Hot patch processing method based on instruction repair and related device
By parsing the hot patch rules on the server on the client and writing jump instructions in memory to overwrite the vulnerability instructions, the problem of poor timeliness of hot patch processing in the existing technology is solved, realizing instant vulnerability repair and defense.
Patent Information
- Application Number
- CN202510474320.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-16
- Publication Date
- 2025-07-08
AI Technical Summary
Existing hot patch processing requires compiling the patch source file, resulting in poor timeliness for emergency vulnerabilities repair. Users need to upgrade the hot patch library file to defend against it.
The hot patch processing method based on instruction repair is used to obtain the hot patch rules issued by the server, parse the matching target repair instructions, and write jump instructions in memory to overwrite the original vulnerability instructions, realizing instant repair.
Improves the timeliness of vulnerability repair, no need to compile complete files, ensures defense effects, and quickly responds to emergency vulnerabilities.
Smart Images

Figure CN120277676A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer technology, and in particular, to a hot patch processing method based on instruction repair and related devices. Background Art
[0002] The hot patch technology is a technology that can repair software defects without restarting the system or application. It can instantaneously repair errors existing in the software or system while the system is running, thereby significantly reducing the downtime caused by updates or patching, and improving the availability and stability of the system.
[0003] At present, hot patch processing requires compiling the patch source file, which makes it necessary for users to first upgrade the hot patch library file to achieve defense after discovering an emergency vulnerability, resulting in very poor timeliness. Summary of the Invention
[0004] In view of the above problems, this application provides a hot patch processing method based on instruction repair and related devices to achieve the purpose of improving the timeliness of vulnerability repair. The specific solutions are as follows:
[0005] In the first aspect of this application, a hot patch processing method based on instruction repair is provided. The hot patch processing method based on instruction repair is applied to a client, and the hot patch processing method based on instruction repair includes:
[0006] Obtain the hot patch rule of the target vulnerability sent by the server, and parse from the hot patch rule to obtain the target repair instruction that matches the terminal;
[0007] When it is determined to repair the target vulnerability, obtain the instruction length of the first jump instruction, and determine the original vulnerable instruction to be overwritten according to the instruction length;
[0008] Apply for the first memory, and sequentially write the target repair instruction and the second jump instruction into the first memory. The second jump instruction is used to jump to the start address of the next function instruction of the original vulnerable instruction;
[0009] Modify the original vulnerable instruction to the first jump instruction, and the first jump instruction is used to jump to the first memory.
[0010] In a possible implementation, the hot patch rule includes the hot patch repair data of the target vulnerability. The hot patch repair data includes the operating system version range and the repair instruction set for different operating system versions within the operating system version range. The repair instruction set includes repair instructions corresponding to different operating system bit widths and different vulnerability file versions;
[0011] Parsing the target repair instruction that matches the terminal from the hot patch rule includes:
[0012] Obtain the target operating system version, target operating system bit number, and target vulnerability file version corresponding to the terminal;
[0013] Determine whether the target system version is within the operating system version range;
[0014] If so, obtain the target repair instruction set corresponding to the target operating system version, and filter the target repair instruction from the target repair instruction set according to the target operating system bit number and the target vulnerability file version.
[0015] In a possible implementation, the hot patch rule further includes description data of the target vulnerability, and the description data includes a vulnerability type. The method for determining the repair method for the target vulnerability includes:
[0016] If the vulnerability type is a kernel-mode vulnerability and the first driver to which the target vulnerability belongs is a resident system driver, obtain the first feature information of the target vulnerability and the second feature information of the vulnerability repaired by the target repair instruction; when the first feature information is the same as the second feature information, determine to perform repair on the target vulnerability;
[0017] If the vulnerability type is a kernel-mode vulnerability and the second driver to which the target vulnerability belongs is a dynamic system driver, monitor the second driver, and when it is monitored that the second driver is loaded, determine to perform repair on the target vulnerability;
[0018] If the vulnerability type is a user-mode vulnerability, obtain the third feature information of the target vulnerability and the fourth feature information of the vulnerability repaired by the target repair instruction; when the third feature information is the same as the fourth feature information, determine to perform repair on the target vulnerability.
