, all other embodiments obtained by those skilled in the art without making creative work belong to the scope of protection of the present application.

[0035] In order to efficiently obtain the operands of the PAC instruction, and to obtain the basis for reverse analysis of the PA signature context type and the hard-coded constant value under the PA signature context type and its generation method based on the generated operands, the present application provides a PA signature context analysis method based on dynamic and static analysis, specifically, Figure 1 , Figure 2 As shown, the analysis method includes:

[0036] S100, collecting multiple PAC instructions in the binary file, and obtaining operands of the PAC instructions through the exception handling function and hook function of the hypervisor.

[0037] Here, if the operand of the PAC instruction is propagated through the data flow between functions, that is, complex data propagation, the operand of the PAC instruction is obtained through the exception handling function and hook function of the hypervisor, such as Figure 3 As shown, the specific steps are:

[0038] S110, replacing the instruction before the pac instruction with the hvc instruction through binary replacement.

[0039] In a specific embodiment, after obtaining the PAC instruction, at least one instruction before the PAC instruction is saved, and at least one instruction before the saved PAC instruction is converted into an HVC instruction through binary replacement, so that the operating system can request a hypervisor service when executing the HVC instruction.

[0040] S120. Execute the hvc instruction through the macOS operating system to obtain exception information, and transmit the exception information to the hypervisor.

[0041] In a specific embodiment, a macOS operating system based on the ARM instruction set is run on the EL1 exception level of the Apple M1 chip, and the hvc instruction is executed by the macOS operating system to generate an exception and record the exception information. Based on the hvc instruction, the macOS operating system passes the exception information to the hypervisor running on the EL2 exception level of the Apple M1 chip, and the hypervisor calls the exception handling function to handle the exception information.

[0042] S130, simulating the instructions before the corresponding PAC instruction through the exception handling function of the hypervisor, and updating the value of the register in the CPU at the same time.

[0043] In a specific embodiment, the process of the exception handling function processing the exception information is to simulate the operation process of the instruction before the PAC instruction corresponding to the exception information, and simultaneously update the value of the register in the CPU during the simulation process to ensure that the value of the register in the CPU is the value before the PAC instruction is executed, so that the operand corresponding to the operation process before the PAC instruction is executed can be accurately stored in the CPU.

[0044] S140, calling the updated register value through the hypervisor hook function to obtain the operand of the PAC instruction.

[0045] In a specific embodiment, a hook function is set in the hypervisor, and the value of the updated register is called through the set hook function, and the value of the updated register is the operand of the pac instruction. The operand includes a pointer value and a context value, and the context value includes a hard-coded constant value.

[0046] The present invention also provides that if the operand of the PAC instruction is propagated through the internal data flow of the function, the operand of the PAC instruction is extracted through an intra-procedural analysis method.

[0047] In a preferred embodiment, the in-process analysis tracks the operand registers of the PAC instruction, filters the instructions before the PAC instruction in the function that will affect the operand registers of the PAC instruction, reversely deduce the source of the operand registers, and finally identifies the destination pointer and PA signature context value of the PAC instruction, that is, obtains the operand of the PAC instruction.

[0048] S200, dividing multiple PAC instructions into three types of PAC instruction sets based on PA signature context types.

[0049] Here, the PA signature context types include hard-coded constant types, address types, and hard-coded constant plus address types; PAC instructions that meet the hard-coded constant type are screened from multiple PAC instructions to obtain a PAC instruction set that only contains hard-coded constants, and the PAC instructions that only contain hard-coded constants only contain hard-coded constants and do not contain addresses; PAC instructions that meet the address type are screened from multiple PAC instructions to obtain a PAC instruction set that only contains addresses, and the PAC instructions that only contain addresses only contain addresses and do not contain hard-coded constants; PAC instructions that meet the hard-coded constant plus address type are screened from multiple PAC instructions to obtain a hard-coded constant plus address PAC instruction set, and the hard-coded constant plus address PAC instruction contains both hard-coded constants and addresses.

[0050] S300, extracting the same PAC instruction features from each category of PAC instruction set as shared features, and using the shared features to infer PA signature context types.

