A method and apparatus for data loading
By calling asynchronous procedure call objects from kernel and user state thread queues during data loading and executing corresponding callback functions, the problem that the existing technology cannot load data on target processes with self-protection functions is solved, and the objective function data loading in user state mode is realized.
Patent Information
- Application Number
- CN202410692157.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-05-30
- Publication Date
- 2025-05-30
- Estimated Expiration
- 2044-05-30
AI Technical Summary
The prior art cannot effectively inject target processes with self-protection functions during data loading, resulting in the inability to load data for specific processes.
By calling the pre-inserted first asynchronous procedure call object from the kernel state thread queue and executing the first callback function, triggering the user state context, and calling the pre-inserted second asynchronous procedure call object from the user state thread queue and executing the second callback function, bypassing the detection of the target process with self-protection in the kernel state, data loading of the target function is achieved.
Implementing the data loading process of the objective function in the user mode mode avoids detection of self-protection mechanisms in the kernel mode and meets the need for data loading for specific processes.
Smart Images

Figure CN118467204B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer technologies, and in particular, to a method and apparatus for data loading. Background Art
[0002] During the data loading process, it is usually necessary to call an asynchronous procedure call object pre-registered with a callback function to achieve the purpose of data loading through the callback function. However, there are certain limitations in the process of injecting a target function for data loading into a target process to be loaded in the prior art. For example, the commonly used SetWindowsHookEx injection technology injects into all processes in the operating system and cannot inject into specific processes. The injection method combining OpenProcess and LoadLibrary, on the other hand, cannot inject into processes with self-protection functions. Therefore, the prior art can only perform the data loading process on processes without self-protection functions and cannot perform it according to user requirements. Summary of the Invention
[0003] In view of this, embodiments of the present invention provide a method and apparatus for data loading. By calling a pre-inserted first asynchronous procedure call object from a kernel-mode thread queue and executing a first callback function, a user-mode context is triggered. And by calling a pre-inserted second asynchronous procedure call object from a user-mode thread queue and executing a second callback function, the detection of a target process with self-protection in the kernel mode can be bypassed, and the data loading process of the target function can be implemented in the user-mode.
[0004] To achieve the above object, according to one aspect of the embodiments of the present invention, a method for data loading is provided.
[0005] A method for data loading according to an embodiment of the present invention includes: obtaining a target process to be loaded; obtaining a first asynchronous procedure call object from a kernel-mode thread queue corresponding to the target process, and triggering the user mode through a first callback function registered in the first asynchronous procedure call object; obtaining a second asynchronous procedure call object from a user-mode thread queue corresponding to the target process, and implementing data loading through a second callback function registered in the second asynchronous procedure call object; wherein, the second callback function contains parameters corresponding to a target function for implementing data loading.
[0006] Optionally, before obtaining the target process to be loaded, it further includes: in the kernel mode of the running system, inserting the first asynchronous procedure call object and the second asynchronous procedure call object into the kernel-mode thread queue and the user-mode thread queue corresponding to the target process, respectively.
[0007] Optionally, the step of inserting the first asynchronous procedure call object and the second asynchronous procedure call object into the kernel-mode thread queue and the user-mode thread queue corresponding to the target process respectively includes: registering a first callback function indicating the trigger of the user-mode to the first asynchronous procedure call object, and inserting the registered first asynchronous procedure call object into the kernel-mode thread queue corresponding to the target process; registering the second callback function to the second asynchronous procedure call object, and inserting the registered second asynchronous procedure call object into the user-mode thread queue corresponding to the target process, so as to inject the target function into the target process.
[0008] Optionally, the method further includes: using a pre-registered process notification callback function to monitor one or more processes in the startup state in the running system in real time; and screening out the target process to be injected according to the process parameters among the one or more processes in the startup state.
[0009] Optionally, the method further includes: storing the parameters corresponding to the target function and the second callback function in the executable memory corresponding to the target process.
[0010] Optionally, the method further includes: storing the parameters corresponding to the target function and the second callback function in two consecutive pages of the executable memory respectively; wherein, storing the parameters corresponding to the target function in the first page and storing the second callback function in the second page.