[0019] In a possible implementation, the hot patch processing method based on instruction repair further includes:
[0020] If the vulnerability type is a user-mode vulnerability, before modifying the original vulnerability instruction to the first jump instruction, obtain other threads except the current thread under the vulnerability process and suspend them. The current thread is the thread for hot patch processing, and the vulnerability process is the process where the current thread is located;
[0021] For each suspended thread, determine the current call position of the thread according to the call stack of the thread; if the current call position is within the original vulnerability instruction, adjust the current call position to the start address of the first jump instruction.
[0022] In a possible implementation, the writing of the target repair instruction and the second jump instruction in the first memory in sequence includes:
[0023] Write an audit instruction, the target repair instruction, and the second jump instruction in the first memory in sequence, where the audit instruction is used to output a vulnerability protection warning log.
[0024] In a possible implementation, the hot patch processing method based on instruction repair further includes:
[0025] Apply for a second memory and write the original vulnerability instruction in the second memory.
[0026] A second aspect of this application provides a hot patch processing device based on instruction repair. The hot patch processing method based on instruction repair is applied to a client. The hot patch processing device based on instruction repair includes:
[0027] A rule parsing module, configured to obtain a hot patch rule for a target vulnerability sent by a server, and parse and obtain a target repair instruction matching the terminal from the hot patch rule;
[0028] An instruction repair module, configured to, when it is determined to repair the target vulnerability, obtain the instruction length of the first jump instruction, and determine the original vulnerability instruction to be overwritten according to the instruction length; apply for a first memory, and write the target repair instruction and the second jump instruction in the first memory in sequence, where the second jump instruction is used to jump to the last address of the original vulnerability instruction; modify the original vulnerability instruction to a first jump instruction, where the first jump instruction is used to jump to the first memory.
[0029] A third aspect of this application provides a computer program product, including computer-readable instructions, which, when running on an electronic device, enable the electronic device to implement the hot patch processing method based on instruction repair in the first aspect or any implementation manner of the first aspect.
[0030] A fourth aspect of this application provides an electronic device, including at least one processor and a memory connected to the processor, where:
[0031] The memory is used to store a computer program;
[0032] The processor is used to execute the computer program so that the electronic device can implement the hot patch processing method based on instruction repair according to the first aspect or any implementation manner of the first aspect described above.
[0033] A fifth aspect of the present application provides a computer storage medium carrying one or more computer programs. When the one or more computer programs are executed by an electronic device, the electronic device can implement the hot patch processing method based on instruction repair according to the first aspect or any implementation manner of the first aspect described above.
[0034] By means of the above technical solution, a hot patch processing method based on instruction repair and related devices provided by the present application are applied to a client. The method includes obtaining a hot patch rule for a target vulnerability sent by a server and parsing a target repair instruction matching the terminal from the hot patch rule; when it is determined to repair the target vulnerability, obtaining the instruction length of a first jump instruction and determining the original vulnerable instruction to be overwritten according to the instruction length; applying for a first memory and sequentially writing the target repair instruction and a second jump instruction into the first memory, where the second jump instruction is used to jump to the start address of the next function instruction of the original vulnerable instruction; and modifying the original vulnerable instruction to the first jump instruction, where the first jump instruction is used to jump to the first memory. In the present application, the server can compare the instructions repaired before the vulnerability patch to generate a hot patch rule and send it when the client needs to repair the vulnerability. Thus, when the client repairs the vulnerability, the vulnerability can be repaired by means of instruction overwrite, which eliminates the need to compile a complete file, improves the timeliness of vulnerability repair, and ensures the defense effect. BRIEF DESCRIPTION OF THE DRAWINGS
[0035] In combination with the drawings and with reference to the following specific embodiments, the above and other features, advantages, and aspects of the various embodiments of the present disclosure will become more apparent. Throughout the drawings, the same or similar reference numerals denote the same or similar elements. It should be understood that the drawings are schematic and the elements and elements are not necessarily drawn to scale.
[0036] Figure 1 It is a schematic flowchart of a hot patch processing method based on instruction repair provided by an embodiment of the present application;
[0037] Figure 2 It is a partial schematic flowchart of a hot patch processing method based on instruction repair provided by an embodiment of the present application;
[0038] Figure 3 It is a schematic structural diagram of a hot patch processing device based on instruction repair provided by an embodiment of the present application;
[0039] Figure 4 It is a schematic structural diagram of an electronic device provided by an embodiment of the present application. DETAILED DESCRIPTION
[0040] The embodiments of the present application will be described below with reference to the accompanying drawings in the embodiments of the present application. The terms used in the embodiments of the present application are only used to explain the specific embodiments of the present application, rather than intended to limit the present application.
