Application program shelling method and device, electronic equipment and readable storage medium

By monitoring and starting the shelling thread, setting the compiler filter attribute of the Android system source code to validate only, and dumping the dex file of the dump target application from memory, solving the problem of unshelling and hardening applications in the non-virtual machine environment in the existing technology, and achieving low-privileges and low-cost application shelling.

CN119939563APending Publication Date: 2025-05-06BEIJING BANGCLE TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311443349.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-11-01
Publication Date
2025-05-06

AI Technical Summary

Technical Problem

The existing sandbox shelling method cannot install most apks in the emulator or virtual machine environment. The dynamic shelling method requires high permissions of the application process and may be restricted by security measures of the Android system. It cannot effectively shell and reinforce the application.

Method used

By monitoring the startup of the target application, starting the shelling thread, setting the attribute parameters of the compiler filter in the Android system source code to validate only, verify only the code of the target application, and dump the dex file of the target application from memory.

Benefits of technology

It realizes the shelling of the target application without the need for a virtual machine or emulator environment, reduces the requirements for application process permissions, and can easily and conveniently unsheath the reinforced application, saving costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119939563A_ABST
    Figure CN119939563A_ABST
Patent Text Reader

Abstract

The invention discloses an application program shelling method and device, electronic equipment and a readable storage medium, and belongs to the technical field of computers. The method comprises the following steps: starting a shelling thread under the condition of monitoring that a target application program is started; under the condition that the value of the attribute parameter of the compiler filter in the source code file of the Android system is only verified, only verifying the program code of the target application program in the process of loading the program code of the target application to the memory; through the unshelling thread, dumping a dex file of the target application program from the memory; and storing the dex file.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application belongs to the field of computer technology, and specifically relates to a method, device, electronic device and readable storage medium for de-shelling an application. Background Art

[0002] With the development of smart technology, more and more users are using Android phones in their daily lives.

[0003] For security and encryption reasons, more and more applications are being shelled, and the dex file (Dalvik Executable file) of the application is encrypted, so that the code contained in the dex file cannot be fully visible. Unshelling refers to the attempt to remove or bypass the encryption and protection mechanism of the application in order to analyze, modify or crack the application, which plays an important role in software development, security research and vulnerability analysis. The method of unshelling varies depending on the protection technology of the application.

[0004] There are two current unpacking methods: sandbox unpacking and dynamic unpacking, both of which have certain problems. The sandbox unpacking method is usually performed in an emulator or virtual machine environment, but most apk (Android application package) cannot be installed in an emulator or virtual machine. The dynamic unpacking method requires certain permissions of the application process when used, but the Android system may have different security measures to restrict applications. Summary of the invention

[0005] The purpose of the embodiments of the present application is to provide a method, device, electronic device and readable storage medium for unpacking an application, which can solve the problem that the simulator or virtual machine cannot install the application, resulting in the inability to obtain the unpacking file and the inability to unpack the reinforced application.

[0006] In a first aspect, an embodiment of the present application provides a method for unpacking an application, the method comprising: starting an unpacking thread when a target application is detected to be started; when the value of an attribute parameter of a compiler filter in an Android system source code file is verification only, only verifying the program code of the target application during loading the program code of the target application into memory; dumping a dex file of the target application from the memory through the unpacking thread; and saving the dex file.

[0007] In a second aspect, an embodiment of the present application provides a device for unpacking an application, the device comprising: a monitoring module, for monitoring whether a target application is started, and triggering a startup module when the target application is detected to be started; the startup module is used to start an unpacking thread; a loading module, for verifying only the program code of the target application during the process of loading the program code of the target application into the memory when the value of the attribute parameter of the compiler filter in the Android system source code file is verification only; a dump module, for dumping a dex file of the target application from the memory through the unpacking thread; and a storage module, for saving the dex file.