[0011] Optionally, when the target process is a native process, the target function is the LdrloadDLL function; or when the target process is a wow64 process, the target function is the RtlQueueApcWow64Thread function.
[0012] Optionally, the step of inserting the registered first asynchronous procedure call object into the kernel-mode thread queue corresponding to the target process includes: obtaining the first thread of the target process in the kernel-mode; and inserting the registered first asynchronous procedure call object into the queue corresponding to the first thread.
[0013] To achieve the above object, according to another aspect of the embodiments of the present invention, a data loading device is provided.
[0014] A data loading device according to an embodiment of the present invention includes:
[0015] An obtaining module, configured to obtain a target process to be loaded;
[0016] The first call module is used to obtain a first Asynchronous Procedure Call (APC) object from the kernel-mode thread queue corresponding to the target process, and trigger the user-mode by means of the first callback function registered in the first APC object.
[0017] The second call module is used to obtain a second APC object from the user-mode thread queue corresponding to the target process, and implement data loading by means of the second callback function registered in the second APC object; wherein, the second callback function contains the parameters corresponding to the target function for implementing data loading.
[0018] To achieve the above object, according to another aspect of the embodiments of the present invention, there is provided an electronic device for data loading.
[0019] An electronic device for data loading according to an embodiment of the present invention includes: one or more processors; a storage device for storing one or more programs, which when executed by the one or more processors, cause the one or more processors to implement a data loading method according to an embodiment of the present invention.
[0020] To achieve the above object, according to still another aspect of the embodiments of the present invention, there is provided a computer-readable storage medium.
[0021] A computer-readable storage medium according to an embodiment of the present invention stores a computer program thereon, and when the program is executed by a processor, it implements a data loading method according to an embodiment of the present invention.
[0022] One embodiment of the above invention has the following advantages or beneficial effects: By calling the pre-inserted first APC object from the kernel-mode thread queue and executing the first callback function, the user-mode context is triggered, and by calling the pre-inserted second APC object from the user-mode thread queue and executing the second callback function, the detection of the target process with self-protection in the kernel-mode can be bypassed, and the data loading process of the target function can be implemented in the user-mode.
[0023] The further effects of the above non-conventional optional manner will be described in conjunction with the specific embodiments hereinafter. BRIEF DESCRIPTION OF THE DRAWINGS
[0024] The drawings are used to better understand the present invention and do not constitute an improper limitation to the present invention. Among them:
[0025] Figure 1 is a main flowchart of a data loading method according to an embodiment of the present invention;
[0026] Figure 2 is a main flowchart of inserting APC objects twice according to an embodiment of the present invention;
[0027] Figure 3 is a schematic diagram of the main process for determining the target process of the APC object to be inserted according to an embodiment of the present invention;
[0028] Figure 4 is a schematic diagram of the process for inserting the first asynchronous call object according to an embodiment of the present invention;
[0029] Figure 5 is a schematic diagram of the specific process of the thread injection process according to an embodiment of the present invention;
[0030] Figure 6 is a schematic diagram of the specific process of the data loading process according to an embodiment of the present invention;
[0031] Figure 7 is a schematic diagram of the main modules of the data loading device according to an embodiment of the present invention;
[0032] Figure 8 is an exemplary system architecture diagram to which an embodiment of the present invention can be applied;
[0033] Figure 9 is a schematic diagram of the structure of a computer system of a terminal device or a server suitable for implementing an embodiment of the present invention. Detailed implementation manners
[0034] The following describes exemplary embodiments of the present invention with reference to the accompanying drawings. Various details of the embodiments of the present invention are included to facilitate understanding, and they should be considered merely exemplary. Therefore, those of ordinary skill in the art should recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope and spirit of the present invention. Similarly, for clarity and conciseness, descriptions of well-known functions and structures are omitted in the following.
[0035] It should be noted that, without conflict, the embodiments of the present invention and the technical features in the embodiments can be combined with each other.
[0036] Figure 1 is a schematic diagram of the main steps of the data loading method according to an embodiment of the present invention.
