A method, device and medium for initializing a unidbg simulation execution environment
By suspending the software process to be analyzed during the middle section execution trigger, performing memory data dumping and error log processing, the initialization difficulty of the unidbg simulation execution environment in complex situations is solved, and simplified so file dependencies and efficient simulation calls are achieved.
Patent Information
- Application Number
- CN202311093272.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-08-28
- Publication Date
- 2025-07-25
- Estimated Expiration
- 2043-08-28
AI Technical Summary
In complex situations, it is more cumbersome and difficult to implement unidbg simulation execution of the so file that depends on the context or device environment information through conventional environment replenishment.
By suspending the execution process of the software to be analyzed during the middle section execution trigger, performing memory data dumping, traversing the dump file and applying for the memory context environment through the unidbg interface, receiving and processing error logs, and adding missing memory blocks to realize simulated calls of the unidbg simulation execution environment.
It avoids unidbg's complex initialization call chain, simplifies the initialization process of so files, and improves the efficiency and reliability of simulation execution.
Smart Images

Figure CN117112137B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of reverse debugging technology, and in particular, to a method, device, and medium for initializing the unidbg simulation execution environment. Background Art
[0002] Currently, unidbg is a standard Java project and a reverse tool based on unicorn and dynamic. It can directly call the so files in Android software in a black-box manner. In offline protocol reverse, it is a powerful tool whether directly simulating the execution of algorithms or performing white-box trace analysis.
[0003] During the use of unidbg, when simulating the execution of so files that depend on context or device environment information, it is often necessary to supplement the environment and perform the loading and initialization of the so files. For situations with a not-complex environment, generally, hook operations, patch operations, or file redirection operations are performed to achieve the dependence of unidbg simulation execution on so files with context or device environment information. However, in complex situations, it is often difficult to perform the initialization work of so files through the conventional method of supplementing the environment to achieve the dependence of unidbg simulation execution on so files with context or device environment information. Summary of the Invention
[0004] Embodiments of this application provide a method, device, and medium for initializing the unidbg simulation execution environment to solve the technical problem that in the prior art, in complex situations, it is often cumbersome and difficult to achieve the dependence of unidbg simulation execution on so files with context or device environment information through the conventional method of supplementing the environment.
[0005] On the one hand, embodiments of this application provide a method for initializing the unidbg simulation execution environment, including:
[0006] Determine the software to be analyzed and the code to be executed corresponding to the software to be analyzed, and based on the mid-section characteristics of the code to be executed, suspend the execution process corresponding to the software to be analyzed when the mid-section of the code to be executed is triggered;
[0007] Determine the real-time acquisition requirements of memory data, and dump the memory data corresponding to the real-time acquisition requirements in the memory area to save corresponding multiple dump files;
[0008] Traverse each dump file, and apply for memory for the memory blocks obtained through traversal through the corresponding interfaces in unidbg to determine the memory context environment corresponding to the memory application;
[0009] Write the memory context environment to the Unidbg, execute the memory context environment, and receive the error logs during the execution process;
[0010] According to the missing memory addresses in the error logs, obtain the corresponding missing memory blocks, add the missing memory blocks to the memory context environment, and execute the added memory context environment in Unidbg to implement the simulated call of the Unidbg simulated execution environment.
[0011] In an implementation manner of the present application, traversing each dump file and performing memory application on the memory blocks obtained by traversing through the corresponding interfaces in Unidbg to determine the memory context environment corresponding to the memory application specifically includes:
[0012] For each dump file, traverse the dump file and determine the start address and end address corresponding to the dump file;
[0013] According to the start address and end address, determine the capacity of the memory block to be applied for by the dump file, and perform memory application on the memory block of the capacity through the corresponding application interface in Unidbg;
[0014] Determine the multiple memory blocks that have been applied for, and determine the memory context environment corresponding to the memory application according to the multiple memory blocks.
