Debugging operation method and terminal
By generating secondary processes in the main process and building callback modules, communication between the main process and the secondary process is established, and the pit-occupying characteristics of the debugging mechanism are used to prevent interference from external debugging tools, solving the problem of malicious debugging of processes and enhancing the security and stability of the program.
Patent Information
- Application Number
- CN202510114873.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-24
- Publication Date
- 2025-05-30
AI Technical Summary
The prior art is difficult to effectively prevent processes from being maliciously debugged by external programs, especially in scenarios where security requirements are high, traditional anti-debugging technology is difficult to provide sufficient security guarantees.
Through the main process, it generates a secondary process with the same structure as its structure, and builds a callback module in the secondary process to establish communication between the main process and the secondary process, and uses the pit-occupying characteristics of the debugging mechanism to prevent interference from external debugging tools.
It realizes secure communication and operating status monitoring between the main process and the secondary process, avoids the risk of directly exposing the main process logic, reduces the possibility that the main process will be attacked or debugged, and enhances the security and stability of the program.
Smart Images

Figure CN120066941A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of data security, and particularly to a debugging and running method and a terminal. Background Art
[0002] In the prior art, process debugging is a common technical means, which is widely used in software development, problem troubleshooting, and performance optimization. However, the debugging mechanism may also be maliciously exploited. An attacker can perform illegal operations on the target process through debugging tools, such as tampering with process data, injecting malicious code, or reverse engineering to analyze the core logic of the process, resulting in abnormal software functions or even data leakage. This problem of a process being maliciously debugged by an external program seriously threatens the security and stability of the software system.
[0003] To protect a process from being maliciously debugged, some protection means have been proposed in the traditional technology. For example, debugging detection technology is used to monitor whether the process is in a debugged state; code obfuscation, anti-debugging technology, etc. are used to interfere with the operation of the debugging tool. However, these methods still have certain limitations when facing highly skilled attackers: the debugging detection technology can be bypassed, and the code obfuscation and anti-debugging mechanisms can be broken by reverse engineering. Especially in some scenarios with high security requirements, such as financial transaction systems, data encryption transmission systems, or commercial software products, relying solely on traditional anti-debugging technology is difficult to provide sufficient security protection. Summary of the Invention
[0004] The technical problem to be solved by the present invention is: to provide a debugging and running method and a terminal to solve the problem of a process being maliciously debugged by an external program.
[0005] To solve the above technical problem, the technical solution adopted by the present invention is: A debugging and running method, comprising the steps of: S1. Controlling the main process to copy itself to generate a sub-process with the same structure as the main process; S2. Constructing a callback module in the sub-process; S3. Setting the sub-process to a debugged state, and establishing communication between the main process and the sub-process by using the callback module; S4. Controlling the main process to transmit execution data to the sub-process by using the debugging mechanism, and receiving the execution feedback of the sub-process for the execution data.
[0006] To solve the above technical problem, another technical solution adopted by the present invention is: A debugging and running terminal, comprising a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, the following steps are completed: S1. Control the main process to copy itself to generate a secondary process with the same structure as the main process; S2. Build a callback module in the secondary process; S3. Set the secondary process to the debug state and use the callback module to establish communication between the main process and the secondary process; S4. Control the main process to transmit execution data to the secondary process using the debugging mechanism and receive the execution feedback of the secondary process for the execution data.
[0007] The beneficial effects of the present invention are as follows: A debugging and running method and a terminal are provided. By the main process copying itself to generate a secondary process and building a callback module in the secondary process, communication and running state monitoring between the main process and the secondary process are achieved. Through the pit occupation feature of the debugging mechanism, external debugging tools are prevented from interfering with the main process and the secondary process. The main process uses the debugging mechanism to perform data transmission and running state monitoring on the secondary process, ensuring that the secondary process executes tasks according to the established logic, avoiding the risk of directly exposing the main process logic. At the same time, by separating the secondary process that executes tasks, the possibility of the main process being attacked or debugged is reduced, enhancing the security and stability of the program. Description of the Drawings
[0008] Figure 1 It is a flowchart of a debugging and running method in an embodiment of the present invention; Figure 2 It is a schematic diagram of a debugging and running terminal in an embodiment of the present invention; Label Description: 1. A debugging and running terminal; 2. A memory; 3. A processor. Detailed Embodiments
[0009] To describe in detail the technical content, achieved objectives, and effects of the present invention, the following is described in conjunction with the embodiments and with reference to the drawings.
