Controllable Data Obfuscation Method and System Based on Object Mapping

Through the controllable data obfuscation method based on object mapping, the data in the program is encapsulated and obfuscated by class inheritance, derivation and polymorphism, solving the problem of poor performance of traditional code obfuscating technology in reverse analysis, achieving higher data security and flexible obfuscation strength.

CN116226799BActive Publication Date: 2025-06-17Chinese People's Liberation Army Cyberspace Force Information Engineering University
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211581541.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-05
Publication Date
2025-06-17
Estimated Expiration
2042-12-05

AI Technical Summary

Technical Problem

Traditional code obfuscation technology is not effective when facing reverse analysis and has a large operating overhead, making it difficult to adapt to the needs of software protection.

Method used

Using a controllable data obfuscation method based on object mapping, by converting the target program into an intermediate language, mining data reference relationships and execution path information, building a data semantic association graph, and using class inheritance, derivation and polymorphism to encapsulate and obfuscate key data.

Benefits of technology

It effectively enhances the program's anti-reverse analysis ability, destroys the original data flow structure, improves the data security of code and software, and has scalability in obfuscation strength.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116226799B_ABST
    Figure CN116226799B_ABST
Patent Text Reader

Abstract

The present invention belongs to the field of Internet technologies, and particularly relates to a controllable data obfuscation method and system based on object mapping. The target program is transformed into an intermediate language, data reference relationships and execution path information in the program are mined, and a data semantic association graph of the target program is constructed. The data semantic association graph is traversed, and key data is stripped from the program structure and encapsulated into data classes according to the data semantic information. The inheritance, derivation, and polymorphism of the classes are used to obfuscate the program data flow structure, so that the direct access to data in the program is converted into indirect access to data through classes. The present invention effectively protects the program data semantic information, makes the program data access more complex, and enhances the anti-reverse analysis ability of the program; through the class derivation strategy and polymorphism mechanism, the program data flow can be arbitrarily complex, and the obfuscation strength is scalable; by adding various security functions to the encapsulated and derived classes to achieve specific data protection purposes, the obfuscation method is extensible.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of Internet technologies, and particularly relates to a controllable data obfuscation method and system based on object mapping. Background Art

[0002] Code obfuscation is an adversarial technology proposed for software reverse engineering. By performing equivalent transformations on the code structure, it can effectively prevent reverse analysts from understanding the code logic and increase the reverse engineering cost. However, with the rapid development of reverse engineering technologies in recent years, the effectiveness of traditional code obfuscation technologies is continuously weakening. How to construct a more adversarial code obfuscation algorithm has become an urgent problem to be solved in the academic community. Control flow and data flow are the main bases for program analysis. The purpose of control flow analysis is to construct a control flow graph expressing the program structure based on the jump statements in the program. Data flow analysis can obtain data flow results of interest through iterative analysis on the basis of the control flow graph.

[0003] Currently, relatively more research has been conducted on control flow obfuscation in code obfuscation, while the research on software data flow protection is not extensive and in-depth. Data is the basis of data flow analysis. There are many data-related structures in a program. For example, arrays, structures, strings, etc. contain important semantic information. Changing the conventional usage mode and the structural characteristics of the data itself can effectively increase the difficulty of data flow reverse analysis and achieve the protection of the program at the data flow level. In software control flow protection, the opaque predicate obfuscation algorithm and the flattened control flow obfuscation algorithm are two important code protection methods. The opaque predicate obfuscation algorithm constructs an opaque predicate that is always true or always false, adding a pseudo-branch to the program, or constructs an opaque predicate that can be true or false, adding equivalent basic blocks to the program to make the structure of the control flow more complex. The control flow flattening algorithm flattens the original nested loops and conditional transfer statements in the program and connects them through switch statements, so that each basic block loses the basic information clearly recording the control flow direction, thus counteracting reverse analysis.