[0015] In an implementation manner of the present application, receiving the error logs during the execution process specifically includes:
[0016] Compare the similarity between the memory context environment and the execution environment required by Unidbg, and find the missing memory blocks corresponding to the execution environment of Unidbg;
[0017] Throw the error logs corresponding to the missing memory blocks and receive the error logs.
[0018] In an implementation manner of the present application, according to the missing memory addresses in the error logs, obtaining the corresponding missing memory blocks and adding the missing memory blocks to the memory context environment specifically includes:
[0019] When the missing memory blocks in the error logs are not applied for, determine the missing memory addresses corresponding to the missing memory blocks in the error logs, and find the unapplied missing memory blocks in the execution process of the software to be analyzed according to the corresponding missing memory addresses;
[0020] Dump the unapplied missing memory blocks, and add the dumped unapplied missing memory blocks to the memory context environment, so as to write the memory context environment after addition to the unidbg again.
[0021] In an implementation manner of the present application, the obtaining the corresponding missing memory block according to the missing memory address in the error log and adding the missing memory block to the memory context environment specifically includes:
[0022] When the missing memory block in the error log is a memory access error, determine the missing memory address corresponding to the missing memory block with a memory access error in the error log;
[0023] Through the corresponding interface in the unidbg and according to the missing memory address, obtain the missing memory block with a memory access error among the memory blocks obtained by traversing multiple dump files;
[0024] Add the missing memory block with a memory access error to the memory context environment, and write the memory context environment after addition to the unidbg again.
[0025] In an implementation manner of the present application, before the method suspends the execution process corresponding to the software to be analyzed when the mid-section feature of the code to be executed is triggered during the mid-section execution of the code to be executed, the method further includes:
[0026] Preprocess the software to be analyzed and obtain the memory data corresponding to the software to be analyzed after preprocessing; the preprocessing at least includes reinforcement processing, anti-debugging processing, and unpacking processing;
[0027] Determine the position of the target so file to be analyzed and the offset value corresponding to the target function in the memory data, and write the dump script corresponding to the software to be analyzed and build the initial framework of the unidbg according to the position of the target so file to be analyzed and the offset value corresponding to the target function.
[0028] In an implementation manner of the present application, the dumping the memory data corresponding to the real-time acquisition requirement in the memory area to save the corresponding multiple dump files specifically includes:
[0029] Obtain the memory data corresponding to the real-time acquisition requirement in the memory area through a dump tool and a dump script; the dump tool at least includes: a hook tool, a debugger;
[0030] When the dump tool is a debugger, determine the hash value of the memory block corresponding to the obtained memory data, and name the corresponding memory block according to the hash value of the memory block;
[0031] In the case where the number of memory blocks with the same name exceeds two, delete the memory blocks with duplicate names, and dump the memory blocks after deleting the duplicate names, so as to save multiple dump files corresponding to multiple memory blocks.
[0032] In an implementation manner of the present application, after receiving the error log during the execution process, the method further includes:
[0033] Determine whether there is a so export symbol table in the multiple dump files obtained by dumping, and in the case where there is a so export symbol table in the dump file, determine the address where the memory acquisition fails and the symbol name of the memory acquisition failure according to the so export symbol table;
[0034] Through the IDA tool, and according to the address where the memory acquisition fails and the symbol name of the memory acquisition failure, determine the position of the corresponding plt table;
[0035] Perform a hook operation on the function at the position of the plt table through unidbg, modify the value of the corresponding PC register, and supplement the Java native call to implement the simulated call of the unidbg simulated execution environment.
[0036] On the other hand, the embodiment of the present application further provides a device for initializing a unidbg simulated execution environment, and the device includes:
[0037] At least one processor;
[0038] And a memory communicatively connected to the at least one processor;
[0039] Wherein, the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute a method for initializing a unidbg simulated execution environment as described above.