[0008] In a third aspect, an embodiment of the present application provides an electronic device, which includes a processor and a memory, wherein the memory stores programs or instructions that can be run on the processor, and when the program or instructions are executed by the processor, the steps of the method described in the first aspect are implemented.

[0009] In a fourth aspect, an embodiment of the present application provides a readable storage medium, on which a program or instruction is stored, and when the program or instruction is executed by a processor, the steps of the method described in the first aspect are implemented.

[0010] In a fifth aspect, an embodiment of the present application provides a chip, comprising a processor and a communication interface, wherein the communication interface is coupled to the processor, and the processor is used to run a program or instruction to implement the method described in the first aspect.

[0011] In a sixth aspect, an embodiment of the present application provides a computer program product, which is stored in a storage medium and is executed by at least one processor to implement the method described in the first aspect.

[0012] In an embodiment of the present application, when the target application is detected to be started, the shelling thread is started. The dex file of the target application is dumped from the memory by the shelling thread, and the application information is obtained according to the dex file for further analysis and processing. The shelling method provided in the embodiment of the present application does not require a virtual machine or simulator environment and has low requirements for the permissions of the application. It is simple and convenient to shell the reinforced target application, saving costs. BRIEF DESCRIPTION OF THE DRAWINGS

[0013] Figure 1 It is a flow chart of a method for de-shelling an application program provided by an exemplary embodiment of the present application;

[0014] Figure 2 It is a flowchart of an implementation method of a method for de-shelling an application provided by an exemplary embodiment of the present application;

[0015] Figure 3 is a block diagram of an application deshelling device provided by an exemplary embodiment of the present application;

[0016] Figure 4 is a schematic diagram of an electronic device provided by an exemplary embodiment of the present application;

[0017] Figure 5 It is a structural block diagram of a computer device provided by an exemplary embodiment of the present application. DETAILED DESCRIPTION

[0018] The following will be combined with the drawings in the embodiments of the present application to clearly describe the technical solutions in the embodiments of the present application. Obviously, the described embodiments are part of the embodiments of the present application, rather than all the embodiments. All other embodiments obtained by ordinary technicians in this field based on the embodiments in the present application belong to the scope of protection of this application.

[0019] The terms "first", "second", etc. in the specification and claims of the present application are used to distinguish similar objects, and are not used to describe a specific order or sequence. It should be understood that the data used in this way can be interchangeable under appropriate circumstances, so that the embodiments of the present application can be implemented in an order other than those illustrated or described here, and the objects distinguished by "first", "second", etc. are generally of one type, and the number of objects is not limited. For example, the first object can be one or more. In addition, "and / or" in the specification and claims represents at least one of the connected objects, and the character " / " generally indicates that the objects associated with each other are in an "or" relationship.

[0020] The following is a detailed description of the method for de-shelling an application provided by the embodiment of the present application through specific embodiments and application scenarios in conjunction with the accompanying drawings.

[0021] Figure 1 The present invention provides an exemplary embodiment of an application program de-shelling method. The method 100 can be executed by an electronic device, which can be a mobile phone, a computer or other terminal device, and is not limited in the present embodiment. Figure 1 As shown, the method mainly includes the following steps:

[0022] S101: When detecting that a target application is started, start an unpacking thread.

[0023] In an optional implementation of an embodiment of the present application, before the unpacking thread is started, the method further includes: setting the value of the attribute parameter of the compiler filter in the Android system source code file setting to verification only. Set Compiler Filter (Compiler Filter:: kVerify) in the Android system source code dex2oat.cc file. The full name of dex2oat is: dalvik excutable file to optimized art file, which is a program for compiling and optimizing dex files under the Android system. Setting the value of the attribute parameter of the compiler filter in the Android system source code file setting to verification only can avoid certain forms of optimization from affecting the dex file finally obtained.