[0004] In software data protection, the aim is to obfuscate data and hide the data structure of a program. A common data obfuscation method is to encrypt strings and store them statically in the program, and decrypt them dynamically when using the strings. For variables in the program, they are converted into complex boolean arithmetic expressions and restored dynamically at runtime. The converted arithmetic expressions are difficult to simplify back to the original form. However, the above obfuscation methods only focus on protecting the control flow or the data structure, and do not provide unified protection for the control flow and data. Therefore, the development of automated software reverse engineering technology has severely impacted the effectiveness of existing data flow protection. Research shows that taint analysis, symbolic execution, and program synthesis are widely used to eliminate code obfuscation. Taint analysis traces and marks all dependent variables through input and output taint sources, simplifies the control structure of the code, and obtains the core semantics of the program. Symbolic execution summarizes assembly code algebraically, simplifies complex assembly code, and can effectively resist existing data flow obfuscation methods. Compared with the above two, program synthesis does not rely on syntactic analysis, runs at the semantic level, treats the code as a black box, and attempts to reconstruct the original code based on observable behavior. Automated software reverse engineering technology effectively eliminates the obstacles to program cracking by existing obfuscation algorithms, making it difficult for the software protection industry to achieve further breakthroughs. Obviously, the current code obfuscation algorithms are difficult to meet the needs of software protection, and the innovation of algorithms is particularly important. Therefore, it has become an urgent problem to propose a data flow protection scheme with higher security. Summary of the Invention

[0005] To this end, the present invention provides a controllable data obfuscation method and system based on object mapping, which solves problems such as low obfuscation intensity, large running overhead, and obvious obfuscation features in traditional code obfuscation schemes, and effectively improves the data security of code and software.

[0006] According to the design scheme provided by the present invention, a controllable data obfuscation method based on object mapping is provided, which includes the following steps: converting the target program into an intermediate language, mining the data reference relationships and execution path information in the program, and constructing a data semantic association graph of the target program;

[0007] Traverse the data semantic association graph, strip key data from the program according to the data semantic information and encapsulate it into a data class, and use inheritance, derivation, and polymorphism of the class to obfuscate the data flow structure of the program, so that the direct access to data in the program is converted into indirect access to data through the class.

[0008] As the controllable data obfuscation method based on object mapping in the present invention, further, to construct a data semantic association graph, the program first converts the program into LLVM intermediate language, analyzes the control flow and data flow of the program at the intermediate language level, and then mines the existing data reference relationships in the program; then, constructs a data semantic association graph based on the existing data reference relationships.

[0009] As the controllable data obfuscation method based on object mapping in the present invention, further, in data class encapsulation, key data is stripped from the program and encapsulated into a data class according to data semantic information. Guided by data semantic entropy, all data in the program is analyzed to mine the key data program in the program, and the key data is encapsulated and integrated into a data class.

[0010] As the controllable data obfuscation method based on object mapping in the present invention, further, guided by data semantic entropy, the process of obtaining data semantic entropy is as follows: First, the reference relationships between all data are obtained according to the data semantic association graph, and the probability of obtaining semantic information from the data is obtained according to the reference relationships; then, the probability of obtaining semantic information from the data is used, and combined with the program global data and reference relationships to obtain data semantic entropy.

[0011] As the controllable data obfuscation method based on object mapping in the present invention, further, the program data flow structure is obfuscated by using class inheritance, derivation, and polymorphism, including: using the class derivation strategy to generate the same subclass for unrelated data in the program, so that the data access of unrelated functions accesses the same subclass, and the data access of the same function accesses different subclasses. The multiple derived subclasses are used as the data access interfaces during program execution; and the program key data is hidden in the class structure data access by using the polymorphism mechanism.

[0012] As the controllable data obfuscation method based on object mapping in the present invention, further, the diversified derivation strategy includes: adding security enhancement functions to different subclasses, where the security enhancement functions include but are not limited to: string encryption functions, data complex boolean operation functions, variable splitting and reconstruction functions.

[0013] As the controllable data obfuscation method based on object mapping in the present invention, further, the program key data is hidden in the class structure data access by using the polymorphism mechanism, including: using static polymorphism and / or dynamic polymorphism to hide the executed data access by calling the function object type, where static polymorphism uses function overloading to implement the hiding of the data scheme, and dynamic polymorphism implements the hiding of data access by defining virtual functions.

[0014] Further, the present invention also provides a controllable data obfuscation system based on object mapping, including: a data analysis module and a data obfuscation module, where the data analysis module is used to transform the target program into an intermediate language, mine the data reference relationships and execution path information in the program, and construct a data semantic association graph of the target program;

[0015] A data obfuscation module is used to traverse the data semantic association graph, strip key data from the program according to the data semantic information and encapsulate it into a data class, and utilize the inheritance, derivation, and polymorphism of the class to obfuscate the program data flow structure, so that the direct access to data in the program is converted into indirect access to data through the class.