[0040] On the other hand, the embodiment of the present application further provides a non-volatile computer storage medium storing computer-executable instructions, and the computer-executable instructions are set as:
[0041] A method for initializing a unidbg simulated execution environment as described above.
[0042] The embodiment of the present application provides a method, a device and a medium for initializing a unidbg simulated execution environment, and at least includes the following beneficial effects:
[0043] By suspending the execution process of the software to be analyzed when a trigger is executed in the middle section, and then dumping the corresponding memory data according to requirements, a corresponding plurality of dump files can be obtained; traversing the dump files can obtain the memory context environment of the unidbg memory application, and receive the error logs during the execution process when executing the memory context environment in unidbg, perform a secondary dump according to the error report, modify the exception, and execute the modified memory context environment to achieve the simulated call of the unidbg simulated execution environment. In this way, through the method of memory dumping, the complex initialization call chain of unidbg is avoided. Brief Description of the Drawings
[0044] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation to the present application. In the drawings:
[0045] Figure 1 It is a schematic flowchart of a method for initializing a unidbg simulated execution environment provided by an embodiment of the present application;
[0046] Figure 2 It is a schematic internal structure diagram of a device for initializing a unidbg simulated execution environment provided by an embodiment of the present application. Detailed Embodiments
[0047] To make the objectives, technical solutions, and advantages of the present application clearer, the technical solutions of the present application will be clearly and completely described below in conjunction with the specific embodiments of the present application and the corresponding drawings. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.
[0048] Embodiments of the present application provide a method, device, and medium for initializing a unidbg simulated execution environment. By suspending the execution process of the software to be analyzed when a trigger is executed in the middle section, and then dumping the corresponding memory data according to requirements, a corresponding plurality of dump files can be obtained; traversing the dump files can obtain the memory context environment of the unidbg memory application, and receive the error logs during the execution process when executing the memory context environment in unidbg, perform a secondary dump according to the error report, modify the exception, and execute the modified memory context environment to achieve the simulated call of the unidbg simulated execution environment. In this way, through the method of memory dumping, the complex initialization call chain of unidbg is avoided. The technical problem that in the prior art, in complex situations, it is often cumbersome and difficult to realize the dependence of unidbg simulated execution on the so files of context or device environment information through the conventional method of supplementing the environment is solved.
[0049] The technical solutions provided by the embodiments of the present application will be described in detail below with reference to the accompanying drawings.
[0050] Figure 1 It is a schematic flowchart of a method for initializing the unidbg simulation execution environment provided by an embodiment of the present application. As Figure 1 shown, a method for initializing the unidbg simulation execution environment provided by an embodiment of the present application includes:
[0051] 101. Determine the software to be analyzed and the code to be executed corresponding to the software to be analyzed, and based on the mid-section characteristics of the code to be executed, suspend the execution process corresponding to the software to be analyzed when the mid-section execution of the code to be executed is triggered.
[0052] When using unidbg for simulation execution, the focus is often only on the encryption logic, and complex call chains and pre-initialization functions are not concerned. At this time, the memory dump method can be used to perform the mid-section execution of the software to be analyzed, avoiding spending a lot of time on processing these environments.
[0053] In an embodiment of the present application, before the server suspends the execution process corresponding to the software to be analyzed when the mid-section execution of the code to be executed is triggered based on the mid-section characteristics of the code to be executed, when analyzing the software to be analyzed, problems such as application reinforcement and anti-debugging will be encountered. Therefore, the software to be analyzed needs to be preprocessed, and the memory data corresponding to the software to be analyzed after preprocessing is obtained. It should be noted that the preprocessing in the embodiments of the present application at least includes reinforcement processing, anti-debugging processing, and unpacking processing.
[0054] The server also needs to determine the location of the target so file to be analyzed and the offset value corresponding to the target function in the memory data. Before performing the unidbg simulation call, it is necessary to achieve an active call in the real machine environment, and for the convenience of multiple calls, the input and output need to be fixed. Here, it may be necessary to perform a hook reverse operation on some system random numbers and time functions to ensure the consistency of the output. The server also writes a dump script corresponding to the software to be analyzed and builds the initial framework of unidbg according to the location of the target so file to be analyzed and the offset value corresponding to the target function.
