A Method for Locating the Base Address and Size of ntoskrnl.exe in Memory Based on Exported Functions
By comparing the function address with ImageBase and ImageSize of each module based on the export function, the problem of unstable positioning of the tonoskrnl.exe module in the prior art is solved, and absolutely accurate module positioning and information acquisition are achieved.
Patent Information
- Application Number
- CN202411422891.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-10-12
- Publication Date
- 2025-05-30
- Estimated Expiration
- 2044-10-12
AI Technical Summary
The prior art has instability when locating the ntoskrnl.exe module in Windows system memory, which may lead to the inability to obtain module information correctly.
A method based on export functions is adopted, by selecting a function A exported in ntoskrnl.exe, its location in memory is determined, and the identity of the module is determined by comparing the function address with the ImageBase and ImageSize of each module.
The absolute accurate positioning of the ntoskrnl.exe module is achieved, which avoids the instability problem in the prior art and ensures the ability to correctly obtain module information.
Smart Images

Figure CN119336654B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of memory addressing, and in particular, to a method for locating the base address and size of ntoskrnl.exe in memory based on exported functions. Background Art
[0002] During the development of anti-virus or advanced threat detection software, due to concerns that functions provided by various operating systems required may be tampered with by viruses, advanced threat detection software needs to find the ntoskrnl.exe module (which can be understood as the Windows kernel and exports many functions for developers to directly use) that has been loaded into the Windows system memory before working; by obtaining the loading address and size information of this module, the location of this module in the folder can be obtained, and then reloaded into memory, so that functions that have not been contaminated or tampered with can be used for virus detection and killing operations. At this time, a fast and stable method is needed to find the ntoskrnl.exe module among the many modules already loaded in memory.
[0003] Currently, the publicly available technical solution is to write a Windows driver and use the _LDR_DATA_TABLE_ENTRY structure of the driver itself to traverse the modules already loaded in memory (including ntoskrnl.exe). Most of the time, the ntoskrnl.exe module is in the third position, that is, the ntoskrnl.exe can be found by counting to the third module. However, this method is unstable and may go wrong; as a result, the information of the ntoskrnl.exe module cannot be correctly obtained. Summary of the Invention
[0004] The purpose of the present invention is to solve the problem of instability in locating the address of the ntoskrnl.exe module in the prior art, and to propose a method for locating the base address and size of ntoskrnl.exe in memory based on exported functions.
[0005] In order to achieve the above purpose, the present invention adopts the following technical solutions:
[0006] A method for locating the base address and size of ntoskrnl.exe in memory based on exported functions, comprising the following steps:
[0007] S1. Select a function A exported by ntoskrnl.exe and determine its location in memory;
[0008] S2. Query the information of all modules loaded into memory and determine the information size of all loaded modules;
[0009] S3. Apply for a memory space with the same size as the size of the loaded module information obtained in step S2 for storing information;
[0010] S4. Query all the module information loaded into the memory again and store the result in the memory space applied for in step S3;
[0011] S5. Use a variable of type PRTL_PROCESS_MODULE_INFORMATION to traverse the ImageBase and ImageSize of the module;
[0012] S6. Use the address of function A obtained in step S1 to compare the sum of ImageBase + ImageSize of each module;
[0013] S7. If the address of function A is greater than or equal to the ImageBase of a certain module and less than the ImageBase + ImageSize of this module; then, it can be determined that the address of function A is within the memory range occupied by this module, and this module must be ntoskrnl.exe.
[0014] In some embodiments, the function A is the NtOpenFile function.
[0015] In some embodiments, in step S1, the MmGetSystemRoutineAddress function is used to determine the position of function A in the memory.
[0016] In some embodiments, in step S2, the ZwQuerySystemInformation function is used for the first time to query all the module information loaded into the memory.
[0017] In some embodiments, in step S3, the ExAllocatePoolWithTag function is used to apply for a memory space with the same size as the size of the loaded module information obtained in step S2.
[0018] In some embodiments, in step S4, the ZwQuerySystemInformation function is used again to query all the module information loaded into the memory.
[0019] Compared with the prior art, the present invention provides a method for locating the base address and size of ntoskrnl.exe in the memory based on an exported function, having the following beneficial effects.
[0020] 1. In the present invention, through a function exported from ntoskrnl.exe, using its address to analogize the module information, the ntoskrnl.exe module is found, with absolute accuracy.
[0021] 2. The present invention calls the ZwQuerySystemInformation function twice. The first call is to accurately know the size of all loaded module information, so as to determine how much memory space needs to be allocated to store the result returned by the second call to the ZwQuerySystemInformation function.
[0022] 3. In the present invention, since the selected function is exported by the ntoskrnl.exe module, the address of this function in memory must be within the memory range occupied by the ntoskrnl.exe module. Therefore, as long as the address of this function in memory is greater than or equal to the ImageBase of a certain module and less than the ImageBase + ImageSize of this module, then this module must be ntoskrnl.exe, and no error will occur.
[0023] Other advantages, objectives and features of the present invention will be described to some extent in the subsequent specification; and to some extent, based on the study of the following text, it will be obvious to those skilled in the art; or, teachings can be obtained from the practice of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS
[0024] Figure 1 It is a flowchart of the invention. DETAILED DESCRIPTION OF THE INVENTION
[0025] The following clearly and completely describes the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments.