[0037] As Figure 1 shown, the data loading method of the embodiment of the present invention mainly includes the following steps:
[0038] Step S101: Obtain the target process to be loaded;
[0039] Step S102: Obtain the first asynchronous procedure call object from the kernel-mode thread queue corresponding to the target process, and trigger the user-mode through the first callback function registered in the first asynchronous procedure call object;
[0040] Step S103: Obtain a second Asynchronous Procedure Call (APC) object from the user-mode thread queue corresponding to the target process, and implement data loading through the second callback function registered in the second APC object; wherein, the second callback function contains the parameters corresponding to the target function for implementing data loading.
[0041] Wherein, the APC object is the Asynchronous Procedure Call object. In the prior art, the Windows system can only be in one of the kernel-mode or user-mode at the same time, so it usually only involves kernel-mode calls or user-mode calls. Correspondingly, the storage location of the APC object is also different in different modes. That is, in an optional embodiment, the kernel-mode thread queue is stored in the kernel space, and the user-mode thread queue is stored in the user space, so that when executing, the corresponding APC object can be obtained from different storage spaces.
[0042] It can be understood that in order to implement data loading for the target process in the above process, it is necessary to pre-insert the parameters of the target function for loading data into the target process, so that through Step S102 and Step S103, the target function can be called by calling the parameters corresponding to the target function in the target process, and finally data loading can be achieved. Therefore, before Step S101, it also includes: in the kernel-mode of the running system, insert the first APC object and the second APC object into the kernel-mode thread queue and the user-mode thread queue corresponding to the target process respectively.
[0043] The following specifically describes the process of inserting the above two APC objects, as Figure 2 shown, including:
[0044] Step S201: Register the first callback function indicating the trigger of the user-mode to the first APC object, and insert the registered first APC object into the kernel-mode thread queue corresponding to the target process
[0045] Step S202: Register the second callback function to the second APC object, and insert the registered second APC object into the user-mode thread queue corresponding to the target process to inject the target function into the target process.
[0046] Among them, the execution permissions of the kernel mode and the user mode are different. In many operating systems, the memory is divided into a kernel space and a user space, that is, only the kernel program with very high permissions can access the kernel space, while most application programs only have relatively small running permissions. Therefore, the user space is specifically used for the access of application programs. For an application program with a self-protection function, injecting only through the user mode cannot bypass its self-protection mechanism. Therefore, in the embodiment of the present invention, by inserting APC objects twice, during the call process of the APC object, the user mode can be triggered by calling the first callback function in the kernel mode with high permissions, and further, the call of the target function can be finally realized by calling the second callback function in the user mode.
[0047] In order to inject the target process in a targeted manner, in an optional embodiment, before step S201, as Figure 3 shown, it further includes:
[0048] Step S301: Use a pre-registered process notification callback function to monitor one or more processes in the running system that are in the startup state in real time;
[0049] Step S302: Among the one or more processes in the startup state, screen out the target process to be injected according to the process parameters.
[0050] Among them, by running the process notification callback function, the processes running in the running system can be monitored in real time. When a process starts, the process parameters corresponding to the started process will be obtained through the process notification callback function, which can specifically include the process name, the process startup time, and the application program to which the process belongs, etc. When it is necessary to inject a specific target process, the process name of the started process can be matched with the process name of the target process. When the match is consistent, the started process is considered to be the target process. In an optional embodiment, the process notification callback function is registered in the kernel mode with higher operating system permissions, so that the startup of the process can be monitored in time and the APC object can be quickly delivered.
[0051] It should be noted that for the process of inserting the APC object for the first time in step S201, it is not randomly selected from multiple threads corresponding to the target process. In an optional embodiment, step S201 is as Figure 4 shown, and includes:
[0052] Step S401: Obtain the first thread corresponding to the target process;
[0053] Step S402: Insert the first asynchronous procedure call object into the queue corresponding to the first thread.
[0054] Among them, the target process usually corresponds to multiple threads with different functions, such as the initialization module startup thread, the A module startup thread, the B module startup thread, etc. Each thread corresponds to its own thread queue. Not all thread queues can insert an APC object. Usually, only the initialization module can insert an APC object, and the initialization module is precisely the first thread started by each process (i.e., the first thread in the process). Therefore, the embodiment of the present invention selects to insert the APC object into the queue corresponding to the first thread corresponding to the target process, which can ensure the effective insertion of the APC object and prevent the situation of insertion failure.
