Firmware base address positioning method and device based on absolute pointer constraint modeling, electronic equipment and storage medium

By adopting an absolute pointer constraint modeling method in firmware base address positioning, combining the absolute address, function prologue and string sequence characteristics of LDR instructions loading, the problem of inaccurate positioning in the existing technology is solved, and higher accuracy and applicability are achieved.

CN120216394APending Publication Date: 2025-06-27BEIJING UNIV OF POSTS & TELECOMM
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510367165.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-26
Publication Date
2025-06-27

AI Technical Summary

Technical Problem

The prior art has problems with 0xB5 traps and problems of over-reliance on single clues that lead to inaccurate positioning when locating the firmware file base address of ARM device.

Method used

Using the method based on absolute pointer constraint modeling, by analyzing all absolute addresses loaded by LDR instructions in the target firmware, combining function prologue and string sequence features, an absolute address set, a binary function entry address set and a string address set are generated, and the scores of candidate base addresses are counted, and the target base address is finally determined.

Benefits of technology

It improves the accuracy and applicability of firmware base address positioning, avoids the problems of 0xB5 traps and single clue dependencies, and achieves more comprehensive and accurate base address positioning.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120216394A_ABST
    Figure CN120216394A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of electronics, in particular to a firmware base address positioning method and device based on absolute pointer constraint modeling, electronic equipment and a storage medium. And positioning a binary function entry address in the target firmware based on the function ordinal feature and positioning a character string address in the target firmware based on the character string sequence feature to obtain an absolute address set, a binary function entry address set and a character string address set. According to the firmware base address positioning method based on absolute pointer constraint modeling provided by the invention, three types of constraints including a function entry address, a character string address and an absolute address loaded by an LDR instruction are combined, and an optimal base address is determined through a scoring model and is solved through comprehensive constraints; and meanwhile, firmware loading base address positioning is carried out by taking two aspects of function ordinal words and character string sequence features as clues, so that the method has higher accuracy and wider applicability.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of electronic technologies, and in particular, to a method, apparatus, electronic device, and storage medium for locating a firmware base address based on absolute pointer constraint modeling. Background Art

[0002] Firmware generally refers to the underlying software system used to manage and control hardware devices. Embedded device firmware is a software system designed specifically for embedded devices, mainly including peripheral device drivers, a small operating system or operation processing library, and a series of specific processing logics or application functions. When the firmware base address is loaded to the correct position, the corresponding target addresses can be correctly parsed, and the firmware instructions can be correctly executed; if the firmware base address is loaded to the wrong position, the target address will point to the wrong position or exceed the firmware address space, and the corresponding instructions cannot be correctly executed.

[0003] The prior art provides a method for automatically locating the base address of an ARM device firmware file. This method mainly targets firmware files with the ARM / Thumb instruction set and realizes the automatic location of the firmware base address by analyzing the characteristic instructions of the function prologue. First, in the firmware file, it is found that there is some code with a special format at the start of the function module, that is, the function prologue, which stores the structure definition and local variables of the function module. The entry address of each function module is determined according to the format of the function prologue, and then the potential candidate base addresses in the firmware are searched. At the correct loading base address position, the number of function entry addresses it contains will far exceed other positions, so a loading base address location method based on the function entry table is proposed.

[0004] However, in the actual application process, the above method still has technical defects specifically:

[0005] When locating the firmware loading base address based on the function entry table, first, the 0xB5 trap problem will occur;

[0006] Over-reliance on a single clue to locate the firmware loading base address will lead to inaccurate location when the function entry table or function prologue is missing. Summary of the Invention

[0007] In view of this, the purpose of the present invention is to provide a method, apparatus, electronic device, and storage medium for locating a firmware base address based on absolute pointer constraint modeling.

[0008] In the first aspect, an embodiment of the present invention provides a method for locating a firmware base address based on absolute pointer constraint modeling, and the method includes:

[0009] Parse all the absolute addresses loaded by the LDR instruction in the target firmware, and locate the binary function entry addresses in the target firmware based on the function prologue features and the string addresses in the target firmware based on the string sequence features, to obtain an absolute address set, a binary function entry address set, and a string address set;

[0010] Use the range from 0 to the minimum address in the absolute address set as the traversal range of the candidate base address, with a granularity of all even addresses;

[0011] For each candidate base address, count the mapping matching numbers between the absolute addresses in the absolute address set and the binary function entry address set and the string address set, and generate a score;

[0012] Combine all the scores and use the candidate base address with the highest score as the target base address of the target firmware.