[0024] In a specific implementation, when the startup of the target application is monitored, an unshelling thread is started, including: when the startup of the target program is monitored, the target identifier of the target application is obtained; when the target identifier belongs to a preset identifier in the set of application identifiers that need to be unshelled, the unshelling thread is started. The unshelling method for an application provided in an embodiment of the present application obtains the target identifier of the target application when the startup of the target application is detected, and when the target identifier belongs to a preset identifier in the set of application identifiers that need to be unshelled, the unshelling thread is started to unshell the target application, which can ensure that the application to be unshelled is a preset reinforced application that needs to be unshelled, avoids starting applications that do not need to be unshelled, and saves resources.

[0025] Optionally, the target identifier of the target application includes: the package name of the target application. The unpacking method of the application provided in the embodiment of the present application uses the package name of the target application as the target identifier to verify whether the target application belongs to the pre-set application that needs to be unpacked. If it does, the unpacking thread can be started to perform the next unpacking operation. The target identifier of the application can be the package name of the application, and sometimes the class name can also be used.

[0026] In a specific implementation, monitoring the startup of the target application includes: monitoring the running startup of the application through a hook framework to obtain monitoring information; determining the target application based on the monitoring information. The method for unshelling an application provided in an embodiment of the present application monitors the running startup of the application in the Android system through a hook framework to obtain monitoring information, and determines the target application based on the monitoring information. The running startup of the application in the system can be monitored through the hook framework, thereby obtaining the startup information of the target application and determining the startup status of the target application. When the startup of the target application is monitored, the target identifier of the target application is verified, and when the target identifier belongs to a pre-set identifier in the set of application identifiers that need to be unshelled, the unshelling thread of the target application is started.

[0027] S102: When the value of the attribute parameter of the compiler filter in the Android system source code file is verification only, only the program code of the target application is verified during the process of loading the program code of the target application into the memory.

[0028] In a specific implementation, when the value of the attribute parameter of the compiler filter in the Android system source code file is verification only, that is, the code in the Android system source code dex2oat.cc file is: SetCompilerFilter(CompilerFilter::kVerify). In the process of loading the program code of the target application into the memory, only the program code of the target application is verified, so that the target application can be operated accurately and resources are saved.

[0029] S103: dumping the dex file of the target application from the memory through the unpacking thread.

[0030] In a specific implementation, the shelling method of the application provided in the embodiment of the present application dumps the dex file of the target application from the memory through the shelling thread. Dumping generally refers to exporting and transferring data into a file or static form, and the dex file is an executable file of the Android system, which contains all the operating instructions and runtime data of the application. By dumping the dex file of the target application through the shelling thread, the information of the target application can be obtained for the next step of research and development.

[0031] S104: Save the dex file.

[0032] In an embodiment of the present application, the dex file dumped in the memory in the previous step is saved. By obtaining the dex file of the hardened application, you can try to analyze the decryption process, find the decryption key, or crack other protection layers.

[0033] In an embodiment of the present application, when the target application is detected to be started, the shelling thread is started, and when the value of the attribute parameter of the compiler filter in the Android system source code file is verification only, in the process of loading the program code of the target application into the memory, only the program code of the target application is verified; the dex file of the target application is dumped from the memory and saved by the shelling thread, and the application information is obtained according to the dex file for decrypting the application. The shelling method provided in the embodiment of the present application can accurately shell the target application, and can obtain accurate dex files for research. The method provided in the embodiment of the present application has simple operation steps, fewer obstacles encountered when shelling the application, and can save costs and avoid waste of resources.

[0034] Figure 2 The flowchart of the implementation method of the de-shelling method of the application provided by an exemplary embodiment of the present application is shown. The method can be implemented by an electronic device, which can be a terminal device such as a mobile phone or a computer, and is not limited in the specific embodiment of the present application. Figure 2 As shown, the method mainly includes the following steps:

[0035] S201: Set CompilerFilter to verify only in dex2oat.

[0036] Set the code in the Android system source code dex2oat.cc file in advance to: SetCompilerFilter(CompilerFilter::kVerify), and set the CompilerFilter to verification only.