[0041] The embodiments of the present application will be described below with reference to the accompanying drawings. Those of ordinary skill in the art will know that with the development of technology and the emergence of new scenarios, the technical solutions provided by the embodiments of the present application are also applicable to similar technical problems.
[0042] The terms "first", "second", etc. in the specification of the present application and the above accompanying drawings are used to distinguish similar objects, and do not have to be used to describe a specific order or sequence. It should be understood that such terms can be interchanged under appropriate circumstances, which is only a way of distinguishing when describing objects with the same attributes in the embodiments of the present application. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusion, so that a process, method, system, product or device including a series of units does not have to be limited to those units, but may include other units not clearly listed or inherent to these processes, methods, products or devices.
[0043] See Figure 1 , Figure 1 which is a schematic flowchart of a hot patch processing method based on instruction repair provided by an embodiment of the present application. As Figure 1 shown, a hot patch processing method based on instruction repair provided by an embodiment of the present application, which is applied to a client, may include the following steps S10 to S40, and these steps will be described in detail below.
[0044] S10, obtain the hot patch rule of the target vulnerability sent by the server, and parse from the hot patch rule to obtain the target repair instruction matching the terminal to which it belongs.
[0045] In the embodiments of the present application, the server can realize the unified management of hot patches. Users can customize hot patch rules on the server and can also view the vulnerability handling situations of different clients. Among them, the hot patch rules managed by the server include the description information of different vulnerabilities and the hot patch repair data. Among them, the hot patch repair data contains the repair instructions under different types of terminals.
[0046] In this regard, the server can send the hot patch rule of the vulnerability that the client may need to repair (i.e., the target vulnerability) to the client according to the actual situation of the user. After obtaining the hot patch rule of the target vulnerability, the client parses from the hot patch repair data to obtain the target repair instruction matching the terminal to which it belongs.
[0047] In a possible implementation, the target repair instruction can be obtained by parsing according to the operating system version, the operating system bit number, and the vulnerability file version. Among them, the hot patch rule of the target vulnerability contains the hot patch repair data of the target vulnerability, and the hot patch repair data contains the operating system version range and the repair instruction set for different operating system versions within the operating system version range. The repair instruction set contains the repair instructions corresponding to different operating system bit numbers and different vulnerability file versions. See Figure 2 , Figure 2 which is a partial process schematic diagram of a hot patch processing method based on instruction repair provided by an embodiment of the present application. As Figure 2 shown, a hot patch processing method based on instruction repair provided by an embodiment of the present application, in which step S10, "parsing the target repair instruction that matches the terminal from the hot patch rule", may include the following steps S101 to S103, and these steps will be described in detail below.
[0048] S101, obtaining the target operating system version, the target operating system bit number, and the target vulnerability file version corresponding to the terminal.
[0049] In the embodiment of the present application, the operating system version (i.e., the target operating system version), the operating system bit number (i.e., the target operating system bit number), and the vulnerability file version (i.e., the target vulnerability file version) corresponding to the terminal are obtained according to the configuration information of the terminal.
[0050] S102, determining whether the target system version is within the operating system version range; if so, execute step S103.
[0051] In the embodiment of the present application, determining whether the target system version is within the operating system version range to determine whether the terminal has the target vulnerability. If the target system version is not within the operating system version range, it is determined that the terminal does not have the target vulnerability.
[0052] S103, obtaining the target repair instruction set corresponding to the target operating system version, and screening the target repair instruction from the target repair instruction set according to the target operating system bit number and the target vulnerability file version.
[0053] In the embodiment of the present application, if the target system version is within the operating system version range, it is determined that the terminal has the target vulnerability, and then the repair instruction set corresponding to the target operating system (i.e., the target repair instruction set) is obtained, and the matching repair instruction (i.e., the target repair instruction) is screened from the target repair instruction set using the target operating system bit number and the target vulnerability file version.
[0054] S20, when it is determined to repair the target vulnerability, obtaining the instruction length of the first jump instruction, and determining the original vulnerability instruction to be overwritten according to the instruction length.