[0013] Combined with the first aspect, the steps of parsing all the absolute addresses loaded by the LDR instruction in the target firmware include:

[0014] Based on the target state of the LDR instruction, identify it through the machine code features corresponding to the target state, and calculate the absolute address loaded by the LDR instruction based on the parsing formula corresponding to the target state.

[0015] Combined with the first aspect, the target states include: ARM state and Thumb state;

[0016] The steps of identifying through the machine code features corresponding to the target state based on the target state of the LDR instruction and calculating the absolute address loaded by the LDR instruction based on the parsing formula corresponding to the target state include:

[0017] For the LDR instruction in the ARM state, identify it through the machine code feature 0xE59F, and calculate the absolute address based on the formula address = (pc & 0xFFFFFFFC) + imm12;

[0018] For the LDR instruction in the Thumb state, identify it through the machine code feature 0b01001, and calculate the absolute address based on the formula address = (pc & 0xFFFFFFFC) + (imm8 * 4).

[0019] Combined with the first aspect, the steps of locating the binary function entry addresses in the target firmware based on the function prologue features include:

[0020] Read the binary file of the target firmware into a binary array, and the size of the binary array is the same as the number of file bytes;

[0021] Initialize the offset to 0 and traverse each address in the binary array;

[0022] For each address, based on the parity of the address, when the specified byte meets the preset condition, mark the address as a function entry address;

[0023] Combine all the function entry addresses to obtain the first function entry address set;

[0024] Based on the preset adjustment step size, adjust the offset, traverse each address in the binary array again, and determine the second function entry address set based on the parity of the address until the adjusted offset exceeds the range of the binary array;

[0025] Combine the first function entry address set and all the second function entry address sets to generate a binary function entry address set.

[0026] Combined with the first aspect, the steps of locating the string address in the target firmware based on the string sequence feature include:

[0027] Read the binary file of the target firmware into a binary array, and the size of the binary array is the same as the number of file bytes;

[0028] Initialize the offset to a specified value and traverse each address in the binary array;

[0029] For each address, determine whether the address meets the condition that the corresponding byte is a character within the ASCII range and the previous byte is the padding byte 0x00;

[0030] If so, mark the address as a potential string start address;

[0031] For the potential string start address, when the consecutive bytes after the potential string start address are characters within the ASCII range and the consecutive length reaches the preset threshold, determine that the potential string is a valid string, and record the start address of the valid string to the string address set;

[0032] Increment the offset by the consecutive length, traverse each address in the binary array again to obtain the start address of the valid string to the string address set until the offset exceeds the range of the binary array.

[0033] Combined with the first aspect, after the step of determining whether the address meets the condition that the corresponding byte is a character within the ASCII range and the previous byte is the padding byte 0x00, it further includes:

[0034] Otherwise, adjust the offset based on the second adjustment step size, traverse each address in the binary array again, and judge whether the address meets the preset condition until a target address that meets the condition is obtained, and mark the target address as a potential string start address.

[0035] In combination with the first aspect, for each candidate base address, the steps of counting the mapping matching quantity between the absolute addresses in the absolute address set and the binary function entry address set or the string address set and generating scores include:

[0036] For each candidate base address, initialize the candidate base address to 0x00000000;

[0037] For each absolute address in the absolute address set, iteratively calculate the difference between the absolute address and the candidate base address to obtain the target address;

[0038] If the target address belongs to the binary function entry address set or the string address set, assign a score to the candidate base address.

[0039] In the second aspect, the present application provides a firmware base address positioning device based on absolute pointer constraint modeling. The device includes:

[0040] A parsing and positioning module for parsing all the absolute addresses loaded by the LDR instruction in the target firmware, and positioning the binary function entry addresses in the target firmware based on the function prologue feature and positioning the string addresses in the target firmware based on the string sequence feature to obtain an absolute address set, a binary function entry address set, and a string address set;

[0041] A traversal rule determination module for using the range between 0 and the minimum address in the absolute address set as the traversal range of the candidate base address, and the granularity is all even addresses;

[0042] A score calculation module for, for each candidate base address, counting the mapping matching quantity between the absolute addresses in the absolute address set and the binary function entry address set and the string address set and generating scores;

[0043] A target base address positioning module for combining all the scores and using the candidate base address with the highest score as the target base address of the target firmware.

[0044] In the third aspect, the present application provides an electronic device. The electronic device includes a memory and a processor. The memory is used to store a computer program, and the processor runs the computer program to enable the electronic device to execute the above method.