[0010] Please refer to Figure 1 and Figure 2 , a debugging and running method, including the steps: S1. Control the main process to copy itself to generate a secondary process with the same structure as the main process; S2. Build a callback module in the secondary process; S3. Set the secondary process to the debug state and use the callback module to establish communication between the main process and the secondary process; S4. Control the main process to transmit execution data to the secondary process using the debugging mechanism and receive the execution feedback of the secondary process for the execution data.
[0011] It is understandable that in the above method, due to the placeholder feature, if the main process crashes, the secondary process will also crash because it is in a debugging state with the main process; if the secondary process crashes, the main process cannot receive information from the secondary process and thus cannot transmit data, resulting in an exception.
[0012] From the above description, it can be seen that the present invention generates a secondary process by the main process replicating itself, and constructs a callback module in the secondary process to achieve communication and running state monitoring between the main process and the secondary process. The core advantage of this method is that through the placeholder feature of the debugging mechanism, it prevents external debugging tools from interfering with the main process and the secondary process, while achieving precise control of the secondary process by the main process. The main process uses the debugging mechanism to perform data transmission and running state monitoring on the secondary process to ensure that the secondary process executes tasks according to the established logic. This design avoids the risk of directly exposing the main process logic, and at the same time, by separating the secondary process that executes tasks, it reduces the possibility of the main process being attacked or debugged, enhancing the security and stability of the program.
[0013] In some embodiments, step S1 specifically includes: Controlling the main process to replicate itself to generate a blank image, and clearing other data in the blank image except for the executable data; Reserving memory in the blank image for data reception and execution; Building the blank image into a secondary process with the same structure as the main process.
[0014] From the above description, by specifically describing the process of the main process replicating itself to generate a secondary process, the implementation manner of the debugging and running method is further refined. The steps of generating and clearing the blank image ensure that only executable data and necessary callback modules are retained in the secondary process, thereby reducing resource waste and improving the running efficiency of the secondary process. By reserving memory in the blank image for receiving and executing data, memory resources can be dynamically allocated to ensure the stability of data transmission and execution. In addition, building the blank image into a secondary process with the same structure as the main process enables the secondary process to accurately simulate the running environment of the main process, thereby enhancing the flexibility and reliability of the debugging and running process, optimizing memory usage, and improving the coordination efficiency between the main and secondary processes.
[0015] In some embodiments, step S3 further includes: Obtaining a string randomly obtained in the main process to construct a main secret key, using a string randomly obtained in the secondary process to construct a secondary secret key, encrypting communication data using the main secret key as a marker, and subsequently performing secondary encryption on the communication data using the secondary secret key as a marker.
[0016] As can be seen from the above description, the solution of double-encrypting communication data with the main secret key and the secondary secret key significantly improves the security of communication between the main and secondary processes. Specifically: generating a secret key through a randomly obtained string can effectively prevent communication data from being intercepted or tampered with externally, ensuring the integrity and confidentiality of the data during transmission. At the same time, the double-encryption mechanism (the combination of the main secret key and the secondary secret key) further enhances the security of communication data, increasing the difficulty of cracking, thus providing multiple layers of protection for data protection during the debugging and running process.
[0017] In some embodiments, the debugging mechanism includes: Step S3 further includes: Detect whether the secondary process is in a debugged state. If so, return data to the main process and establish communication between the main process and the secondary process using the callback module; otherwise, wait to receive the debug return data from the main process.