[0016] Advantages of the present invention:

[0017] By protecting the data flow information in the program, the present invention converts and obfuscates the data access method in the program by using the mechanisms of class encapsulation, inheritance, and polymorphism, destroys the original data flow structure of the program, and enhances the anti-reverse analysis ability of the program; and through the application of the derivation strategy and polymorphism mechanism, the program data flow can be arbitrarily complex, and the obfuscation strength is scalable; by adding various security functions to the encapsulated and derived classes to achieve the required data protection purpose, the obfuscation method is extensible. Description of the drawings

[0018] Figure 1 Schematic diagram of the controllable data obfuscation process based on object mapping in the embodiment;

[0019] Figure 2 Schematic diagram of the data semantic association graph in the embodiment;

[0020] Figure 3 Schematic diagram of the controllable data obfuscation principle framework in the embodiment;

[0021] Figure 4 Schematic diagram of the data flow obfuscation process in the embodiment;

[0022] Figure 5 Schematic diagram of the code conversion example in the embodiment. Specific implementation manners

[0023] To make the purpose, technical solutions, and advantages of the present invention clearer and more understandable, the present invention will be further described in detail below in conjunction with the drawings and technical solutions.

[0024] Traditional obfuscation methods mainly increase the complexity of the control flow to improve the program complexity and resist reverse analysis. The obfuscation strength of this method depends on the complexity of the code control flow structure, and it is difficult to cope with the increasingly efficient automated analysis technology. Introducing complex control flows in the program will lead to a serious reduction in the code running efficiency and obvious obfuscation features, which do not meet the needs of the software industry development. In the embodiments of this case, refer to Figure 1 as shown, a controllable data obfuscation method based on object mapping is provided, including:

[0025] S101. Convert the target program into an intermediate language, mine the data reference relationship and execution path information in the program, and construct the data semantic association graph of the target program;

[0026] S102. Traverse the data semantic association graph, extract key data from the program according to the data semantic information and encapsulate it into data classes, use class inheritance, derivation and polymorphism to confuse the program data flow structure, and convert direct access to data in the program into indirect access to data through classes.

[0027] In the embodiment of this case, starting from the semantic level of program data, based on control flow analysis and data flow analysis, automatic data flow obfuscation is achieved through data semantic association diagram, which effectively solves the problem that traditional obfuscation methods are difficult to resist automatic analysis methods. In addition, the program size and execution efficiency have not changed significantly after the algorithm is applied, which has good applicability.

[0028] As a preferred embodiment, further, the target program is converted into an intermediate language, and a data semantic association graph of the target program is constructed, including: first, the program is converted into an intermediate language, and the data structure and dependency relationship existing in the program are mined by analyzing the control flow and data flow in the program; then, a data semantic association graph is constructed based on the existing data structure and dependency relationship.

[0029] The data semantic association diagram uses data relationships to express program semantic information. Figure 2 The construction process of the data semantic association graph representing the program converts the data into nodes in the graph, and the reference relationship between the data is abstracted as directed edges in the graph. There are many reference relationships between data, such as direct reference relationships between data, indirect reference relationships based on multi-level variables, and indirect reference relationships based on function transfer. The data semantic association graph abstracts all the data in the program into the relationship between edges and nodes in the graph, providing a basis for the subsequent calculation of data semantic entropy.

[0030] The LLVM framework is an extensible program optimization platform that provides an API for analyzing and modifying intermediate language code. Figure 3 As shown, in the embodiment of this case, an obfuscation system is implemented on the basis of LLVM to automatically obfuscate the data flow of the program. The obfuscation process is divided into three stages: the front-end code compilation stage, the analysis and conversion stage, and the binary file generation stage. In the front-end code compilation stage, the C / C++ source program can be used as input, and the output is a binary file after data flow obfuscation processing. Each C / C++ source code file of the program is compiled by the LLVM front-end (that is, Clang can be used as the front-end) to generate a corresponding intermediate language file (IR). All generated .bc intermediate language files can be merged into one Orig.bc file through llvm-link.

[0031] As the controllable data obfuscation method based on object mapping in the present invention, further, key data is stripped from the program according to data semantic information and encapsulated into a data class. Guided by data semantic entropy, the data of all functions in the program is analyzed, all data types are extracted, the extracted data types are used as key data to be stripped from the program, and the key data is encapsulated and integrated into a data class, providing a basis for subsequent data obfuscation protection based on class features.