[0055] Specifically, first, a suitable timing needs to be selected to save the memory environment of the execution process. When the software to be analyzed is in mid-execution, it often depends on global variables that are assigned and modified in the initialization or pre-function. If the software to be analyzed is dumped too early, some variables may not have been assigned yet; if the software to be analyzed is dumped too late, the relevant memory may also be overwritten or destroyed by other data. Therefore, the determined memory dump point is generally at the beginning of mid-execution. When the code block to be executed is about to be executed, the execution process is paused through a debugger or other third-party hook framework.
[0056] In one embodiment, a breakpoint is set when dumping the memory, and the execution is paused at the selected dump timing, which can be achieved by either a debugger or a hook tool. Taking the relatively common hook framework Frida as an example, the hook operation is performed through Module.findBaseAddress(SoName).add(offset), and the target so file is dumped in Interceptor.attach. In fact, in addition to the target so file, there is also some other small amount of memory for the required memory data. However, if the entire memory of the execution process is saved at once, it will take a long time.
[0057] 102. Determine the real-time acquisition requirements of the memory data, and dump the memory data corresponding to the real-time acquisition requirements in the memory area to save the corresponding multiple dump files.
[0058] Specifically, in one embodiment of the present application, the server obtains the memory data corresponding to the real-time acquisition requirements in the memory area through a dump tool and a dump script. It should be noted that the dump tool in the embodiment of the present application at least includes: a hook tool and a debugger.
[0059] When the dump tool is a debugger, the server determines the hash value of the memory block corresponding to the obtained memory data, names the corresponding memory block according to the hash value of the memory block, and then, when the number of memory blocks with the same name exceeds two, deletes the memory blocks with duplicate names, and dumps the memory blocks after deleting the duplicate names to realize the saving of multiple dump files corresponding to multiple memory blocks. Because there are many cases where memory pages are all-zero memory, naming by hash hash value during saving can also avoid storing the same memory block.
[0060] In one embodiment, the server first temporarily suspends the execution process of the software to be analyzed, and then dumps the corresponding memory block when a certain memory is missing. Frida can send a SIGSTOP signal through raise to pause the execution process of the software to be analyzed. However, at the same time, Frida also pauses. When dumping again, a third-party tool needs to be used, such as MemDumper. Since the memory dumped in batches is not large, the dd command can be directly used to save the dumped memory. In addition, dumping can also be performed through a debugger. When the debugger breaks at a breakpoint, it will suspend the threads other than itself, and it can still operate itself. The idea of its dumping is to first traverse the memory area of the execution process, record information such as the start address, end address, and permissions of the memory block, and then read according to the start address and end address. Regarding the problem of dumping speed, since there are a large number of consecutive 0 areas in the memory, compression can greatly reduce the size of the dump file. Therefore, the memory can be compressed when saving the memory, and some black and white list filtering can also be added, and then decompressed when loading the memory in these dump files by unidbg.
[0061] 103. Traverse each dump file, and use the corresponding interface in unidbg to apply for memory for the memory blocks obtained by traversal to determine the memory context environment corresponding to the memory application.
[0062] Specifically, in an embodiment of the present application, the server traverses each dump file, determines the start address and end address corresponding to the dump file, and thus determines the capacity of the memory block to be applied for by the dump file according to the start address and end address. Then, through the corresponding application interface in unidbg, memory is applied for the memory block of the capacity. Then, the server also needs to determine the multiple memory blocks obtained by the application, and determine the memory context environment corresponding to the memory application according to the multiple memory blocks.