[0018] As can be seen from the above description, by detecting whether the secondary process is in a debugged state, it is ensured that the communication between the main and secondary processes can be carried out under controlled conditions. When the secondary process is in a debugged state, its running logic is completely controlled by the main process, avoiding interference from external debugging tools. If the secondary process is not in a debugged state, the system will actively enter a waiting state, avoiding blind operations or data transmissions. This design ensures the security and accuracy of communication between the main and secondary processes through real-time detection of the debug state, while reducing unnecessary resource consumption and operation risks. This mechanism can effectively detect external debugging behaviors and stop communication when an anomaly is detected, ensuring the security and reliability of the debugging process.
[0019] In some embodiments, Step S4 further includes: Control the secondary process to execute the execution data transmitted by the main process. When an anomaly is detected, terminate the debugging relationship and issue an alarm.
[0020] As can be seen from the above description, by controlling the secondary process to execute the execution data transmitted by the main process and terminating the debugging relationship and issuing an alarm when an anomaly is detected, the security and stability of the debugging and running method are further improved. In this method, the main process can monitor the running state of the secondary process in real time. Once an anomaly in the secondary process is detected, the main process will immediately terminate the debugging relationship to prevent the anomaly from spreading to the entire system. Through the alarm mechanism, developers can quickly locate the problem and take repair measures, thus reducing the system risks caused by anomalies in the secondary process.
[0021] A debugging and running terminal includes a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, it completes the steps in a debugging and running method. That is, it provides an execution carrier for the above-mentioned debugging and running method.
[0022] Please refer to Figure 1 , Embodiment 1 of the present invention is as follows: A debugging and running method, including the steps: S1. Control the main process to copy itself to generate a sub-process with the same structure as the main process; Specifically, the building process of the above-mentioned sub-process is as follows: Control the main process to copy itself to generate a blank image, and clear other data in the blank image except the executable data; Reserve memory in the blank image for data reception and execution; Build the blank image into a sub-process with the same structure as the main process.
[0023] S2. Build a callback module in the sub-process; S3. Set the sub-process to the debug state, and use the callback module to establish communication between the main process and the sub-process; At the same time, perform encryption during the communication process. The encryption process is as follows: Obtain a string randomly obtained in the main process to construct a main secret key, use a string randomly obtained in the sub-process to construct a sub-secret key, encrypt the communication data with the main secret key as a marker, and then perform secondary encryption on the communication data with the sub-secret key as a marker.
[0024] When decrypting, first decrypt the sub-secret key and then decrypt the main secret key.
[0025] And, detect whether the sub-process is in the debug state. If so, return data to the main process, and use the callback module to establish communication between the main process and the sub-process; otherwise, wait to receive the debug return data from the main process.
[0026] S4. Control the main process to transmit execution data to the sub-process by using the debugging mechanism, and receive the execution feedback of the sub-process for the execution data.
[0027] Control the sub-process to execute the execution data transmitted by the main process. When an exception is detected, terminate the debugging relationship and give an alarm.
[0028] Please refer to Figure 2 , Embodiment 2 of the present invention is as follows: A debugging and running terminal 1, including a memory 2, a processor 3, and a computer program stored on the memory 2 and executable on the processor 3. When the processor 3 executes the computer program, it completes the steps in a debugging and running method. That is, provide an execution carrier for the above-mentioned debugging and running method.
[0029] In summary, a debugging and running method and a terminal provided by the present invention generate a secondary process by copying the main process itself and construct a callback module to achieve communication and running state monitoring between the main process and the secondary process, which have remarkable security, stability and efficiency. Through the placeholder feature of the debugging mechanism, external debugging tools are prevented from interfering with the main process and the secondary process. At the same time, the logic of the main and secondary processes is separated, the risk of the main process being attacked or debugged is reduced, and the overall security of the program is enhanced. The communication data is protected by a dual encryption mechanism to ensure the confidentiality and integrity of data transmission. Through the crash detection, abnormal termination and warning mechanisms, exceptions can be monitored and processed in real time to prevent problems from spreading. The generation of the blank image of the secondary process and the memory optimization design reduce resource waste, improve the efficiency of data transmission and execution, and at the same time maintain the structural consistency of the main and secondary processes, improving the collaborative running ability. Real-time detection of the debugging state of the secondary process ensures that the communication process is carried out under controlled conditions, further enhancing the reliability and flexibility of the program. Overall, the present invention provides a debugging and running solution with high security, efficient resource use and rapid exception handling by optimizing the debugging and running process, which is applicable to scenarios with complex and high security requirements.