[0055] In the embodiment of the present invention, first, the APC object (i.e., the first asynchronous procedure call object) is inserted into the kernel-mode thread queue in the kernel mode, and a first callback function indicating the trigger of the user mode is registered in the first asynchronous procedure call object. When the subsequent process starts, the previously inserted APC object can be obtained from the kernel-mode thread queue in the kernel mode, and the first callback function registered in the APC object is executed to trigger the user mode of the system. By inserting the APC object (i.e., the second asynchronous procedure call object) into the user-mode thread queue for the second time, and a second callback function containing the parameters corresponding to the target function is registered in the second asynchronous procedure call object. After the user mode is triggered, the target function can be called according to the parameters of the target function by executing the second callback function.
[0056] In an optional embodiment, the parameters corresponding to the target function and the second callback function can be stored in the executable memory corresponding to the target process. For different processes, each process corresponds to an independent storage space, that is, an independent executable memory. Therefore, after the second asynchronous procedure call object is inserted into the target process, the functions and parameters related to the second asynchronous procedure call object should also be stored in the executable memory corresponding to the target process.
[0057] In a further optional embodiment, the parameters corresponding to the target function and the second callback function are respectively stored in two consecutive pages of executable memory; among them, the parameters corresponding to the target function are stored in the first page, and the second callback function is stored in the second page. It can be understood that when the target processes are different, the corresponding target functions to be inserted are also different, and naturally the corresponding parameter sizes are also different. In an optional embodiment, when the target process is a native process, the target function is the LdrloadDLL function; and when the target process is a wow64 process, the target function is the RtlQueueApcWow64Thread function. The reason why the parameters corresponding to the target function are stored in the first page in the embodiments of the present invention is that for the above-mentioned two target functions, the sizes are usually not more than 1024 kb, and the available storage space on the first page of the executable memory is 4096 kb, that is, the parameters corresponding to the target function can be completely stored, and there will be no situation where the single-page storage space is insufficient. And storing the second callback function on the second page is for convenient calling. Only the executable memory on the second page needs to be directly accessed, without having to identify the second callback function from the executable memory during the calling process, which improves the calling efficiency. Among them, when the target function is the LdrloadDLL function, the corresponding parameter is the dynamic link library path, that is, the loading of the dynamic link library is executed through the call of the LdrloadDLL function.
[0058] The following uses a specific embodiment to specifically illustrate the process of thread injection provided by the present invention, as Figure 5 shown, including:
[0059] Step S501: Register a kernel-mode process notification callback function with the operating system to monitor the processes started in the real-time operating system;
[0060] Step S502: When it is monitored that the target process starts, traverse all the threads corresponding to the target process, and obtain the first thread (initialization thread) among them;
[0061] Step S503: In the kernel-mode, insert an APC object (the first asynchronous procedure call object) into the kernel-mode thread queue; among them, a Normal callback function RoutineA (the first callback function) is registered on this APC object;
[0062] Step S504: Insert an APC object (the second asynchronous procedure call object) into the user-mode thread queue; among them, a Normal callback function RoutineB (the second callback function) and the parameter address of the RoutineB function are registered on this APC object, and the dynamic link library path (the parameter when the target function is the LdrLoadDll function) is included in the callback function RoutineB.
[0063] Through the above process, the APC object is inserted into the kernel-mode thread queue and the user-mode thread queue in two separate times in the kernel-mode, so that the corresponding function can be called during the data loading process. The following specifically describes the data calling process, that is, after steps S501 - S504 are executed, as Figure 6 shown, execute:
[0064] Step S601: Obtain the target process to be loaded;
[0065] Step S602: Obtain the APC object (the first asynchronous procedure call object) from the kernel-mode thread queue, and trigger the user-mode through the callback function RoutineA (the first callback function);
[0066] Step S603: Obtain the APC object (the second asynchronous procedure call object) from the user-mode thread queue, and obtain the dynamic link library path (the parameter when the target function is the LdrLoadDll function) through the callback function RoutineB (the second callback function);
[0067] Step S604: Execute the loading of the dynamic link library according to the dynamic link library path.