[0055] In the embodiment of the present application, after determining that the terminal has a target vulnerability, it is possible to determine whether to repair the target vulnerability currently according to the vulnerability type of the target vulnerability. When it is determined to repair the target vulnerability, the address is offset in the vulnerability function according to the original vulnerability instruction, and the machine code after the offset address in the vulnerability function is disassembled to determine the original vulnerability instruction that will be overwritten by the jump instruction (i.e., the subsequent first jump instruction). Of course, the instruction length of the original vulnerability instruction is greater than or equal to the instruction length of the first jump instruction. The vulnerability function is the function code where the target vulnerability is located.
[0056] For ease of understanding, assume that the instruction length of the first jump instruction is 10. According to the offset address of the original vulnerability instruction in the vulnerability function, it is determined that the function instruction with a vulnerability in the vulnerability function is function instruction a, and the subsequent function instructions in the vulnerability function are function instruction b, function instruction c, function instruction d... in sequence. Continuing to assume that the instruction length of function instruction a is 5, the instruction length of function instruction b is 4, the instruction length of function instruction c is 2, and the instruction length of function instruction d is 4, it can be determined that the original vulnerability instructions overwritten by the first jump instruction include function instruction a, function instruction b, and function instruction c, and an invalid machine code with an instruction length of 1 needs to be added to the end of the first jump instruction.
[0057] In a possible implementation, the hot patch rule also includes description data of the target vulnerability, and the description data includes the vulnerability type. Correspondingly, determining to repair the target vulnerability may include the following steps:
[0058] If the vulnerability type is a kernel-mode vulnerability and the first driver to which the target vulnerability belongs is a resident system driver, obtain the first characteristic information of the target vulnerability and the second characteristic information of the vulnerability repaired by the target repair instruction; when the first characteristic information is the same as the second characteristic information, determine to repair the target vulnerability;
[0059] If the vulnerability type is a kernel-mode vulnerability and the second driver to which the target vulnerability belongs is a dynamic system driver, monitor the second driver, and when it is monitored that the second driver is loaded, determine to repair the target vulnerability;
[0060] If the vulnerability type is a user-mode vulnerability, obtain the third characteristic information of the target vulnerability and the fourth characteristic information of the vulnerability repaired by the target repair instruction; when the third characteristic information is the same as the fourth characteristic information, determine to repair the target vulnerability.
[0061] In the embodiments of the present application, vulnerability types can be divided into kernel-mode vulnerabilities and user-mode vulnerabilities. Among them, kernel-mode vulnerabilities are caused by system driver files, while user-mode vulnerabilities are caused by vulnerabilities in the application itself or the loading of vulnerable dynamic-link libraries (DLLs) during the startup process. The function interfaces of kernel-mode vulnerabilities are divided into resident system drivers and dynamic system drivers. Among them, resident system drivers are automatically loaded and resident after the system starts, and dynamic system drivers are loaded when the system needs them. For the scenario where the vulnerability type is a kernel-mode vulnerability and the first driver to which the target vulnerability belongs is a resident system driver, the first feature information corresponding to the target vulnerability and the second feature information of the vulnerability repaired by the target repair instruction can be obtained. If the first feature information is the same as the second feature information, it is determined to execute the repair on the target vulnerability. Among them, the feature information can be machine code. If the machine code of the target vulnerability is the same as the machine code of the vulnerability repaired by the target repair instruction, it is determined to execute the repair on the target vulnerability.
[0062] For the scenario where the vulnerability type is a kernel-mode vulnerability and the second driver to which the target vulnerability belongs is a dynamic system driver, the second driver can be monitored according to the driver name. When it is monitored that the second driver is loaded, it is determined to execute the repair on the target vulnerability.
[0063] For the scenario where the vulnerability type is a user-mode vulnerability, the third feature information corresponding to the target vulnerability and the fourth feature information of the vulnerability repaired by the target repair instruction can be obtained. If the third feature information is the same as the fourth feature information, it is determined to execute the repair on the target vulnerability. Among them, the feature information can be machine code. If the machine code of the target vulnerability is the same as the machine code of the vulnerability repaired by the target repair instruction, it is determined to execute the repair on the target vulnerability.
[0064] S30, apply for the first memory, and sequentially write the target repair instruction and the second jump instruction into the first memory. The second jump instruction is used to jump to the start address of the next function instruction of the original vulnerability instruction.
[0065] In the embodiments of the present application, apply for the first memory for the target repair instruction, and sequentially write the target repair instruction and the second jump instruction into the first memory. The second jump instruction is used to jump to the start address of the next function instruction of the original vulnerability instruction in the vulnerability function. Continuing with the example where the original vulnerability instruction includes function instruction a, function instruction b, and function instruction c, the jump position of the second jump instruction in the first memory is the start address of function instruction d, that is, after the target repair instruction is executed, function instruction d starts to be executed.