[0063] In one embodiment, if saved through a hook tool when saving the environment, these tools are generally implemented through inlinehook, which will cause the function header to save not the original code, but the jump instruction modified by the hook tool. Therefore, it is necessary to first read the normal original instruction at the beginning through mem_read, and then restore the original instruction through mem_write. If the dump memory is saved through a debugger, there is generally no problem. Generally, the debugger implements the interruption through a software breakpoint. Although the bytecode is also modified, the debugger makes corresponding processing so that the user still gets the original instruction.
[0064] In one embodiment, the server needs to load the memory blocks dumped in the previous step. First, it traverses these dump files, reads out the start address and end address, and then applies for memory through the corresponding API interface of Unidbg.
[0065] 104. Write the memory context environment into Unidbg, execute the memory context environment, and receive the error logs during the execution process.
[0066] Specifically, in one embodiment of the present application, the server compares the similarity between the memory context environment and the execution environment required by Unidbg, finds the missing memory blocks corresponding to the execution environment of Unidbg, and then throws the error logs corresponding to the missing memory blocks and receives the error logs.
[0067] In one embodiment of the present application, after the server receives the error logs during the execution process, it determines whether there is an so export symbol table in the multiple dump files of the dump. If there is an so export symbol table in the dump file, according to the so export symbol table, it determines the address where the memory acquisition fails and the symbol name of the memory acquisition failure. Then, through the IDA tool, according to the address where the memory acquisition fails and the symbol name of the memory acquisition failure, it determines the position of the corresponding plt table. Then, the server performs a hook operation on the function at the position of the plt table through Unidbg, modifies the value of the corresponding PC register, and supplements the Java Native Interface (JNI) to implement the simulated call of the Unidbg simulated execution environment.
[0068] In one embodiment, when performing a dump, dump an additional so export symbol table of the target so file that may be used. Then, when the execution process throws an error log, these situations can be directly passed to Undib. Since Unidbg itself processes some system functions, we only need to transfer the control flow to Unidbg when the program executes to these system functions. The specific operation is to find the address when Fetch memoryfailed and the corresponding symbol name in the so export symbol table dumped, and find the position of its plt table through IDA. Finally, perform a hook operation on this position through Unidbg and modify the value of its PC register. After the dump environment is loaded, that is, the initialization work of the so file has been completed, and then the required JNI calls can be supplemented in the same way as the normal call to complete the simulated call.
[0069] 105. Obtain the corresponding missing memory block according to the missing memory address in the error log, add the missing memory block to the memory context environment, and execute the added memory context environment in Unidbg to implement the simulated call of the Unidbg simulated execution environment.
[0070] Specifically, in an embodiment of the present application, when the missing memory block in the error log has not been applied for, the server determines the missing memory address corresponding to the missing memory block in the error log, and according to the corresponding missing memory address, finds the unapplied missing memory block in the execution process of the software to be analyzed, then dumps the unapplied missing memory block, and adds the dumped unapplied missing memory block to the memory context environment, so as to write the added memory context environment into Unidbg again.
[0071] In an embodiment, when not all memory has been dumped previously, there will still be some memory that needs to be dumped again by the server. Specifically, when simulating execution in Unidbg, an error log of Readmemory failed will be thrown when encountering unapplied memory. Through the address in the error log, that is, the address of the missing memory block, the memory block where the address is located is found in the execution process maps, and the corresponding missing memory block is dumped again, and then the memory block is added to the memory context environment obtained by the dump. The missing memory block can be supplemented and connected into Unidbg through the added memory context environment.
[0072] Specifically, in an embodiment of the present application, when the missing memory block in the error log has a memory access error, the server determines the missing memory address corresponding to the missing memory block with a memory access error in the error log, so that through the corresponding interface in Unidbg and according to the missing memory address, the missing memory block with a memory access error is obtained from the memory blocks obtained by traversing multiple dump files. Then, the server adds the missing memory block with a memory access error to the memory context environment, and writes the added memory context environment into Unidbg again.