[0068] According to the data loading method of the embodiment of the present invention, by calling the pre-inserted first asynchronous procedure call object from the kernel-mode thread queue and executing the first callback function, the user-mode context is triggered, and by calling the pre-inserted second asynchronous procedure call object from the user-mode thread queue and executing the second callback function, the detection of the target process with self-protection in the kernel-mode can be bypassed, and the data loading process of the target function can be implemented in the user-mode.
[0069] Figure 7 is a schematic diagram of the main modules of the data loading device according to the embodiment of the present invention.
[0070] As Figure 7 shown, the data loading device 700 according to the embodiment of the present invention includes:
[0071] An obtaining module 701, configured to obtain the target process to be loaded;
[0072] A first calling module 702, configured to obtain the first asynchronous procedure call object from the kernel-mode thread queue corresponding to the target process, and trigger the user-mode through the first callback function registered in the first asynchronous procedure call object;
[0073] The second call module 703 is configured to obtain a second asynchronous procedure call object from the user-mode thread queue corresponding to the target process, and implement data loading through a second callback function registered in the second asynchronous procedure call object; wherein, parameters corresponding to a target function for implementing data loading are included in the second callback function.
[0074] In an optional embodiment of the present invention, the apparatus further includes a process injection module, configured to insert the first asynchronous procedure call object and the second asynchronous procedure call object into the kernel-mode thread queue and the user-mode thread queue corresponding to the target process respectively in the kernel-mode of the running system before obtaining the target process to be loaded.
[0075] In an optional embodiment of the present invention, the process injection module is further configured to register a first callback function indicating the trigger of the user-mode to the first asynchronous procedure call object, and insert the registered first asynchronous procedure call object into the kernel-mode thread queue corresponding to the target process; register the second callback function to the second asynchronous procedure call object, and insert the registered second asynchronous procedure call object into the user-mode thread queue corresponding to the target process, so as to inject the target function into the target process.
[0076] In an optional embodiment of the present invention, the process injection module is further configured to monitor one or more processes in the startup state in the running system in real time by using a pre-registered process notification callback function; and screen out the target process to be injected according to the process parameters among the one or more processes in the startup state.
[0077] In an optional embodiment of the present invention, the process injection module is further configured to store the parameters corresponding to the target function and the second callback function into the executable memory corresponding to the target process.
[0078] In an optional embodiment of the present invention, the process injection module is further configured to store the parameters corresponding to the target function and the second callback function into two consecutive pages of the executable memory respectively; wherein, the parameters corresponding to the target function are stored in the first page, and the second callback function is stored in the second page.
[0079] In an optional embodiment of the present invention, when the target process is a native process, the target function is the LdrloadDLL function; or when the target process is a wow64 process, the target function is the RtlQueueApcWow64Thread function.
[0080] In an alternative embodiment of the present invention, the process injection module is further configured to obtain the first thread of the target process in the kernel mode; and insert the registered first asynchronous procedure call object into the queue corresponding to the first thread.
[0081] According to the data loading device of the embodiment of the present invention, by calling the pre-inserted first asynchronous procedure call object from the kernel mode thread queue and executing the first callback function, the user mode context is triggered, and by calling the pre-inserted second asynchronous procedure call object from the user mode thread queue and executing the second callback function, the detection of the target process with self-protection in the kernel mode can be bypassed, and the data loading process of the target function can be implemented in the user mode.
[0082] Figure 8 An exemplary system architecture 800 is shown to which the data loading method or the data loading device of the embodiment of the present invention can be applied.
[0083] As Figure 8 shown, the system architecture 800 may include terminal devices 801, 802, 803, a network 804, and a server 805. The network 804 is used to provide a medium for a communication link between the terminal devices 801, 802, 803 and the server 805. The network 804 may include various connection types, such as wired, wireless communication links, or fiber optic cables, etc.
[0084] Users may use the terminal devices 801, 802, 803 to interact with the server 805 through the network 804 to receive or send data, etc. Various communication client applications may be installed on the terminal devices 801, 802, 803, such as shopping applications, web browser applications, search applications, instant messaging tools, email clients, social platform software, etc.