[0045] In the fourth aspect, the present application provides a readable storage medium. Computer program instructions are stored in the readable storage medium. When the computer program instructions are read and run by a processor, the above method is executed.

[0046] The embodiments of the present invention bring the following beneficial effects: The firmware base address positioning method, device, electronic device, and storage medium provided by this application based on absolute pointer constraint modeling. The method includes parsing all absolute addresses loaded by LDR instructions in the target firmware, and locating the binary function entry addresses in the target firmware based on function prologue features and the string addresses in the target firmware based on string sequence features, to obtain an absolute address set, a binary function entry address set, and a string address set; taking the range between 0 and the smallest address in the absolute address set as the traversal range of candidate base addresses, and the granularity is all even addresses; for each candidate base address, counting the mapping matching numbers between the absolute addresses in the absolute address set and the binary function entry address set and the string address set to generate scores; combining all the scores, and taking the candidate base address with the highest score as the target base address of the target firmware.

[0047] The firmware base address positioning method provided by this application combines three types of constraints: function entry addresses, string addresses, and absolute addresses loaded by LDR instructions. It uses a scoring model to determine the optimal base address through a comprehensive constraint solving method. At the same time, considering function prologue and string sequence features as clues for firmware loading base address positioning, it has higher accuracy and wider applicability.

[0048] Other features and advantages of the present invention will be described in the following specification, and, in part, will be obvious from the specification, or will be understood by implementing the present invention. The objectives and other advantages of the present invention are achieved and obtained by the structures specifically pointed out in the specification, claims, and drawings.

[0049] To make the above objectives, features, and advantages of the present invention more obvious and understandable, the following specific preferred embodiments are given, and in conjunction with the accompanying drawings, the detailed description is as follows. Description of the Drawings

[0050] In order to more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the following will briefly introduce the drawings required for the description of the specific embodiments or the prior art. Obviously, the following drawings are some embodiments of the present invention. For those skilled in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0051] Figure 1 It is a schematic flowchart of a firmware base address positioning method based on absolute pointer constraint modeling provided by an embodiment of the present invention;

[0052] Figure 2 It is a schematic diagram of two types of mapping relationships between function entry addresses - absolute addresses and string addresses - absolute addresses after the firmware is loaded into memory under ideal conditions provided by an embodiment of the present invention;

[0053] Figure 3 Schematic diagram of absolute address loading based on the LDR instruction provided by an embodiment of the present invention;

[0054] Figure 4 Schematic diagram of the structure of a firmware base address positioning device based on absolute pointer constraint modeling provided by an embodiment of the present invention;

[0055] Figure 5 Schematic diagram of the structure of an electronic device provided by an embodiment of the present invention.

[0056] Reference numerals:

[0057] 10 - Parsing and positioning module, 20 - Traversal rule determination module, 30 - Score calculation module, 40 - Target base address positioning module;

[0058] 130 - Processor, 131 - Memory, 132 - Bus, 133 - Communication interface. Specific embodiments

[0059] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0060] To facilitate the understanding of this embodiment, the application scenarios and design concepts of the embodiments of the present application will be briefly introduced below.

[0061] In the prior art, the accuracy of firmware base address positioning is low, and it is difficult to accurately determine the firmware base address.

[0062] Based on this, the embodiments of the present application provide a firmware base address positioning method, device, electronic device, and storage medium based on absolute pointer constraint modeling.

[0063] Embodiment 1

[0064] The present application provides a firmware base address positioning method based on absolute pointer constraint modeling, as shown in combination with Figure 1 The method includes:

[0065] S110, parsing all absolute addresses loaded by the LDR instruction in the target firmware, and positioning the binary function entry address and string address in the target firmware to obtain an absolute address set, a binary function entry address set, and a string address set.

[0066] S120, use the range between 0 and the minimum address in the absolute address set as the traversal range of the candidate base address, with the granularity being all even addresses.

[0067] S130, for each candidate base address, count the mapping matching quantity between the absolute addresses in the absolute address set and the binary function entry address set and the string address set, and generate a score.

[0068] S140, combining all the scores, use the candidate base address with the highest score as the target base address of the target firmware.

[0069] The firmware base address positioning method based on absolute pointer constraint modeling provided by this application combines three types of constraints: function entry address, string address, and absolute address loaded by the LDR instruction. By scoring to determine the optimal base address, and at the same time considering using the function prologue and string sequence features as clues to solve the firmware loading base address constraint positioning, it has higher accuracy and wider applicability.