[0037] S202: Start the shelling thread.

[0038] Start the application's unpacking thread and begin unpacking the hardened application.

[0039] S203: Dump dex from memory.

[0040] Dump the dex file of the dump application in memory through the shelling thread.

[0041] S204: Save the dex file.

[0042] Save the dumped dex file for decryption analysis of the application.

[0043] The application shelling method provided in the embodiment of the present application can be executed by an application shelling device. The application shelling method is executed by an application shelling device as an example to illustrate the application shelling device provided in the embodiment of the present application.

[0044] Figure 3 A block diagram of an application deshelling device provided by an exemplary embodiment of the present application is shown. The device can implement the following Figure 1 , Figure 2 All or part of any of the embodiments shown, such as Figure 3 As shown, the application program de-shelling device 300 includes: a monitoring module 301 , a startup module 302 , a loading module 303 , a dump module 304 and a storage module 305 .

[0045] The monitoring module 301 is used to monitor whether the target application is started, and trigger the starting module 302 when the target application is detected to be started.

[0046] The starting module 302 is used to start the unpacking thread.

[0047] The loading module 303 is used to verify only the program code of the target application program when the program code of the target application is loaded into the memory when the value of the attribute parameter of the compiler filter in the Android system source code file is verification only.

[0048] The dump module 304 is used to dump the dex file of the target application from the memory through the unpacking thread.

[0049] The storage module 305 is used to store the dex file.

[0050] In an optional implementation, the application program unpacking device further includes a setting module 306 for setting the value of the attribute parameter of the compiler filter in the Android system source code file setting to verification only.

[0051] In an optional implementation, the monitoring module 301 triggers the startup module 302, including: when the startup of the target program is detected, obtaining the target identifier of the target application; when the target identifier belongs to a pre-set set of application identifiers that need to be unshelled, triggering the startup module 302.

[0052] In an optional implementation, the target identifier of the target application includes: a package name of the target application.

[0053] In an optional implementation, monitoring the startup of the target application includes: monitoring the running startup of the application through a hook framework to obtain monitoring information; and determining the target application according to the monitoring information.

[0054] The shelling device of the application in the embodiment of the present application can be an electronic device, or a component in the electronic device, such as an integrated circuit or a chip. The electronic device can be a terminal, or other devices other than the terminal. Exemplary, the electronic device can be a mobile phone, a tablet computer, a laptop computer, a palmtop, a vehicle-mounted electronic device, a mobile Internet device (Mobile Internet Device, MID), augmented reality (augmented reality, AR) / virtual reality (virtual reality, VR) equipment, a robot, a wearable device, an ultra-mobile personal computer (ultra-mobilepersonal computer, UMPC), a netbook or a personal digital assistant (personal digital assistant, PDA), etc., and can also be a server, a network attached storage (Network Attached Storage, NAS), a personal computer (personal computer, PC), a television (television, TV), a teller machine or a self-service machine, etc., and the embodiment of the present application is not specifically limited.

[0055] The application shell removal device provided in the embodiment of the present application can achieve Figure 1 to Figure 2 To avoid repetition, the various processes implemented by the method embodiment are not described here.

[0056] Alternatively, if Figure 4 As shown, an embodiment of the present application also provides an electronic device 400, including a processor 401 and a memory 402, wherein the memory 402 stores programs or instructions that can be executed on the processor 401, and when the program or instructions are executed by the processor 401, the various steps of the embodiment of the method for unpacking the above-mentioned application are implemented, and the same technical effect can be achieved. To avoid repetition, they are not described here.

[0057] It should be noted that the electronic devices in the embodiments of the present application include the mobile electronic devices and non-mobile electronic devices mentioned above.