[0030] The above are only the embodiments of the present invention, and do not limit the patent scope of the present invention accordingly. Any equivalent transformation made by using the content of the specification and drawings of the present invention, or directly or indirectly applied in the related technical fields, shall be equally included in the patent protection scope of the present invention.
Claims
1. A debugging operation method, characterized in that: Includes steps: S1, controlling the main process to replicate itself to generate a secondary process with the same structure as the main process; S2, constructing a callback module in the secondary process; S3, setting the secondary process to a debugged state, and using the callback module to establish communication between the main process and the secondary process; S4. Control the main process to transmit execution data to the sub-process by using a debugging mechanism, and receive execution feedback from the sub-process for the execution data.
2. A debugging operation method according to claim 1, characterized in that: The step S1 specifically includes: Control the main process to copy itself to generate a blank image, and clear other data except executable data in the blank image; Reserving memory in the blank image for data reception and execution; The blank image is constructed as a secondary process having the same structure as the primary process.
3. A debugging operation method according to claim 1, characterized in that: The step S3 further comprises: Obtain a randomly obtained string in the main process to construct a primary key, use a randomly obtained string in the secondary process to construct a secondary key, use the primary key as a mark to encrypt communication data, and subsequently use the secondary key as a mark to re-encrypt the communication data.
4. A debugging operation method according to claim 1, characterized in that: The debugging mechanism includes: Step S3 also includes: Detect whether the secondary process is in a debugged state. If so, return data to the main process and use the callback module to establish communication between the main process and the secondary process; otherwise, wait to receive debugging return data from the main process.
5. A debugging operation method according to claim 1, characterized in that: The step S4 further comprises: The secondary process is controlled to execute the execution data transmitted by the primary process, and when an abnormality is detected, the debugging relationship is terminated and an alarm is issued.
6. A debugging operation terminal, characterized in that: The invention comprises a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the computer program, the following steps are performed: S1, controlling the main process to replicate itself to generate a secondary process with the same structure as the main process; S2, constructing a callback module in the secondary process; S3, setting the secondary process to a debugged state, and using the callback module to establish communication between the main process and the secondary process; S4. Control the main process to transmit execution data to the sub-process by using a debugging mechanism, and receive execution feedback from the sub-process for the execution data.
7. A debugging and operation terminal according to claim 6, characterized in that: The step S1 specifically includes: Control the main process to copy itself to generate a blank image, and clear other data except executable data in the blank image; Reserving memory in the blank image for data reception and execution; The blank image is constructed as a secondary process having the same structure as the primary process.
8. A debugging operation terminal according to claim 6, characterized in that: The step S3 further comprises: Obtain a randomly obtained string in the main process to construct a primary key, use a randomly obtained string in the secondary process to construct a secondary key, use the primary key as a mark to encrypt communication data, and subsequently use the secondary key as a mark to re-encrypt the communication data.
9. A debugging operation terminal according to claim 6, characterized in that: The debugging mechanism includes: Step S3 also includes: Detect whether the secondary process is in a debugged state. If so, return data to the main process and use the callback module to establish communication between the main process and the secondary process; otherwise, wait to receive debugging return data from the main process.
10. A debugging operation terminal according to claim 6, characterized in that: The step S4 further comprises: The secondary process is controlled to execute the execution data transmitted by the primary process, and when an abnormality is detected, the debugging relationship is terminated and an alarm is issued.