[0073] In one embodiment, a memory block may also be missing in the case of a memory access error. In this case, the situation shown in Unidbg is "Fetch memory failed". This kind of problem is an error when the current execution flow jumps to this address. Similarly, search in maps according to the previous method. However, in this kind of situation, generally, the so file is calling some system library functions. For example, when calling some functions in libc.so, the number of library functions called in the general logic algorithm is not very large. It can be handled specially by manual implementation or skipping. Unidbg also provides a corresponding hook module. You can implement the corresponding function by yourself in new CodeHook in emulator.getBackend().hook_add_new.
[0074] The above is the method embodiment proposed in this application. Based on the same inventive concept, the embodiments of this application also provide a device for initializing the Unidbg simulation execution environment, and its structure is as Figure 2 shown.
[0075] Figure 2 is the internal structure schematic diagram of a device for initializing the Unidbg simulation execution environment provided by the embodiments of this application. As Figure 2 shown, the device includes:
[0076] At least one processor;
[0077] And a memory communicatively connected to at least one processor;
[0078] Wherein, the memory stores instructions executable by at least one processor. The instructions are executed by at least one processor so that at least one processor can:
[0079] Determine the software to be analyzed and the code to be executed corresponding to the software to be analyzed, and based on the mid-section characteristics of the code to be executed, suspend the execution process corresponding to the software to be analyzed when the mid-section of the code to be executed is triggered;
[0080] Determine the real-time acquisition requirement of the memory data, and dump the memory data corresponding to the real-time acquisition requirement in the memory area to save a corresponding plurality of dump files;
[0081] Traverse each dump file, and apply for memory for the memory blocks obtained by traversing through the corresponding interfaces in Unidbg to determine the memory context environment corresponding to the memory application;
[0082] Write the memory context environment into Unidbg, execute the memory context environment, and receive the error logs during the execution process;
[0083] Obtain the corresponding missing memory block according to the missing memory address in the error log, add the missing memory block to the memory context environment, and execute the added memory context environment in Unidbg to implement the simulated call of the Unidbg simulated execution environment.
[0084] The embodiments of the present application also provide a non-volatile computer storage medium storing computer-executable instructions, and the computer-executable instructions are set as follows:
[0085] Determine the software to be analyzed and the code to be executed corresponding to the software to be analyzed, and based on the mid-section characteristics of the code to be executed, suspend the execution process corresponding to the software to be analyzed when the mid-section of the code to be executed is triggered;
[0086] Determine the real-time acquisition requirement of the memory data, and dump the memory data corresponding to the real-time acquisition requirement in the memory area to save the corresponding multiple dump files;
[0087] Traverse each dump file, and apply for memory for the memory blocks obtained by traversal through the corresponding interface in Unidbg to determine the memory context environment corresponding to the memory application;
[0088] Write the memory context environment into Unidbg, execute the memory context environment, and receive the error log during the execution process;
[0089] Obtain the corresponding missing memory block according to the missing memory address in the error log, add the missing memory block to the memory context environment, and execute the added memory context environment in Unidbg to implement the simulated call of the Unidbg simulated execution environment.
[0090] Each embodiment in the present application is described in a progressive manner. For the same or similar parts between the embodiments, reference can be made to each other. Each embodiment focuses on the differences from other embodiments. In particular, for the device and medium embodiments, since they are basically similar to the method embodiments, the description is relatively simple, and for the relevant parts, reference can be made to the partial description of the method embodiments.
[0091] The above describes specific embodiments of the present application. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims may be performed in a different order than in the embodiments and still achieve the desired result. Additionally, the processes depicted in the figures do not necessarily require the particular order or sequential order shown to achieve the desired result. In certain implementations, multitasking and parallel processing are also possible or may be advantageous.
[0092] The devices, media, and methods provided by the embodiments of this application correspond one by one. Therefore, the devices and media also have beneficial technical effects similar to those of their corresponding methods. Since the beneficial technical effects of the methods have been described in detail above, the beneficial technical effects of the devices and media will not be elaborated here.