[0051] The present application provides specific steps for obtaining PAC instruction features from PAC instructions: extracting the corresponding function name from the XNU kernel binary file based on the pointer value of the PAC instruction, and obtaining the corresponding PAC instruction features through open source code based on the function name, wherein the PAC instruction features include parameter type, parameter order, number of parameters, return value type, function name, data type, variable name, pointer variable type (C++ class member variable or virtual function pointer) and its base class.

[0052] In a specific embodiment, the same PAC instruction feature extracted from the PAC instruction set containing only hard-coded constants is used as the third shared feature, and based on the third shared feature, it can be inferred that the PA signature context type is a hard-coded constant type.

[0053] In a specific embodiment, the third shared feature is a C++ class member function pointer. When a pointer is a member variable function pointer in a C++ class, the PA signature context type used by the XNU kernel when signing the pointer is a hard-coded constant type.

[0054] In a specific embodiment, the same pac instruction feature extracted from the pac instruction set containing only addresses is used as the fourth shared feature, and based on the fourth shared feature, it can be inferred that the PA signature context type is an address type.

[0055] In a specific embodiment, the fourth shared feature includes a PPL processing function and a Block function. When a function pointer points to a PPL processing function or a Block function, the PA signature context type used by the XNU kernel when signing the pointer is an address type.

[0056] In a specific embodiment, a pac instruction feature extracted from a hard-coded constant plus address pac instruction set is used as the fifth shared feature, and based on the fifth shared feature, it can be inferred that the PA signature context type is a hard-coded constant plus address type.

[0057] In a specific embodiment, the fifth shared feature includes a C++ class virtual function pointer. When a pointer is a virtual function pointer in a C++ class, the PA signature context type used by the XNU kernel when signing the pointer is a hard-coded constant plus address type.

[0058] In a preferred embodiment, for the present application, the following steps are used to infer the hard-coded constant value and its generation method when the PA signature context type is a hard-coded constant type. Specifically, the specific steps of the inference method are as follows:

[0059] Based on different hard-coded constant values, the PAC instruction set containing only hard-coded constants is divided to obtain multiple PAC instruction subsets containing only coded constants, and the same PAC instruction features of each PAC instruction subset containing only coded constants are extracted as the first shared feature, and the first shared feature is used to infer the hard-coded constant value and its generation method when the PA signature context type is a hard-coded constant type.

[0060] In a specific embodiment, the first shared feature includes: function type, function name or data variable name, and the definition of the function type includes: number of parameters, parameter types, parameter order and return value type. By observing the number of parameters, parameter types, parameter order and return value type of the pointers in the pac instruction subset, when the shared characteristics defined by the function pointers in the set are only the number of parameters, parameter types, parameter order and return value type, it can be determined that the hard-coded constant value is calculated according to the number of parameters, parameter types, parameter order and return value type during the compilation process.

[0061] In a preferred embodiment, for the present application, the following steps are used to infer the hard-coded constant value and its generation method when the PA signature context type is a hard-coded constant plus an address type. Specifically, the specific steps of the inference method are as follows:

[0062] Based on different hard-coded constant values, the hard-coded constant plus address PAC instruction set is divided to obtain multiple hard-coded constant plus address PAC instruction subsets, and the same PAC instruction features of each hard-coded constant plus address PAC instruction subset are extracted as the second shared feature, and the second shared feature is used to infer the hard-coded constant value and its generation method when the PA signature context type is a hard-coded constant plus address type.

[0063] In a specific embodiment, the second shared feature is the base class, that is, when the shared characteristics defined by the pointers in the pac instruction subset only belong to the same base class, it can be determined that the hard-coded constant value is calculated according to the base class during the compilation process.

[0064] The method of the present invention aims at analyzing the closed-source problem of PA signature context in XNU kernel operating system, and proposes a set of PA signature context reverse engineering analysis solutions based on dynamic and static analysis, and has low labor cost. The present invention fills the gap of the existing PA signature context reverse engineering analysis, can further analyze the generation process of PA signature context, promote researchers' understanding of PA signature context, so as to further improve the security of operating system.