[0070] The specific process of parsing all the absolute addresses loaded by the LDR instruction in step S110 includes:

[0071] S110, based on the target state of the LDR instruction, identify through the machine code features corresponding to the target state, and calculate the absolute address loaded by the LDR instruction based on the parsing formula corresponding to the target state.

[0072] In ARM firmware, absolute address loading is generally performed through the LDR or ADR instruction. However, the ADR instruction is a relative addressing mode based on the PC and has nothing to do with the loading base address of the firmware. Therefore, this application only considers the absolute address loaded by the LDR instruction. The absolute addresses loaded by the LDR instruction include function entry addresses, string addresses, structure addresses, etc. This work mainly performs constraint modeling through function entry addresses and string addresses. As Figure 2 shown are the two types of mapping relationships between function entry address - absolute address and string address - absolute address after the firmware is loaded into memory under ideal circumstances. The following combines Figure 3 Taking the loading of a string address as an example to illustrate how to load an absolute address based on the LDR instruction. There is a string "somestring" at address 0x23058. Since this address cannot be directly saved through the MOV Register,immediate instruction because the address value cannot be represented as a legal immediate number, an address value of 0x23058 is defined at address 0x1FF98, and this address value is loaded into the register through the LDR instruction, thus completing the loading of the string address.

[0073] Among them, the LDR instruction includes the ARM state and the Thumb state. In this embodiment, traverse the binary code of the target firmware, find the machine code features that conform to the ARM or Thumb state, and according to the current state (ARM or Thumb), apply the corresponding parsing formula to calculate the absolute address, and then store the calculated absolute address into the absolute address set.

[0074] Step S110 includes:

[0075] S111, for the LDR instruction in the ARM state, identify it through the machine code feature 0xE59F, and calculate the absolute address based on the formula address = (pc & 0xFFFFFFFC) + imm12;

[0076] S112, for the LDR instruction in the Thumb state, identify it through the machine code feature 0b01001, and calculate the absolute address based on the formula address = (pc & 0xFFFFFFFC) + (imm8 * 4).

[0077] The comparison of the calculation methods for loading the absolute address in the ARM and Thumb states is shown in Table 1. According to the features in Table 1, the LDR instructions in the two states can be located and parsed respectively.

[0078] Table 1 is a comparison table of the calculation methods for loading the absolute address in the ARM and Thumb states.

[0079]

[0080]

[0081] Specifically, when the target state of the LDR instruction is the ARM state, step S111 includes:

[0082] S1110, read the input binary file into a binary array, and the array size is the same as the number of file bytes.

[0083] S1111, initialize the offset to 0.

[0084] S1112, traverse the binary file. For each LDR instruction, if the first 2 bytes of the LDR instruction are 0xE59F, calculate the addressing address using the following formula:

[0085] address = (pc & 0xFFFFFFFC) + imm12.

[0086] S1113, read and record the 4-byte content of the addressing address to obtain the absolute address finally loaded by the LDR instruction.

[0087] S1114. After the offset is incremented by 4 bytes, steps S1112 - S1113 are repeated until the traversal ends, and an absolute address set is generated by combining all the absolute addresses.

[0088] Among them, in the ARM architecture, the standard format of the LDR instruction is [{LDR} Rd, [Rn, #imm12]]; Rd is the destination register, Rn is the base register (usually PC), and #imm12 is a 12 - bit immediate offset.

[0089] The machine code feature 0xE59F is a specific prefix of the LDR instruction in the ARM state. If an instruction in the firmware starts with 0xE59F, it can be preliminarily determined that this is an LDR instruction in the ARM state. During the parsing process, it is ensured whether the first two bytes of the LDR instruction are 0xE59F to ensure that the current instruction is in the ARM state (rather than the Thumb state). If the target state of the LDR instruction is the ARM state, the absolute address is calculated using the calculation formula of the LDR instruction in the ARM state at this time. If not, it means that the target state of the LDR instruction is not the ARM state but the Thumb state. At this time, after adjusting the offset by +4 bytes, the above steps are performed again until the extracted imm12 exceeds a reasonable range (such as pointing to an invalid memory area).

[0090] Similarly, when the target state of the LDR instruction is the Thumb state, step S111 includes:

[0091] S1115. Read the input binary file into a binary array, and the array size is the same as the number of bytes of the file.

[0092] S1116. Initialize the offset to 0.

[0093] S1117. Traverse the binary file. For each LDR instruction, if the first 5 bytes of the LDR instruction are 0b01001, the addressing address is calculated using the following formula:

[0094] address = (pc & 0xFFFFFFFC)+(imm8 * 4).