[0093] Those skilled in the art should understand that the embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, this application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.
[0094] This application is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to the embodiments of this application. It should be understood that each flow and / or block in the flowchart and / or block diagram, as well as the combination of flows and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing devices generate a device for implementing the functions specified in Figure 1 one or more flows and / or Figure 1 blocks.
[0095] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, such that the instructions stored in the computer-readable memory generate a manufactured article including an instruction device that implements the functions specified in Figure 1 one or more flows and / or Figure 1 blocks.
[0096] These computer program instructions can also be loaded onto a computer or other programmable data processing device, such that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process. Thus, the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in Figure 1 one or more flows and / or Figure 1 blocks.
[0097] In a typical configuration, a computing device includes one or more processors (CPUs), an input / output interface, a network interface, and memory.
[0098] The memory may include non - permanent memory in the form of computer - readable media, random access memory (RAM) and / or non - volatile memory such as read - only memory (ROM) or flash RAM. The memory is an example of computer - readable media.
[0099] Computer - readable media includes both permanent and non - permanent, removable and non - removable media that can store information by any method or technology. The information can be computer - readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase - change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read - only memory (ROM), electrically erasable programmable read - only memory (EEPROM), flash memory or other memory technologies, compact disc read - only memory (CD - ROM), digital versatile disc (DVD) or other optical storage, magnetic cassette tapes, magnetic disk storage or other magnetic storage devices, or any other non - transitory media that can be used to store information that can be accessed by a computing device. As defined herein, computer - readable media does not include transitory media such as modulated data signals and carrier waves.
[0100] It should also be noted that the term "comprising", "including" or any other variant thereof is intended to cover non - exclusive inclusion, such that a process, method, article or apparatus that comprises a series of elements includes not only those elements but also other elements not expressly listed, or elements that are inherent to such process, method, article or apparatus. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the process, method, article or apparatus that comprises the element.
[0101] The above - described are only embodiments of the present application and are not used to limit the present application. For those skilled in the art, various changes and modifications can be made to the present application. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present application shall be included within the scope of the claims of the present application.
Claims
1. A method for initializing a unidbg simulation execution environment, characterized in that The method includes: Determine the software to be analyzed and the code to be executed corresponding to the software to be analyzed, and based on the mid-section characteristics of the code to be executed, suspend the execution process corresponding to the software to be analyzed when the mid-section of the code to be executed is triggered; Determine the real-time acquisition requirement of the memory data, and dump the memory data corresponding to the real-time acquisition requirement in the memory area to save multiple corresponding dump files; Traverse each dump file, and apply for memory for the memory blocks obtained by traversal through the corresponding interface in unidbg to determine the memory context environment corresponding to the memory application; Write the memory context environment into unidbg, execute the memory context environment, and receive the error logs during the execution process; According to the missing memory addresses in the error logs, obtain the corresponding missing memory blocks, add the missing memory blocks to the memory context environment, and execute the added memory context environment in unidbg to implement the simulated call of the unidbg simulated execution environment.
2. The method for initializing a unidbg simulation execution environment according to claim 1, wherein The traversing each dump file and applying for memory for the memory blocks obtained by traversal through the corresponding interface in unidbg to determine the memory context environment corresponding to the memory application specifically includes: For each dump file, traverse the dump file and determine the start address and end address corresponding to the dump file; According to the start address and end address, determine the capacity of the memory block to be applied for by the dump file, and apply for memory for the memory block of the capacity through the corresponding application interface in unidbg; Determine the multiple memory blocks applied for, and determine the memory context environment corresponding to the memory application according to the multiple memory blocks.
3. A method for initializing a unidbg simulation execution environment according to claim 1, characterized in that The receiving the error logs during the execution process specifically includes: Compare the similarity between the memory context environment and the execution environment required by unidbg, and find the missing memory blocks corresponding to the execution environment of unidbg; Throw the error logs corresponding to the missing memory blocks and receive the error logs.