[0032] The reference relationship between all data obtained according to the data semantic association graph is n, and the number of times data i is referenced in the association graph is l i , with a direct reference relationship of 1, and the indirect reference relationship increases by 1 for each transit reference. The probability P(A i ) is expressed as:

[0033]

[0034] Therefore, the more complex the reference relationship of data i is, the lower the probability of obtaining semantic information from it. Combining the global data of the program and the reference relationship, the calculation formula of data semantic entropy is expressed as:

[0035]

[0036] Obviously, the larger the data semantic entropy value is, the more complex the program is, the more complex the data reference relationship is, and the greater the difficulty of reverse analysis of the program is.

[0037] Perform data flow obfuscation processing on the intermediate code, mainly for program analysis, mining the data reference relationship and execution path information of the program, and applying the C++ object-oriented mechanism to protect the data flow. Entropy is a measure of information. Since the information theory was proposed, the information theory based on Shannon entropy has always been an important tool. In the Chinese semantic space, semantic entropy can be used as a measure of semantics. In the embodiments of this case, guided by the data semantic entropy value, key data is stripped from the original code structure and integrated into a unified data class.

[0038] Further, use inheritance, derivation, and polymorphism of classes to obfuscate the program data flow structure, including: using the class derivation strategy to generate the same subclass for unrelated data in the program, accessing the same subclass for data of unrelated functions, and accessing different subclasses for data of the same function. Use the multiple subclasses derived as the data access interface during program execution to increase the complexity of data access; and use the polymorphism mechanism to hide the key data of the program in the data access of the class structure. Among them, the diversified derivation strategy includes: adding security enhancement functions to different subclasses, where the security enhancement functions include but are not limited to: string encryption functions, data complex boolean operation functions, variable splitting and reconstruction functions

[0039] The purpose of class encapsulation is to protect or prevent code (data) from being destroyed, protect the attributes of members, and prevent programs outside the class from directly accessing and modifying them, thereby achieving the purpose of hiding methods. Figure 4 As shown in step 1 in the figure, analyze the data used in all functions in the program and extract all the used data types, including basic data structure units such as integers, characters and structures. Encapsulate and integrate the above data types into a large data class "Data Class". At this point, all data access in the program will be accessed through the same data class, and the original direct use of data is changed to indirect access through the class. The encapsulation of the data class integrates the originally unrelated data, and the unrelated data is accessed externally through a unified class, which blurs the relationship between the original data, increases the coupling between unrelated data, and increases the difficulty of data flow analysis.

[0040] Class derivation and inheritance allow the derived subclass to use the member functions and member variables of the parent class, and the subclass can also add unique function functions to complete the functions required by the subclass. Figure 4 As shown in step 2, based on the data class encapsulation, in the embodiment of this case, a derivation strategy can be introduced in the process of deriving subclasses from the data class, and the data of the same function can be derived into different subclasses, and the same subclass has data used by different functions. On the other hand, different security enhancement functions can be added to different subclasses to further protect the data. When the program is executed, the use of the data by the function will be indirectly obtained by accessing different subclasses, and the security of the data will be significantly enhanced.

[0041] As a preferred embodiment, further, a polymorphism mechanism is used to hide key program data in class structure data access, including: using static polymorphism and / or dynamic polymorphism to hide the data access process, wherein static polymorphism uses function overloading to achieve data access hiding, and dynamic polymorphism achieves data access hiding by defining virtual functions.

[0042] When the C++ polymorphism mechanism is used, different functions can be executed according to the object type of the calling function when calling a member function. C++ allows the use of two polymorphism mechanisms: static polymorphism and dynamic polymorphism. The former is implemented through function overloading. The function overloading mechanism can create operator overload functions, such as expanding a one-dimensional array to a two-dimensional array, or converting a two-dimensional array into a one-dimensional array, and operating the converted array through operator overloading, but in the code it is shown as access to arrays of different dimensions. The latter dynamic polymorphism is implemented through virtual functions. The virtual function defined by the parent class can be overwritten in the child class. When the child class redefines the virtual function of the parent class, the parent class pointer dynamically calls the child class function instead of the parent class function according to the different pointer types assigned to it. Using the dynamic nature of virtual functions, data access is hidden in them, making it impossible to perform static data analysis of the program. Dynamic data analysis requires understanding the derivation relationship between the child class and the parent class. However, due to the existence of cross-derivation of subclasses, the correlation between data is discrete, making dynamic data analysis difficult.