[0066] In a possible implementation, to implement vulnerability protection alerts, an audit instruction, a target repair instruction, and a second jump instruction may be sequentially written into the first memory. The audit instruction is used to output vulnerability protection alert logs. Specifically, by sequentially writing the audit instruction, the target repair instruction, and the second jump instruction into the first memory, the audit instruction can report and output the vulnerability protection alert log after the target repair instruction has completed the repair, enabling the user to view the immunity effect of the terminal on the server page.
[0067] If the vulnerability type of the target vulnerability is a kernel-mode vulnerability, the first memory can be applied for in the system, and the audit instruction, the target repair instruction, and the second jump instruction are sequentially written into the first memory. And the MDL (Memory Descriptor List in English, Memory Descriptor List in Chinese) technology is used to overwrite the original vulnerability instruction in the vulnerable function. First, an MDL is allocated for the specified buffer, then it is ensured that the virtual memory page pointed to is resident in physical memory and locked to prevent it from being swapped out to disk. Secondly, the system virtual address of the physical memory described by the MDL is obtained and the protection type is set for the memory address range to ensure normal reading and writing. Finally, a jump instruction (i.e., the first jump instruction) for jumping to the first memory is written at the mapped memory address, and the resources are released and unlocked after use.
[0068] If the vulnerability type of the target vulnerability is a user-mode vulnerability, after the client's driver layer obtains the hot patch rule, it determines whether there is a vulnerable process to which the hot patch rule is issued by enumerating the currently running processes in the system. And in the case where there is such a vulnerable process, the vulnerable process is added to the monitoring list, and an APC (Asynchronous Procedure Call in English, Asynchronous Procedure Call in Chinese) injection DLL hot patch repair component is performed on the vulnerable process when the vulnerable process starts. After the DLL hot patch repair component is injected into the vulnerable process, it can communicate with the client through the socket. When the communication protocol between the two sides is connected, the client will send the hot patch rule to the DLL hot patch repair component, thereby implementing the hot patch processing method based on instruction repair of the present application through the DLL hot patch repair component. For this, the first memory can be applied for in the vulnerable process, and the audit instruction, the target repair instruction, and the second jump instruction are sequentially written into the first memory.
[0069] In a possible implementation, to restore the target repair instruction to the original vulnerability instruction when the subsequent repair policy changes. The embodiment of the present application can apply for another memory to save the original vulnerability instruction. For this, a hot patch processing method based on instruction repair provided by the embodiment of the present application further includes the following steps:
[0070] Apply for the second memory and write the original vulnerability instruction into the second memory.
[0071] If the vulnerability type of the target vulnerability is a kernel-mode vulnerability, a second memory can be applied for in the system, and the original vulnerability instruction can be written into the second memory. Specifically, the MDL technology is used to first allocate an MDL for a specified buffer, then ensure that the virtual memory page pointed to is resident in physical memory and lock it to prevent it from being swapped out to disk. Secondly, obtain the system virtual address of the physical memory described by the MDL and set the protection type for the memory address range to ensure normal reading and writing. Finally, store the original vulnerability instruction in the second memory at the mapped memory address, and release and unlock the resources after use.
[0072] When processing kernel-layer vulnerabilities, the operating system memory uses the MDL mechanism. By using the MDL for the operating system memory, it is ensured that when encountering inaccessible memory, the memory will not be forcibly modified, resulting in system crashes, and it is ensured that each memory modification is compliant. Using the MDL can precisely control the memory area to be modified. When repairing, lock the specified memory page to keep it in physical memory to prevent the page from being swapped out during memory modification. Secondly, the memory page is mapped to the kernel virtual address space through mapping, eliminating the need for complex address translation, improving the access speed and efficiency. And by dynamically adjusting the protection attributes of the mapped memory, the risk of illegal memory access is avoided, improving the security of the operating system. Finally, the repair instruction is replaced into the system memory. During the repair process, the originally repaired memory will be saved. When the function is turned off, the original instruction will be restored in a safe way of operating the memory to ensure the normal operation of the system.
[0073] If the vulnerability type of the target vulnerability is a kernel-mode vulnerability, apply for a second memory in the vulnerability process, and write the original vulnerability instruction into the second memory.