4. A method for initializing a unidbg simulation execution environment according to claim 1, wherein The obtaining the corresponding missing memory blocks according to the missing memory addresses in the error logs and adding the missing memory blocks to the memory context environment specifically includes: When the missing memory blocks in the error logs are not applied for, determine the missing memory addresses corresponding to the missing memory blocks in the error logs, and find the unapplied missing memory blocks in the execution process of the software to be analyzed according to the corresponding missing memory addresses; Dump the unapplied missing memory blocks, and add the dumped unapplied missing memory blocks to the memory context environment to write the added memory context environment into unidbg again.
5. The method for initializing a unidbg simulation execution environment according to claim 4, wherein The obtaining the corresponding missing memory blocks according to the missing memory addresses in the error logs and adding the missing memory blocks to the memory context environment specifically includes: In the case where the missing memory block in the error log is due to a memory access error, determine the missing memory address corresponding to the missing memory block with a memory access error in the error log; Through the corresponding interface in Unidbg and based on the missing memory address, obtain the missing memory block with the memory access error among the memory blocks obtained by traversing multiple dump files; Add the missing memory block with the memory access error to the memory context environment, and write the updated memory context environment back to Unidbg.
6. The method for initializing a unidbg simulation execution environment according to claim 1, wherein Before suspending the execution process of the software to be analyzed when the mid-section feature of the code to be executed is triggered, the method further includes: Preprocess the software to be analyzed and obtain the memory data corresponding to the software to be analyzed after preprocessing; the preprocessing includes at least hardening processing, anti-debugging processing, and unpacking processing; Determine the position of the target so file to be analyzed and the offset value corresponding to the target function in the memory data, and based on the position of the target so file to be analyzed and the offset value corresponding to the target function, write the dump script corresponding to the software to be analyzed and build the initial framework of Unidbg.
7. A method for initializing a unidbg simulation execution environment according to claim 1, characterized in that The specific steps for dumping the memory data corresponding to the real-time acquisition requirement in the memory area to save multiple corresponding dump files include: In the memory area, use a dump tool and a dump script to obtain the memory data corresponding to the real-time acquisition requirement; the dump tool includes at least: a hook tool and a debugger; When the dump tool is a debugger, determine the hash value of the memory block corresponding to the obtained memory data, and name the corresponding memory block according to the hash value of the memory block; When the number of memory blocks with the same name exceeds two, delete the memory blocks with duplicate names, and dump the memory blocks after deleting the duplicates to save multiple dump files corresponding to multiple memory blocks.
8. A method for initializing a unidbg simulation execution environment according to claim 1, characterized in that, After receiving the error log during the execution process, the method further includes: Determine whether there is an so export symbol table in the multiple dumped dump files, and when there is an so export symbol table in the dump file, determine the memory acquisition failure address and the symbol name of the memory acquisition failure according to the so export symbol table; Use the IDA tool and based on the memory acquisition failure address and the symbol name of the memory acquisition failure, determine the position of the corresponding plt table; Use Unidbg to perform a hook operation on the function at the position of the plt table, modify the value of the corresponding PC register, and supplement the Java native call to implement the simulated call in the Unidbg simulated execution environment.
9. A device for initializing a unidbg simulation execution environment, characterized in that, The device includes: At least one processor; And a memory communicatively connected to the at least one processor; Among them, the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute a method for initializing a unidbg simulation execution environment according to any one of claims 1-8.
10. A non-volatile computer storage medium storing computer-executable instructions, characterized in that, The computer-executable instructions are set to: A method for initializing a unidbg simulation execution environment according to any one of claims 1-8.
Citation Information
Patent Citations
Full context-sensitive program control flow integrity protection method and system
CN107194252A
Android end anti-crawling method and device
CN115632817A