[0095] S1118. Read the 4 - byte content of the addressing address and record it to obtain the absolute address finally loaded by the LDR instruction.

[0096] S1119. After the offset is incremented by 2 bytes, steps S1117 - S1119 are repeated until the traversal ends, and an absolute address set is generated by combining all the absolute addresses.

[0097] In this embodiment, first, it is also determined whether it is in the Thumb state according to the characteristics in the LDR instruction. After calculating using the formula corresponding to the Thumb state in this state, the offset is adjusted and the above steps are repeated until the extracted imm8*4 exceeds the reasonable range (such as pointing to an invalid memory area).

[0098] Combined with the first aspect, in step S110, locating the binary function entry address in the target firmware based on the function prologue characteristics specifically includes:

[0099] S1120, read the binary file of the target firmware into a binary array, and the size of the binary array is the same as the number of file bytes.

[0100] S1121, initialize the offset to 0 and traverse each address in the binary array.

[0101] S1122, for each address, based on the parity of the address, when the specified byte meets the preset conditions, mark the address as the function entry address.

[0102] S1123, combine all the function entry addresses to obtain the first function entry address set.

[0103] S1124, adjust the offset based on the preset adjustment step size, traverse each address in the binary array again and determine the second function entry address set based on the parity of the address until the adjusted offset exceeds the range of the binary array.

[0104] S1125, combine the first function entry address set and all the second function entry address sets to generate a binary function entry address set.

[0105] Combined Figure 4 As shown, after reading the binary firmware and traversing, check the parity of each address according to the function prologue characteristics, determine the function entry based on the parity and record it. Subsequently, adjust the offset and perform function entry location again until a binary function entry address set is obtained. Specifically, if the address is even, check whether the contents at the three-byte and four-byte positions of the offset are 0x2DE9. If so, regard the current address as the function entry; if not, adjust the offset and check again whether the contents at the three-byte and four-byte positions are 0x2DE9 until the adjusted offset exceeds the range of the binary array.

[0106] Similarly, if the address is odd, check whether the content at the two-byte position of the offset is 0XB5. If so, regard the current address as the function entry; if not, adjust the offset and check again whether the contents at the three-byte and four-byte positions are 0XB5 until the adjusted offset exceeds the range of the binary array.

[0107] Among them, the function prologue is the first part of the function to start execution. Therefore, the starting address feature of the function can be located by scanning these specific instruction patterns.

[0108] Combined with the first aspect, specifically, the step of locating the string address in the target firmware based on the string sequence feature in step S110 includes:

[0109] S1131, read the binary file of the target firmware into a binary array, and the size of the binary array is the same as the number of file bytes.

[0110] S1132, initialize the offset to the second specified value, and traverse each address in the binary array.

[0111] S1133, for each address, determine whether the address satisfies that the corresponding byte is a character within the ASCII range and the previous byte is the padding byte 0x00.

[0112] S1134, if so, mark the address as a potential string start address.

[0113] S1135, for the potential string start address, when the consecutive bytes after the potential string start address are characters within the ASCII range and the consecutive length reaches the preset value, determine the potential string as a valid string, and record the start address of the valid string to the first string address set.

[0114] S1136, increment the offset by the consecutive length, and traverse each address in the binary array again to obtain the start address of the valid string to the string address set until the offset exceeds the range of the binary array.

[0115] In the actual application process, most firmware characters use the ASCII encoding format, and the firmware character information is shown in Table 2.

[0116] Table 2 is a schematic table of firmware character information.

[0117]

[0118] The ASCII range of the string

[49] can be expressed as (0x09~0x0D)∪(0x20~0x7E). In C language programming, strings are generally stored in character arrays

[50] and end with '\0'.

[0119] For performance considerations, the compiler generally stores strings centrally during compilation, usually using the following steps:

[0120] (1) Identification and collection: Parse the source code to identify and collect strings.

[0121] (2) Duplication removal: Remove duplicates from the collected strings and store each string only once.

[0122] (3) Relocation and alignment: Store the deduplicated strings in a continuous memory area and perform alignment operations, that is, fill in padding bytes 0x00 before the strings so that the start address of each string is an integer multiple of 4.

[0123] (4) Address calculation and replacement: Calculate the new address of each string and replace the references to the strings in the program.