[0058] Figure 5The following is a block diagram of a computer device 500 according to an exemplary embodiment of the present application. The computer device 500 may be implemented as the first terminal and the second terminal described above, such as a smart phone, a tablet computer, a laptop computer, a desktop computer, a smart watch, a TV, etc. The computer device 500 may also be referred to as a user device, a portable terminal, a laptop terminal, a desktop terminal, or other names.

[0059] Typically, the computer device 500 includes a processor 501 and a memory 502 .

[0060] The processor 501 may include one or more processing cores, such as a 4-core processor, a 10-core processor, etc. The processor 501 may be implemented in at least one hardware form of DSP (Digital Signal Processing), FPGA (Field-Programmable Gate Array), and PLA (Programmable Logic Array). The processor 501 may also include a main processor and a coprocessor. The main processor is a processor for processing data in the awake state, also known as a CPU (Central Processing Unit); the coprocessor is a low-power processor for processing data in the standby state. In some embodiments, the processor 501 may be integrated with a GPU (Graphics Processing Unit), which is responsible for rendering and drawing the content to be displayed on the display screen. In some embodiments, the processor 501 may also include an AI (Artificial Intelligence) processor, which is used to process computing operations related to machine learning.

[0061] The memory 502 may include one or more computer-readable storage media, which may be non-transitory. The memory 502 may also include a high-speed random access memory, and a non-volatile memory, such as one or more disk storage devices, flash memory storage devices. In some embodiments, the non-transitory computer-readable storage medium in the memory 502 is used to store at least one instruction, which is used to be executed by the processor 501 to implement all or part of the steps in the method for unpacking the application shown in the method embodiment of the present application.

[0062] In some embodiments, the computer device 500 may also optionally include: a peripheral device interface 503 and at least one peripheral device. The processor 501, the memory 502 and the peripheral device interface 503 may be connected via a bus or a signal line. Each peripheral device may be connected to the peripheral device interface 503 via a bus, a signal line or a circuit board. Specifically, the peripheral device includes: at least one of a radio frequency circuit 504, a display screen 505, a camera assembly 506, an audio circuit 507 and a power supply 508.

[0063] In some embodiments, the computer device 500 further includes one or more sensors 509 , including but not limited to: an acceleration sensor 55 , a gyroscope sensor 511 , a pressure sensor 512 , an optical sensor 513 , and a proximity sensor 514 .

[0064] Those skilled in the art will understand that Figure 5 The structure shown in the figure does not constitute a limitation on the computer device 500, and the computer device 500 may include more or less components than those shown in the figure, or combine some components, or adopt a different arrangement of components.

[0065] The embodiment of the present application also provides a readable storage medium, on which a program or instruction is stored. When the program or instruction is executed by a processor, each process of the above-mentioned application program unpacking method embodiment is implemented, and the same technical effect can be achieved. To avoid repetition, it will not be repeated here.

[0066] The processor is the processor in the electronic device described in the above embodiment. The readable storage medium includes a computer readable storage medium, such as a computer read-only memory ROM, a random access memory RAM, a magnetic disk or an optical disk.

[0067] An embodiment of the present application further provides a chip, which includes a processor and a communication interface, wherein the communication interface is coupled to the processor, and the processor is used to run programs or instructions to implement the various processes of the above-mentioned application program unpacking method embodiment, and can achieve the same technical effect. To avoid repetition, it will not be repeated here.

[0068] It should be understood that the chip mentioned in the embodiments of the present application can also be called a system-level chip, a system chip, a chip system or a system-on-chip chip, etc.

[0069] An embodiment of the present application provides a computer program product, which is stored in a storage medium. The program product is executed by at least one processor to implement the various processes of the above-mentioned application program unpacking method embodiment, and can achieve the same technical effect. To avoid repetition, it will not be repeated here.