[0085] The terminal devices 801, 802, 803 may be various electronic devices having a display screen and supporting web browsing, including but not limited to laptop computers and desktop computers installed with the windows operating system, etc.
[0086] The server 805 may be a server providing various services, such as a background management server for monitoring the processes of application programs launched by users using the terminal devices 801, 802, 803. The background management server may analyze and process data such as the launched target process, etc., and feedback the processing results (such as the target function) to the terminal devices.
[0087] It should be noted that the data loading method provided by the embodiment of the present invention is generally executed by the server 805. Correspondingly, the data loading device is generally arranged in the server 805.
[0088] It should be understood that Figure 8 the numbers of the terminal devices, networks, and servers in
[0089] are merely illustrative. According to the implementation requirements, there can be any number of terminal devices, networks, and servers. Figure 9 Reference is now made to Figure 9 which shows a schematic structural diagram of a computer system 900 of a terminal device suitable for implementing the embodiments of the present invention.
[0090] As Figure 9 shown, the computer system 900 includes a central processing unit (CPU) 901, which can perform various appropriate actions and processes according to the program stored in the read-only memory (ROM) 902 or the program loaded from the storage section 908 into the random access memory (RAM) 903. In the RAM 903, various programs and data required for the operation of the system 900 are also stored. The CPU 901, ROM 902, and RAM 903 are connected to each other via a bus 904. An input / output (I / O) first interface 905 is also connected to the bus 904.
[0091] The following components are connected to the I / O first interface 905: an input section 906 including a keyboard, a mouse, etc.; an output section 907 including such as a cathode ray tube (CRT), a liquid crystal display (LCD), etc. and a speaker, etc.; a storage section 908 including a hard disk, etc.; and a communication section 909 including a network first interface card such as a LAN card, a modem, etc. The communication section 909 performs communication processing via a network such as the Internet. A drive 910 is also connected to the I / O first interface 905 as needed. A removable medium 911, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is installed on the drive 910 as needed so that a computer program read from it can be installed into the storage section 908 as needed.
[0092] Specifically, according to the embodiments disclosed in the present invention, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, the embodiments disclosed in the present invention include a computer program product, which includes a computer program carried on a computer-readable medium, and the computer program includes program codes for performing the methods shown in the flowcharts. In such an embodiment, the computer program can be downloaded and installed from the network through the communication section 909, and / or installed from the removable medium 911. When the computer program is executed by the central processing unit (CPU) 901, the above functions defined in the system of the present invention are executed.
[0093] It should be noted that the computer-readable medium shown in the present invention can be a computer-readable signal medium, a computer-readable storage medium, or any combination of the two. A computer-readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples of a computer-readable storage medium can include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present invention, a computer-readable storage medium can be any tangible medium that contains or stores a program, which can be used by or in conjunction with an instruction execution system, apparatus, or device. In the present invention, a computer-readable signal medium can include a data signal propagated in a baseband or as part of a carrier wave, which carries computer-readable program code. Such a propagated data signal can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. A computer-readable signal medium can also be any computer-readable medium other than a computer-readable storage medium, which can send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device. The program code contained on a computer-readable medium can be transmitted using any appropriate medium, including but not limited to: wireless, wire, optical cable, RF, etc., or any suitable combination of the above.
[0094] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present invention. In this regard, each block in a flowchart or block diagram can represent a module, a program segment, or a part of code that contains one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks can occur in a different order than that marked in the accompanying drawings. For example, two consecutive blocks shown can actually be executed substantially in parallel, and they can sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram or flowchart, and the combination of blocks in the block diagram or flowchart, can be implemented by a dedicated hardware-based system for performing the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.
[0095] The modules involved in the embodiments of the present invention can be implemented in software or in hardware. The described modules can also be provided in a processor. For example, it can be described as: a processor includes an acquisition module, a first call module, and a second call module. Among them, the names of these modules do not constitute a limitation on the modules themselves in some cases. For example, the acquisition module can also be described as "a module for acquiring a target process to be loaded".