[0124] For the strings centrally stored in the firmware, except for the first string, the first and last bytes of the remaining strings are 0x00. When the initialization offset is the second specified value (in this embodiment, the second specified value is 1 for loop control), check whether the current position is a character within the range and the previous byte is 0x00. If so, it is considered possibly the start position of the string; otherwise, increment the offset by 1 byte and continue the check. After determining the start position of the string, slide and check whether the characters are within the range and calculate the string length, and determine whether the string length is greater than the threshold to distinguish possible misjudged machine codes. If the string reaches the threshold, confirm it as a valid string and record the address of the string. Then adjust the offset, increase the sliding length, and obtain the string address again until the offset exceeds the range and the traversal ends.

[0125] In step S110, the absolute address set PA, the binary function entry address set PF, and the string address set PS are obtained. In an ideal situation, the entries in the union of the string address set box PS and the function entry address set PF can form a one-to-one mapping relationship with the entries in the absolute address set PA. In this case, the calculation formula for the firmware loading base address base can be expressed as base = PA(1)_addr - PS(1)_addr.

[0126] However, due to the inevitable misidentifications and omissions in the LDR instruction parsing algorithm, the function entry address location algorithm, and the string address location algorithm, a complete one-to-one mapping relationship cannot actually be formed. Therefore, this embodiment proposes a comprehensive constraint algorithm based on scoring, aiming to find the candidate base address that can satisfy the most constraints, that is, the candidate base address with the highest score, as the best matching base address.

[0127] It can be understood that the range of the candidate base address does not have to be limited to the entire memory space. Therefore, in this embodiment, two types of constraints are imposed through step S120 to optimize the algorithm efficiency.

[0128] Specifically, S120 includes:

[0129] (1) Candidate base address boundary: The minimum value of the loaded base address is 0x00000000, and the maximum value is min(PA), that is, the loaded base address cannot exceed the smallest absolute address in the absolute address set.

[0130] (2) Candidate base address granularity: Within the candidate base address boundary, all even addresses are used as candidate base addresses. The reason is that the LDR instructions in the ARM state and Thumb state are aligned to four bytes and two bytes respectively, so only even values need to be selected.

[0131] Traverse within the traversal range of the candidate base addresses in the manner based on step S120 to obtain multiple candidate base addresses.

[0132] Combined with the first aspect, step S130 includes:

[0133] S131, for each candidate base address, initialize the candidate base address to 0x00000000.

[0134] S132, for each absolute address in the absolute address set, iteratively calculate the difference between the absolute address and the candidate base address to obtain the target address.

[0135] S133, if the target address belongs to the second set or the third set, assign a score to the candidate base address.

[0136] Subsequently, in step S130, for the target address obtained by iteratively calculating each candidate base address with "PA(i)_addr-base", judge the mapping relationship between the entry and the set. This mapping relationship refers to the mapping relationship between the entry in the absolute address set PA and the entry in the union of the binary function entry address set PF and the string address set PS, that is, whether there is a mapping relationship between PA and PF and / or whether there is a mapping relationship between PA and PS.

[0137] If there is a corresponding mapping relationship, score the candidate base address. Then, adjust the candidate base address to increment by 2 bytes and repeat the above iterative scoring steps until the candidate base address exceeds the upper bound to obtain the score corresponding to each candidate base address.

[0138] It can be understood that there are multiple candidate base addresses, and there are corresponding multiple scores. Among them, there may be two or more equal scores among the multiple scores.

[0139] After that, in step S150, use the candidate base address with the highest score as the target base address and associate it with the target firmware.

[0140] In this way, this application simultaneously considers the factors of function prologue features and string series features in two aspects to locate the firmware loading base address, which can improve the accuracy and applicability of the location.

[0141] Second aspect, the present application provides a firmware base address positioning device based on absolute pointer constraint modeling, combined with Figure 4 As shown, the device includes: a parsing and positioning module 10, a traversal rule determination module 20, a score calculation module 30, and a target base address positioning module 40.

[0142] The parsing and positioning module 10 is used to parse all absolute addresses loaded by LDR instructions in the target firmware, and locate the binary function entry address in the target firmware based on the function prologue feature and the string address in the target firmware based on the string sequence feature, to obtain an absolute address set, a binary function entry address set, and a string address set.

[0143] The traversal rule determination module 20 is used to use the range between 0 and the minimum address in the absolute address set as the traversal range of the candidate base address, and the granularity is all even addresses.

[0144] The score calculation module 30 is used to, for each candidate base address, count the mapping matching numbers of the absolute addresses in the absolute address set with the binary function entry address set and the string address set, and generate a score.

[0145] The target base address positioning module 40 is used to combine all the scores, and use the candidate base address with the highest score as the target base address of the target firmware.