[0074] S40, modify the original vulnerability instruction to a first jump instruction, and the first jump instruction is used to jump to the first memory.
[0075] In the embodiment of the present application, the original vulnerability instruction is modified to a first jump instruction. Through this first jump instruction, when the vulnerability function executes to the original vulnerability instruction, it can jump to the address of the first memory, and sequentially execute the target repair instructions in the first memory. After the target repair instructions are executed, through the second jump instruction, other function instructions after the original vulnerability instruction in the vulnerability function can be continued to be executed.
[0076] In a possible implementation, for user-mode vulnerabilities, to avoid the impact of the thread performing hot patching in the vulnerability process on other threads, the present application can adjust the call positions of other threads. In this regard, a hot patching processing method based on instruction repair provided by the embodiment of the present application further includes the following steps:
[0077] If the vulnerability type is a user-mode vulnerability, before executing step S40, obtain and suspend other threads in the vulnerable process except the current thread. The current thread is the thread for hot patch processing, and the vulnerable process is the process where the current thread is located.
[0078] For each suspended thread, determine the current call position of the thread according to the call stack of the thread; if the current call position is within the original vulnerability instruction, adjust the current call position to the start address of the first jump instruction.
[0079] In the embodiments of the present application, if the vulnerability type of the target vulnerability is a user-mode vulnerability, during the process of the current thread performing hot patch processing on the target vulnerability, other threads in the vulnerable process can be obtained and suspended.
[0080] For each suspended thread, obtain the current call stack of the thread to determine the current call position of the thread in the vulnerable function; if the current call position is within the original vulnerability instruction, then adjust the current call position value to the start position of the first jump instruction by modifying RIP or EIP. After the current thread finishes performing hot patch processing on the target vulnerability, resume other threads to continue working.
[0081] Through the above description, a hot patch processing method based on instruction repair provided by the embodiments of the present application can summarize repair instructions according to the processing of the vulnerability before and after the vulnerability patch. The repair instruction is to add a repair function on the premise of ensuring that the original function interface can work normally, ensuring that there is no impact on the original function before and after the repair. When applying the hot patch, directly modify the original vulnerability instruction to a jump instruction, which can jump to the repair instruction, and after execution, jump back to the address after the original vulnerability instruction to continue executing the vulnerable function. This realizes a vulnerability protection framework based on policy rules. When encountering a new vulnerability, security protection personnel can write hot patch rules according to the vulnerability protection method, so as to achieve fast hot protection for the newly discovered vulnerability, without waiting for the manufacturer to provide a new hot patch upgrade package, thereby greatly improving the vulnerability fast protection ability.
[0082] The above introduces a device for a hot patch processing method based on instruction repair provided by the embodiments of the present application. See Figure 3 , Figure 3 which is a schematic structural diagram of a hot patch processing device based on instruction repair provided by the embodiments of the present application. As Figure 3 shown, a hot patch processing device based on instruction repair provided by the embodiments of the present application includes:
[0083] A rule parsing module 10, configured to obtain the hot patch rule of the target vulnerability sent by the server and parse and obtain the target repair instruction matching the terminal.
[0084] The instruction repair module 20 is used to obtain the instruction length of the first jump instruction and determine the original vulnerable instruction covered according to the instruction length when it is determined to repair the target vulnerability; apply for the first memory, and sequentially write the target repair instruction and the second jump instruction into the first memory, where the second jump instruction is used to jump to the start address of the next function instruction of the original vulnerable instruction; modify the original vulnerable instruction to the first jump instruction, and the first jump instruction is used to jump to the first memory.
[0085] In a possible implementation, the hot patch rule contains the hot patch repair data of the target vulnerability, and the hot patch repair data contains the operating system version range and the repair instruction sets of different operating system versions within the operating system version range. The repair instruction sets contain the repair instructions corresponding to different operating system bit widths and different vulnerability file versions.
[0086] The rule parsing module used to parse and obtain the target repair instruction that matches the terminal to which it belongs is specifically used for:
[0087] Obtain the target operating system version, target operating system bit width, and target vulnerability file version corresponding to the terminal; determine whether the target system version is within the operating system version range; if so, obtain the target repair instruction set corresponding to the target operating system version, and filter and obtain the target repair instruction from the target repair instruction set according to the target operating system bit width and the target vulnerability file version.