[0043] The final executable file generated by linking LLVM's intermediate language is as follows: Figure 5 The following is an example of code conversion for data obfuscation. There is an integer variable A in the main function, and variable A is encapsulated into class Data. Data A is accessed indirectly through the subclass SubData derived from class Data. Before data A is used, it needs to be converted through the constructor and data conversion function of class Data and subclass SubData. A virtual function for data transformation is constructed through the polymorphic mechanism for the final data restoration. After the data obfuscation conversion, the access to variable A requires access to class Data and its subclass SubData. The data restoration process needs to go through the constructors and virtual function runtime calculations of the two classes. The data conversion function can be arbitrarily complex, and the data usage process is hidden in the class derivation, polymorphism, and function transformation, which can significantly improve the security of program data.

[0044] In the embodiment of this case, when protecting the program data flow, by constructing a program data semantic association graph, based on the semantic association graph and data semantic entropy, the uncertainty of the semantic information contained in the program data is expressed. The larger the data semantic entropy value, the smaller the purity of the semantic information, and the more complex the amount of semantic information contained in the data. Using the object-oriented mechanism of C++, the important data in the program is encapsulated into classes, and the data's own structure and access method are changed through class inheritance, derivation and polymorphism, so that direct access to data in the program is converted into indirect access through the class. Data security enhancement functions and overloaded functions are introduced into the class to further protect the data. At the same time, program analysis technology is used to maintain functional consistency before and after the transformation, thereby achieving the purpose of increasing the data semantic entropy value, hiding the program data flow logic, resisting reverse analysis, and protecting the code.

[0045] Furthermore, based on the above method, an embodiment of the present invention further provides a controllable data obfuscation system based on object mapping, including: a data analysis module and a data obfuscation module, where,

[0046] The data analysis module is used to transform the target program into an intermediate language, mine the data reference relationships and execution path information in the program, and construct a data semantic association graph of the target program;

[0047] The data obfuscation module is used to traverse the data semantic association graph, strip key data from the program according to the data semantic information and encapsulate it into a data class, and use the inheritance, derivation, and polymorphism of the class to obfuscate the program data flow structure, so that the direct access to data in the program is converted into indirect access to data through the class.

[0048] Transform the program into an intermediate language. At this level, perform control flow and data flow analysis on the program, mine the data structures existing in the program and their corresponding dependency relationships, and construct a data semantic association graph. Secondly, traverse the data association graph, guided by the data semantic entropy value, strip the key data from the original code structure, and integrate it into a unified data class. Then, use the derivation mechanism of the class to derive multiple subclasses as the data access of the program. During the derivation process, generate the same subclass for unrelated data, access the same subclass for data of unrelated functions, and access different subclasses for data of the same function. Finally, introduce polymorphism and operator overloading mechanisms in the class to increase the complex relationship of the internal data relationship of the class.

[0049] Unless otherwise specifically stated, the relative steps, numerical expressions, and numerical values of the components and steps described in these embodiments do not limit the scope of the present invention.

[0050] Each embodiment in this specification is described in a progressive manner. The key point of each embodiment is to illustrate the differences from other embodiments. The same or similar parts among the embodiments can be referred to each other. For the system disclosed in the embodiments, since it corresponds to the method disclosed in the embodiments, the description is relatively simple, and the relevant parts can be referred to the description of the method part.

[0051] Combined with the units and method steps of the examples described in the embodiments disclosed in this article, they can be implemented by electronic hardware, computer software, or a combination of the two. To clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described according to functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Those of ordinary skill in the art can use different methods to implement the described functions for each specific application, but such implementation is not considered to exceed the scope of the present invention.

[0052] Those of ordinary skill in the art can understand that all or part of the steps in the above methods can be completed by instructing relevant hardware through a program, and the program can be stored in a computer-readable storage medium, such as: read-only memory, magnetic disk or optical disc, etc. Optionally, all or part of the steps of the above embodiments can also be implemented using one or more integrated circuits. Correspondingly, each module / unit in the above embodiments can be implemented in the form of hardware or in the form of a software function module. The present invention is not limited to any specific form of combination of hardware and software.