[0146] Third aspect, an embodiment of the present application provides an electronic device, combined with Figure 5 As shown, the electronic device includes a memory 131 and a processor 130. The memory 131 is used to store a computer program, and the processor 130 runs the computer program to enable the electronic device to execute the above method.

[0147] Further, combined with Figure 5 As shown, the electronic device further includes a bus 132 and a communication interface 133. The processor 130, the communication interface 133, and the memory 131 are connected through the bus 132.

[0148] Among them, the memory 131 may include a high-speed random access memory (RAM, Random Access Memory), and may also include a non-volatile memory, such as at least one disk memory. Through at least one communication interface 133 (which can be wired or wireless), a communication connection is realized between the system network element and at least one other network element, and the Internet, wide area network, local area network, metropolitan area network, etc. can be used. The bus 132 can be an ISA bus, a PCI bus, an EISA bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 5It is represented by only one bidirectional arrow, but it does not mean that there is only one bus or one type of bus.

[0149] The processor 130 may be an integrated circuit chip with the ability to process signals. In the implementation process, each step of the above method can be completed by the integrated logic circuit in the hardware of the processor 130 or instructions in the form of software. The above-mentioned processor 130 may be a general-purpose processor, including a central processing unit (CPU for short), a network processor (NP for short), etc.; it may also be a digital signal processor (DSP for short), an application specific integrated circuit (ASIC for short), a field-programmable gate array (FPGA for short), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components. It can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of the present invention. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc. The steps of the method disclosed in combination with the embodiments of the present invention can be directly embodied as being executed and completed by a hardware decoding processor, or executed and completed by a combination of hardware and software modules in the decoding processor. The software module may be located in a mature storage medium in the art such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory, or an electrically erasable programmable memory, a register, etc. This storage medium is located in the memory 131, and the processor 130 reads the information in the memory 131 and combines its hardware to complete the steps of the method in the foregoing embodiments.

[0150] In a fourth aspect, an embodiment of the present application provides a readable storage medium. When computer program instructions stored in the readable storage medium are read and run by a processor, the above-mentioned method is executed.

[0151] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the systems and devices described above can refer to the corresponding processes in the foregoing method embodiments, and will not be elaborated herein.

[0152] In addition, in the description of the embodiments of the present invention, unless otherwise clearly specified and limited, the terms "install", "connect", and "couple" should be understood in a broad sense. For example, it may be a fixed connection, a detachable connection, or an integral connection; it may be a mechanical connection or an electrical connection; it may be directly connected or indirectly connected through an intermediate medium, and it may be the communication inside two components. For those skilled in the art, the specific meanings of the above terms in the present invention can be understood according to specific situations.

[0153] If the above-mentioned functions are implemented in the form of software function units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROMs), random access memories (RAMs), magnetic disks, or optical discs that can store program codes.

[0154] In the description of the present invention, it should be noted that the orientation or positional relationship indicated by the terms "center", "upper", "lower", "left", "right", "vertical", "horizontal", "inner", "outer", etc. is based on the orientation or positional relationship shown in the drawings. It is only for the convenience of describing the present invention and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and thus should not be construed as a limitation to the present invention. In addition, the terms "first", "second", and "third" are only used for descriptive purposes and cannot be understood as indicating or implying relative importance.

[0155] Finally, it should be noted that the above embodiments are only specific embodiments of the present invention, used to illustrate the technical solutions of the present invention, rather than limiting them. The protection scope of the present invention is not limited thereto. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that: any person skilled in the art within the technical scope disclosed by the present invention can still modify the technical solutions described in the foregoing embodiments, or can easily think of changes, or make equivalent replacements for some of the technical features; and these modifications, changes, or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present invention, and should all be covered by the protection scope of the present invention. Therefore, the protection scope of the present invention should be subject to the protection scope of the claims.

Claims

1. A firmware base address positioning method based on absolute pointer constraint modeling, characterized in that: The method comprises: Parse all absolute addresses loaded by LDR instructions in the target firmware, and locate the binary function entry address in the target firmware based on the function preamble feature and locate the string address in the target firmware based on the string sequence feature, to obtain an absolute address set, a binary function entry address set and a string address set; The range from 0 to the minimum address in the absolute address set is used as the traversal range of the candidate base address, and the granularity is all even addresses; For each candidate base address, count the number of mapping matches between the absolute addresses in the absolute address set and the binary function entry address set and the string address set, and generate a score; Combining all the scores, the candidate base address with the highest score is used as the target base address of the target firmware.