[0088] In a possible implementation, the hot patch rule also contains the description data of the target vulnerability, and the description data contains the vulnerability type. The instruction repair module 20 determines the way to repair the target vulnerability, including:
[0089] If the vulnerability type is a kernel-mode vulnerability and the first driver to which the target vulnerability belongs is a resident system driver, obtain the first feature information of the target vulnerability and the second feature information of the vulnerability repaired by the target repair instruction; when the first feature information is the same as the second feature information, determine to repair the target vulnerability.
[0090] If the vulnerability type is a kernel-mode vulnerability and the second driver to which the target vulnerability belongs is a dynamic system driver, monitor the second driver, and when it is monitored that the second driver is loaded, determine to repair the target vulnerability.
[0091] If the vulnerability type is a user-mode vulnerability, obtain the third feature information of the target vulnerability and the fourth feature information of the vulnerability repaired by the target repair instruction; when the third feature information is the same as the fourth feature information, determine to repair the target vulnerability.
[0092] In a possible implementation, the instruction repair module 20 is also used for:
[0093] If the vulnerability type is a user-mode vulnerability, before modifying the original vulnerability instruction into the first jump instruction, obtain other threads except the current thread under the vulnerable process and suspend them. The current thread is the thread for hot patching processing, and the vulnerable process is the process where the current thread is located; for each suspended thread, determine the current call position of the thread according to the call stack of the thread; if the current call position is within the original vulnerability instruction, adjust the current call position to the start address of the first jump instruction.
[0094] In a possible implementation, the instruction repair module 20 for sequentially writing the target repair instruction and the second jump instruction into the first memory is specifically configured to:
[0095] Sequentially write an audit instruction, the target repair instruction, and the second jump instruction into the first memory. The audit instruction is used to output a vulnerability protection warning log.
[0096] In a possible implementation, the instruction repair module 20 is further configured to:
[0097] Apply for a second memory and write the original vulnerability instruction into the second memory.
[0098] It should be noted that for the refined functions of each module in the embodiments of the present application, reference can be made to the corresponding publicly disclosed parts in the above embodiments of the hot patching processing method based on instruction repair, which will not be elaborated here.
[0099] An electronic device is further provided in the embodiments of the present application. Refer to Figure 4 , Figure 4 which is a schematic structural diagram of an electronic device provided in the embodiments of the present application. The electronic device in the embodiments of the present application may include, but is not limited to, fixed terminals such as mobile phones, laptop computers, PDAs (Personal Digital Assistants), PADs (Tablet Computers), desktop computers, and the like. Figure 4 The electronic device shown is only an example and should not impose any limitation on the functions and usage scope of the embodiments of the present application.
[0100] As Figure 4 shown, the electronic device may include a processing device (such as a central processing unit, a graphics processing unit, etc.) 401, which may perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 402 or a program loaded from a storage device 408 into a random access memory (RAM) 403. When the electronic device is powered on, various programs and data required for the operation of the electronic device are also stored in the RAM 403. The processing device 401, the ROM 402, and the RAM 403 are connected to each other through a bus 404. An input / output (I / O) interface 405 is also connected to the bus 404.
[0101] Typically, the following devices can be connected to the I / O interface 405: input devices 406 including, for example, a touch screen, a touch pad, a keyboard, a mouse, a camera, a microphone, an accelerometer, a gyroscope, etc.; output devices 407 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, etc.; storage devices 408 including, for example, a memory card, a hard disk, etc.; and a communication device 409. The communication device 409 can allow the electronic device to communicate with other devices wirelessly or wiredly to exchange data. Although Figure 4 an electronic device with various devices is shown, it should be understood that it is not required to implement or have all the shown devices. Instead, more or fewer devices can be implemented or had.
[0102] An embodiment of the present application also provides a computer program product including computer-readable instructions, which, when running on an electronic device, enable the electronic device to implement any one of the hot patch processing methods based on instruction repair provided by the embodiments of the present application.
[0103] An embodiment of the present application also provides a computer-readable storage medium carrying one or more computer programs, which, when executed by an electronic device, can enable the electronic device to implement any one of the hot patch processing methods based on instruction repair provided by the embodiments of the present application.
[0104] In addition, it should be noted that the device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. In addition, in the drawings of the device embodiments provided in the present application, the connection relationships between the modules indicate that they have communication connections, which can be specifically implemented as one or more communication buses or signal lines.