[0053] Finally, it should be noted that: the above embodiments are only specific embodiments of the present invention, used to illustrate the technical solutions of the present invention, rather than limiting it. The protection scope of the present invention is not limited thereto. Although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that: any person skilled in the art within the technical scope disclosed by the present invention can still modify the technical solutions recorded in the foregoing embodiments, or can easily think of changes, or perform equivalent replacements on some of the technical features; and these modifications, changes or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present invention, and should all be covered by the protection scope of the present invention. Therefore, the protection scope of the present invention should be subject to the protection scope of the claims.

Claims

1. A controllable data obfuscation method based on object mapping, characterized in that It includes the following content: Convert the target program into an intermediate language, mine the data reference relationships and execution path information in the program, and construct a data semantic association graph of the target program; Traverse the data semantic association graph, obtain all the reference relationships between data according to the data semantic association graph, obtain the probability of obtaining semantic information from the data based on the reference relationships, use the probability of obtaining semantic information from the data, and combine the program's global data and reference relationships to obtain the data semantic entropy. According to the data semantic information, strip the key data from the program and encapsulate it into a data class. Using the data semantic entropy as a guide, analyze all the data in the program, mine the key data program in the program, and encapsulate and integrate the key data into a data class. Using the class derivation strategy, generate the same subclass for the irrelevant data in the program, so that the data access of the irrelevant functions accesses the same subclass, and the data access of the same function accesses different subclasses. Use the derived multiple subclasses as the data access interface during program execution; and use the polymorphism mechanism to hide the program's key data in the class structure data access, converting the direct access to data in the program into indirect access to data through the class.

2. The controllable data obfuscation method based on object mapping according to claim 1, characterized in that Construct a data semantic association graph. First, the program converts the program into LLVM intermediate language. At the intermediate language level, the program analyzes the control flow and data flow of the program, and then mines the existing data reference relationships in the program; then, construct a data semantic association graph based on the existing data reference relationships.

3. The controllable data obfuscation method based on object mapping according to claim 1, characterized in that Obtain the probability of obtaining semantic information from data based on the citation relationship, including: setting the citation relationship between all data obtained from the data semantic association graph as n, where the number of times data i is cited in the association graph is l i , with a direct citation relationship of 1, and the indirect citation relationship increases by 1 for each transfer citation. Then the probability P(A i ) is expressed as:

4. The controllable data obfuscation method based on object mapping according to claim 1, characterized in that Using the probability of obtaining semantic information from data and combining the program's global data and reference relationships, the calculation formula for data semantic entropy is expressed as: where P(A i ) is the probability of obtaining semantic information from data i, and N represents the number of data items.

5. The controllable data obfuscation method based on object mapping according to claim 1, characterized in that Diversified derivation strategy, including: adding security enhancement functions to different subclasses, where the security enhancement functions include but are not limited to: string encryption functions, data complex boolean operation functions, variable splitting and reconstruction functions.

6. The controllable data obfuscation method based on object mapping according to claim 1, characterized in that Use the polymorphism mechanism to hide the program's key data in the class structure data access, including: using static polymorphism and / or dynamic polymorphism to hide the data access process, where static polymorphism uses function overloading to achieve the hiding of data access, and dynamic polymorphism achieves the hiding of data access by defining virtual functions.

7. A controllable data obfuscation system based on object mapping, characterized in that It includes: a data analysis module and a data obfuscation module, where The data analysis module is used to convert the target program into an intermediate language, mine the data reference relationships and execution path information in the program, and construct a data semantic association graph of the target program; The data obfuscation module is used to calculate the data semantic entropy by traversing the data semantic association graph, obtain the reference relationships between all data based on the data semantic association graph, obtain the probability of obtaining semantic information from the data according to the reference relationships, utilize the probability of obtaining semantic information from the data, and combine the program's global data and reference relationships to obtain the data semantic entropy. Based on the data semantic information, the key data is stripped from the program and encapsulated into a data class. Using the data semantic entropy as a guide, all data in the program is analyzed to mine the key data in the program, and the key data is encapsulated and integrated into a data class. Using the class derivation strategy, the unrelated data in the program is generated into the same subclass, so that the data accessed by unrelated functions access the same subclass, and the data accessed by the same function access different subclasses. The multiple derived subclasses are used as the data access interfaces during program execution; and the polymorphic mechanism is used to hide the program's key data in the class structure data access, converting the direct access to data in the program into indirect access to data through the class.

Citation Information

Patent Citations

  • Control flow obfuscation method and system based on a callback function

    CN111723345A

  • Code obfuscation method and device, electronic equipment and storage medium

    CN114417267A