2. The method according to claim 1, characterized in that The steps to parse all absolute addresses loaded by LDR instructions in the target firmware include: Based on the target state of the LDR instruction, the absolute address loaded by the LDR instruction is calculated through machine code feature recognition corresponding to the target state and based on the analytical formula corresponding to the target state.

3. The method according to claim 2, characterized in that The target state includes: ARM state and Thumb state; The step of calculating the absolute address loaded by the LDR instruction based on the target state of the LDR instruction by identifying the machine code feature corresponding to the target state and calculating the absolute address loaded by the LDR instruction based on the analytical formula corresponding to the target state comprises: For the LDR instruction in the ARM state, the machine code feature 0xE59F is used to identify the instruction, and the absolute address is calculated based on the formula address=(pc&0xFFFFFFFC)+imm12; The LDR instruction in the Thumb state is identified by the machine code feature 0b01001, and the absolute address is calculated based on the formula address=(pc&0xFFFFFFFC)+(imm8*4).

4. The method according to claim 1, characterized in that: The step of locating the binary function entry address in the target firmware based on the function prologue feature comprises: Reading the binary file of the target firmware into a binary array, the size of the binary array being the same as the number of bytes in the file; Initialize the offset to 0 and traverse each address in the binary array; For each of the addresses, based on the parity of the address, if the designated byte meets a preset condition, marking the address as a function entry address; Combining all of the function entry addresses to obtain a first function entry address set; Adjusting the offset based on a preset adjustment step, traversing each address in the binary array again and determining a second function entry address set based on the parity of the address, until the adjusted offset exceeds the range of the binary array; The first function entry address set and all the second function entry address sets are combined to generate a binary function entry address set.

5. The method according to claim 1, characterized in that The step of locating the string address in the target firmware based on the string sequence feature comprises: Reading the binary file of the target firmware into a binary array, the size of the binary array being the same as the number of bytes in the file; Initialize the offset to a specified value and traverse each address in the binary array; For each address, determine whether the address satisfies the condition that the corresponding byte is a character in the ASCII range and the previous byte is a padding byte 0x00; If so, mark the address as a potential string start address; For the potential string starting address, if the subsequent consecutive bytes corresponding to the potential string starting address are characters within the ASCII range and the consecutive length reaches a preset threshold, the potential string is determined to be a valid string, and the starting address of the valid string is recorded in the string address set; The offset is incremented by the continuous length, and each address in the binary array is traversed again to obtain the starting address of the valid string to the string address set until the offset exceeds the range of the binary array.

6. The method according to claim 5, characterized in that After the step of determining whether the address satisfies the condition that the corresponding byte is a character within the ASCII range and the previous byte is a padding byte 0x00, the step further includes: Otherwise, the offset is adjusted based on the second adjustment step length and each address in the binary array is traversed again to determine whether the address meets the preset condition, until a target address that meets the condition is obtained, and the target address is marked as a potential string starting address.

7. The method according to claim 1, characterized in that For each candidate base address, the step of counting the number of mapping matches between the absolute addresses in the absolute address set and the binary function entry address set or the string address set to generate a score comprises: For each candidate base address, initialize the candidate base address to 0x00000000; For each absolute address in the absolute address set, iteratively calculate the difference between the absolute address and the candidate base address to obtain a target address; If the target address belongs to the binary function entry address set or the string address set, a score is assigned to the candidate base address.

8. A firmware base address positioning device based on absolute pointer constraint modeling, characterized in that: The device comprises: A parsing and positioning module is used to parse all absolute addresses loaded by LDR instructions in the target firmware, and locate the binary function entry address in the target firmware based on the function preamble feature and locate the string address in the target firmware based on the string sequence feature, to obtain an absolute address set, a binary function entry address set and a string address set; A traversal rule determination module, used to use the range from 0 to the minimum address in the absolute address set as the traversal range of the candidate base address, and the granularity is all even addresses; A score calculation module is used to count the number of mapping matches between the absolute addresses in the absolute address set and the binary function entry address set and the string address set for each candidate base address, and generate a score; The target base address positioning module is used to combine all the scores and use the candidate base address with the highest score as the target base address of the target firmware.

9. An electronic device, characterized in that: The electronic device comprises a memory and a processor, wherein the memory is used to store a computer program, and the processor runs the computer program to enable the electronic device to perform the method according to any one of claims 1 to 7.

10. A storage medium, characterized in that: The storage medium stores computer program instructions, and when the computer program instructions are read and executed by a processor, the method according to any one of claims 1 to 7 is executed.