[0070] It should be noted that, in this article, the terms "comprise", "include" or any other variant thereof are intended to cover non-exclusive inclusion, so that the process, method, article or device including a series of elements includes not only those elements, but also includes other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, the elements defined by the sentence "comprise one..." do not exclude the presence of other identical elements in the process, method, article or device including the element. In addition, it should be pointed out that the scope of the methods and devices in the embodiments of the present application is not limited to performing functions in the order shown or discussed, and may also include performing functions in a substantially simultaneous manner or in reverse order according to the functions involved, for example, the described method may be performed in an order different from that described, and various steps may also be added, omitted, or combined. In addition, the features described with reference to certain examples may be combined in other examples.

[0071] Through the description of the above implementation methods, those skilled in the art can clearly understand that the above-mentioned embodiment methods can be implemented by means of software plus a necessary general hardware platform, and of course by hardware, but in many cases the former is a better implementation method. Based on such an understanding, the technical solution of the present application, or the part that contributes to the prior art, can be embodied in the form of a computer software product, which is stored in a storage medium (such as ROM / RAM, a disk, or an optical disk), and includes a number of instructions for a terminal (which can be a mobile phone, a computer, a server, or a network device, etc.) to execute the methods described in each embodiment of the present application.

[0072] The embodiments of the present application are described above in conjunction with the accompanying drawings, but the present application is not limited to the above-mentioned specific implementation methods. The above-mentioned specific implementation methods are merely illustrative and not restrictive. Under the guidance of the present application, ordinary technicians in this field can also make many forms without departing from the purpose of the present application and the scope of protection of the claims, all of which are within the protection of the present application.

Claims

1. A method for unpacking an application, characterized in that: include: When the target application is detected to be started, the shelling thread is started; When the value of the attribute parameter of the compiler filter in the Android system source code file is verification only, only the program code of the target application is verified during the process of loading the program code of the target application into the memory; Dumping the dex file of the target application from the memory through the shelling thread; Save the dex file.

2. The method according to claim 1, characterized in that Before starting the unpacking thread, the method further includes: Set the value of the attribute parameter of the compiler filter in the Android system source file settings to verify only.

3. The method according to claim 1 or 2, characterized in that: When the target application is detected to be started, the shelling thread is started, including: When the target program is detected to be started, obtaining a target identifier of the target application program; In the case where the target identifier belongs to an identifier in a preset set of application identifiers that need to be unshelled, the unshelling thread is started.

4. The method according to claim 3, characterized in that The target identifier of the target application includes: the package name of the target application.

5. The method according to claim 1 or 2, characterized in that: Monitor the target application startup, including: Monitor the running and startup status of the application through the hook framework and obtain monitoring information; The target application is determined according to the monitoring information.

6. A de-shelling device for an application, characterized in that: include: A monitoring module, used to monitor whether the target application is started, and trigger the startup module when the target application is detected to be started; The startup module is used to start the shelling thread; A loading module, configured to verify only the program code of the target application program when the program code of the target application program is loaded into the memory, when the value of the attribute parameter of the compiler filter in the Android system source code file is verification only; A dump module, used for dumping the dex file of the target application from the memory through the unpacking thread; The storage module is used to store the dex file.

7. The device according to claim 6, characterized in that Also includes: A setting module is used to set the value of the attribute parameter of the compiler filter in the Android system source code file setting to verification only.

8. The device according to claim 6 or 7, characterized in that The monitoring module triggers the starting module, including: When the target program is detected to be started, obtaining a target identifier of the target application program; In the case where the target identifier belongs to an identifier in a preset set of application identifiers that need to be unshelled, the start module is triggered.

9. An electronic device, characterized in that: The method comprises a processor and a memory, wherein the memory stores a program or instruction that can be run on the processor, and when the program or instruction is executed by the processor, the steps of the method for de-shelling an application program as described in any one of claims 1 to 5 are implemented.

10. A readable storage medium, characterized in that: The readable storage medium stores a program or instruction, and when the program or instruction is executed by a processor, the steps of the method for de-shelling an application program as described in any one of claims 1 to 5 are implemented.