[0096] As another aspect, the present invention further provides a computer-readable medium. The computer-readable medium can be included in the device described in the above embodiments; or it can exist separately without being assembled into the device. The above computer-readable medium carries one or more programs. When the one or more programs are executed by the device, the device includes: acquiring a target process to be loaded; acquiring a first asynchronous procedure call object from a kernel-mode thread queue corresponding to the target process, and triggering a user-mode through a first callback function registered in the first asynchronous procedure call object; acquiring a second asynchronous procedure call object from a user-mode thread queue corresponding to the target process, and implementing data loading through a second callback function registered in the second asynchronous procedure call object; wherein, parameters corresponding to a target function for implementing data loading are included in the second callback function.
[0097] The above specific embodiments do not limit the protection scope of the present invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can occur depending on design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principle of the present invention should be included within the protection scope of the present invention.
Claims
1. A method for loading data, characterized in that: include: In the kernel mode of the running system, inserting the first asynchronous procedure call object and the second asynchronous procedure call object into the kernel thread queue and the user thread queue corresponding to the target process respectively, including: registering a first callback function indicating triggering the user mode into the first asynchronous procedure call object, and inserting the registered first asynchronous procedure call object into the kernel thread queue corresponding to the target process; registering a second callback function into the second asynchronous procedure call object, and inserting the registered second asynchronous procedure call object into the user thread queue corresponding to the target process, so as to inject the target function into the target process; Get the target process to be loaded; Obtaining a first asynchronous procedure call object from a kernel-mode thread queue corresponding to the target process, and triggering a user-mode mode through a first callback function registered in the first asynchronous procedure call object; A second asynchronous process call object is obtained from the user state thread queue corresponding to the target process, and data loading is implemented through a second callback function registered in the second asynchronous process call object; wherein the second callback function contains parameters corresponding to the target function for implementing data loading.
2. The method according to claim 1, characterized in that Also includes: Using the pre-registered process notification callback function to monitor one or more processes in the startup state in the running system in real time; Among the one or more processes in the startup state, the target process to be injected is screened out according to the process parameters.
3. The method according to claim 1, characterized in that Also includes: The parameters corresponding to the target function and the second callback function are stored in the executable memory corresponding to the target process.
4. The method according to claim 3, characterized in that The parameters corresponding to the target function and the second callback function are stored in two consecutive pages of the executable memory respectively; wherein, The parameters corresponding to the target function are stored on the first page, and the second callback function is stored on the second page.
5. The method according to claim 1, characterized in that When the target process is a native process, the target function is the LdrloadDLL function; or, When the target process is a wow64 process, the target function is the RtlQueueApcWow64Thread function.
6. The method according to claim 1, characterized in that The step of inserting the registered first asynchronous procedure call object into the kernel state thread queue corresponding to the target process includes: Obtain the first thread of the target process in kernel mode; Insert the registered first asynchronous procedure call object into the queue corresponding to the first thread.
7. A data loading device, characterized in that: include: An injection module is used to insert a first asynchronous procedure call object and a second asynchronous procedure call object into a kernel state thread queue and a user state thread queue corresponding to a target process respectively in a kernel state mode of the running system, including: registering a first callback function indicating triggering the user state mode into the first asynchronous procedure call object, and inserting the registered first asynchronous procedure call object into the kernel state thread queue corresponding to the target process; registering a second callback function into the second asynchronous procedure call object, and inserting the registered second asynchronous procedure call object into the user state thread queue corresponding to the target process, so as to inject the target function into the target process; The acquisition module is used to obtain the target process to be loaded; A first calling module is used to obtain a first asynchronous process call object from a kernel thread queue corresponding to the target process, and trigger a user mode through a first callback function registered in the first asynchronous process call object; The second calling module is used to obtain a second asynchronous process call object from the user state thread queue corresponding to the target process, and implement data loading through a second callback function registered in the second asynchronous process call object; wherein the second callback function contains parameters corresponding to the target function for implementing data loading.
8. An electronic device for data loading, characterized in that: include: one or more processors; a storage device for storing one or more programs, When the one or more programs are executed by the one or more processors, the one or more processors implement the method according to any one of claims 1 to 6.
9. A computer readable medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, the method according to any one of claims 1 to 6 is implemented.
Citation Information
Patent Citations
User-Mode Component Injection Techniques
US20170039367A1