Claims

1. A PA signature context analysis method based on dynamic and static analysis, characterized in that: include: Obtain multiple PAC instructions in a binary file. If the operand of the PAC instruction is propagated through the data flow between functions, replace the instruction before the PAC instruction with the HVC instruction by binary replacement. Execute the HVC instruction by the macOS operating system to obtain exception information, and pass the exception information to the hypervisor. Simulate the operation process of the instruction before the corresponding PAC instruction by the exception handling function of the hypervisor, update the value of the register in the CPU at the same time, and call the updated register value by the hook function of the hypervisor to obtain the operand of the PAC instruction. The operand of the PAC instruction includes the pointer value and the hard-coded constant value of the PAC instruction. Obtaining a PA signature context type, wherein the PA signature context type is used to classify multiple PAC instructions into three types of PAC instruction sets, including a PAC instruction set containing only hard-coded constants, a PAC instruction set containing only addresses, and a PAC instruction set containing hard-coded constants and addresses; The same pac instruction feature is extracted from each category pac instruction set as a shared feature, and the shared feature is used to infer the PA signature context type. The pac instruction feature is obtained through open source code based on the pointer value of the pac instruction.

2. The PA signature context analysis method based on dynamic and static analysis according to claim 1 is characterized in that: It also includes, based on different hard-coded constant values, dividing the PAC instruction set containing only hard-coded constants to obtain multiple PAC instruction subsets containing only hard-coded constants, extracting the same PAC instruction features in each PAC instruction subset containing only hard-coded constants as the first shared feature, and the first shared feature is used to infer the hard-coded constant value and its generation method when the PA signature context type is a hard-coded constant type.

3. The PA signature context analysis method based on dynamic and static analysis according to claim 1 is characterized in that: It also includes dividing the hard-coded constant plus address PAC instruction set based on different hard-coded constant values ​​to obtain multiple hard-coded constant plus address PAC instruction subsets, and extracting the same PAC instruction feature in each hard-coded constant plus address PAC instruction subset as a second shared feature, wherein the second shared feature is used to infer the hard-coded constant value and its generation method when the PA signature context type is a hard-coded constant plus address type.

4. The PA signature context analysis method based on dynamic and static analysis according to claim 1 is characterized in that: The specific steps of inferring the PA signature context type based on the shared PAC instruction feature are as follows: The same PAC instruction feature extracted from the PAC instruction set containing only hard-coded constants is used as the third shared feature. Based on the third shared feature, it can be inferred that the PA signature context type is a hard-coded constant type. The same pac instruction feature extracted from the pac instruction set containing only addresses is used as the fourth shared feature. Based on the fourth shared feature, it can be inferred that the PA signature context type is an address type. The pac instruction feature extracted from the hard-coded constant plus address pac instruction set is used as the fifth shared feature. Based on the fifth shared feature, it can be inferred that the PA signature context type is a hard-coded constant plus address type.

5. The PA signature context analysis method based on dynamic and static analysis according to any one of claims 1 to 4, characterized in that: The specific steps of obtaining the PAC instruction feature from the PAC instruction are: extracting the corresponding function name from the XNU kernel binary file based on the pointer value of the PAC instruction, and obtaining the corresponding PAC instruction feature through the open source code based on the function name.

6. The PA signature context analysis method based on dynamic and static analysis according to claim 5 is characterized in that: The PAC instruction features include parameter type, parameter order, number of parameters, return value type, function name, data type, variable name, pointer variable type and its base class.

7. The PA signature context analysis method based on dynamic and static analysis according to claim 1 is characterized in that: The PA signature context type is used to divide multiple PAC instructions into three types of PAC instruction sets in the following specific steps: Filter PAC instructions that match the hard-coded constant type from multiple PAC instructions to obtain a PAC instruction set that only contains hard-coded constants; Filter the PAC instructions that match the address type from multiple PAC instructions to obtain a PAC instruction set that only contains addresses; The PAC instructions that meet the hard-coded constant plus address type are screened from multiple PAC instructions to obtain a hard-coded constant plus address PAC instruction set.

8. The PA signature context analysis method based on dynamic and static analysis according to claim 1 is characterized in that: The method also includes extracting the operand of the PAC instruction by an intra-procedural analysis method if the operand of the PAC instruction is propagated through an internal data flow of a function.

9. The PA signature context analysis method based on dynamic and static analysis according to claim 1 is characterized in that: The hypervisor runs at the EL2 exception level of the Apple M1 chip.

10. The PA signature context analysis method based on dynamic and static analysis according to claim 1, characterized in that: The macOS operating system is macOS based on the ARM instruction set, running at the EL1 exception level of the Apple M1 chip.