[0026] Refer to Figure 1 , a method for locating the base address and size of ntoskrnl.exe in memory based on an exported function, comprising the following steps:
[0027] S1. Select a function A exported by ntoskrnl.exe; and determine its location in memory;
[0028] S2. Query the information of all modules loaded into memory to determine the information size of all loaded modules;
[0029] S3. Allocate a memory space with the same size as the information of the loaded modules obtained in step S2 for storing information;
[0030] S4. Query the information of all modules loaded into memory again, and store the result in the memory space allocated in step S3;
[0031] S5. Use a variable of type PRTL_PROCESS_MODULE_INFORMATION to traverse the ImageBase (module base address, i.e., the first address in memory after loading) and ImageSize (module size) of the module;
[0032] S6. Use the address of function A obtained in step S1 to compare the sum of ImageBase + ImageSize of each module;
[0033] It can be understood that the base address of the module in memory + the size of the module can determine the memory range occupied by the module in memory; if the module has exported functions, the address of the exported function must be within this memory range;
[0034] S7. If the address of function A is greater than or equal to the ImageBase of a certain module and less than the ImageBase + ImageSize of that module; then, it can be determined that the address of function A is within the memory range occupied by that module, and that module must be ntoskrnl.exe;
[0035] That is, the ntoskrnl.exe module in memory is found.
[0036] Among them:
[0037] Preferably, the function A uses the NtOpenFile function.
[0038] It can be understood that any function exported from ntoskrnl.exe can be selected.
[0039] In step S1:
[0040] Use the MmGetSystemRoutineAddress function to determine the location of function A in memory;
[0041] That is, select an exported function NtOpenFile from ntoskrnl.exe; and use the MmGetSystemRoutineAddress function to determine the location of the NtOpenFile function in memory.
[0042] In step S2:
[0043] Use the ZwQuerySystemInformation function for the first time to query information about all modules loaded into memory and determine the information size of all loaded modules.
[0044] In step S3:
[0045] Use the ExAllocatePoolWithTag function to apply for a memory space with the same size as the size of the loaded module information obtained in step S2 for storing information.
[0046] In step S4:
[0047] Use the ZwQuerySystemInformation function again to query the information of all modules loaded into memory and store the result in the memory space applied for in step S3.
[0048] In the present invention, through a function exported from ntoskrnl.exe, using its address to analogize the information of each module, the ntoskrnl.exe module can be found with absolute accuracy.
[0049] In the present invention, the ZwQuerySystemInformation function needs to be called twice; the first call is to accurately know the size of all loaded module information, so as to determine how much memory space needs to be applied for to store the result returned by the second call of the ZwQuerySystemInformation function.
[0050] In the present invention, since the selected function A (NtOpenFile function) is exported from the ntoskrnl.exe module, the address of the NtOpenFile function in memory must be within the memory range occupied by the ntoskrnl.exe module; therefore, as long as the address of the NtOpenFile function in memory is greater than or equal to the ImageBase of a certain module and less than the ImageBase + ImageSize of this module, then this module must be ntoskrnl.exe without any errors.
[0051] The above is only a preferred specific embodiment of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention, according to the technical solution and inventive concept of the present invention, makes equivalent replacements or changes, and all should be covered within the protection scope of the present invention.
[0052] In the description of this specification, the descriptions with reference to the terms "one embodiment", "some embodiments", "example", "specific example", or "some examples", etc. mean that the specific features, structures, materials, or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials, or characteristics described may be combined in any one or more embodiments or examples in a suitable manner. In addition, without contradiction, those skilled in the art can combine and combine the different embodiments or examples described in this specification and the features of different embodiments or examples.
[0053] Although the embodiments of the present invention have been shown and described above, it can be understood that the above embodiments are exemplary and should not be construed as limiting the present invention. Those of ordinary skill in the art can make changes, modifications, substitutions, and variations to the above embodiments within the scope of the present invention.
Claims
1. A method for locating the base address and size of ntoskrnl.exe in memory based on an export function, characterized in that: The following steps are involved: S1. Select a function A exported from ntoskrnl.exe and determine its location in memory. S2. Query all module information loaded into the memory and determine the information size of all loaded modules; S3, applying for a memory space of the same size as the size of the loaded module information obtained in step S2, for storing the information; S4, query all module information loaded into the memory again, and store the result in the memory space applied for in step S3; S5. Use variables of type PRTL_PROCESS_MODULE_INFORMATION to traverse the module's ImageBase and ImageSize; S6, using the address of function A obtained in step S1, to compare the sum of ImageBase+ImageSize of each module; S7. If the address of function A is greater than or equal to the ImageBase of a module and less than the ImageBase+ImageSize of the module, then it can be determined that the address of function A is in the memory range occupied by the module, and the module is ntoskrnl.exe.
2. The method for locating the base address and size of ntoskrnl.exe in memory based on the export function according to claim 1, characterized in that: The function A is the NtOpenFile function.
3. The method for locating the base address and size of ntoskrnl.exe in memory based on the export function according to claim 1, characterized in that: In step S1, the MmGetSystemRoutineAddress function is used to determine the location of function A in memory.
4. The method for locating the base address and size of ntoskrnl.exe in memory based on the export function according to claim 1, characterized in that: In step S2, the ZwQuerySystemInformation function is used for the first time to query the information of all modules loaded into the memory.
5. The method for locating the base address and size of ntoskrnl.exe in memory based on the export function according to claim 1, characterized in that: In step S3, the ExAllocatePoolWithTag function is used to apply for a memory space of the same size as the size of the loaded module information obtained in step S2.
6. The method for locating the base address and size of ntoskrnl.exe in memory based on the export function according to claim 1, characterized in that: In step S4, the ZwQuerySystemInformation function is used again to query the information of all modules loaded into the memory.
Citation Information
Patent Citations
Method for implementing module logicalization
CN101114940A
Computer-implemented method and a system for encoding a heap application memory state using shadow memory
US20180089109A1