[0105] Through the description of the above embodiments, those skilled in the art can clearly understand that the present application can be implemented by means of software plus necessary general hardware. Of course, it can also be implemented by dedicated hardware including application-specific integrated circuits, dedicated CPUs, dedicated memories, dedicated components, etc. Generally, functions accomplished by computer programs can be easily implemented by corresponding hardware, and the specific hardware structures for implementing the same function can also be diverse, such as analog circuits, digital circuits, or dedicated circuits, etc. However, for the present application, in more cases, software program implementation is a better embodiment. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a readable storage medium, such as a floppy disk, USB flash drive, mobile hard disk, ROM, RAM, magnetic disk, or optical disc of a computer, etc., and includes several instructions for causing a computer device (which can be a personal computer, a training device, or a network device, etc.) to execute the methods described in various embodiments of the present application.
[0106] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product.
[0107] The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions described in the embodiments of the present application are generated in whole or in part. The computer can be a general computer, a dedicated computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from a website, a computer, a training device, or a data center to another website, a computer, a training device, or a data center in a wired manner (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or a wireless manner (such as infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium that a computer can store, or a data storage device such as a training device or a data center that includes one or more integrated available media. The available medium can be a magnetic medium (such as a floppy disk, a hard disk, a magnetic tape), an optical medium (such as a DVD), or a semiconductor medium (such as a solid state disk (SSD)), etc.
Claims
1. A hot patch processing method based on instruction repair, characterized in that The hot patch processing method based on instruction repair is applied to the client, and the hot patch processing method based on instruction repair includes: Obtain the hot patch rule of the target vulnerability sent by the server, and parse from the hot patch rule to obtain the target repair instruction that matches the terminal; When it is determined to repair the target vulnerability, obtain the instruction length of the first jump instruction, and determine the original vulnerability instruction to be overwritten according to the instruction length; Apply for the first memory, and sequentially write the target repair instruction and the second jump instruction in the first memory, where the second jump instruction is used to jump to the start address of the next function instruction of the original vulnerability instruction; Modify the original vulnerability instruction to the first jump instruction, where the first jump instruction is used to jump to the first memory; 2. The hot patch processing method based on instruction repair according to claim 1, wherein The hot patch rule contains the hot patch repair data of the target vulnerability, and the hot patch repair data contains the operating system version range and the repair instruction sets of different operating system versions within the operating system version range. The repair instruction sets contain repair instructions corresponding to different operating system bit numbers and different vulnerability file versions; The parsing from the hot patch rule to obtain the target repair instruction that matches the terminal includes: Obtain the target operating system version, target operating system bit number, and target vulnerability file version corresponding to the terminal; Judge whether the target system version is within the operating system version range; If so, obtain the target repair instruction set corresponding to the target operating system version, and filter out the target repair instruction from the target repair instruction set according to the target operating system bit number and the target vulnerability file version; 3. The hot patch processing method based on instruction repair according to claim 2, wherein The hot patch rule also contains the description data of the target vulnerability, and the description data contains the vulnerability type. The method for determining to repair the target vulnerability includes: If the vulnerability type is a kernel-mode vulnerability and the first driver to which the target vulnerability belongs is a resident system driver, obtain the first feature information of the target vulnerability and the second feature information of the vulnerability repaired by the target repair instruction; when the first feature information is the same as the second feature information, determine to repair the target vulnerability; If the vulnerability type is a kernel-mode vulnerability and the second driver to which the target vulnerability belongs is a dynamic system driver, monitor the second driver, and when it is monitored that the second driver is loaded, determine to repair the target vulnerability; If the vulnerability type is a user-mode vulnerability, obtain the third feature information of the target vulnerability and the fourth feature information of the vulnerability repaired by the target repair instruction; when the third feature information is the same as the fourth feature information, determine to repair the target vulnerability; 4. The hot patch processing method based on instruction repair according to claim 3, characterized in that, The hot patch processing method based on instruction repair also includes: If the vulnerability type is a user-mode vulnerability, before modifying the original vulnerability instruction into a first jump instruction, obtain and suspend other threads except the current thread under the vulnerable process, where the current thread is the thread for hot patching processing, and the vulnerable process is the process where the current thread is located; For each suspended thread, determine the current call position of the thread according to the call stack of the thread; if the current call position is within the original vulnerability instruction, adjust the current call position to the start address of the first jump instruction.
5. The hot patch processing method based on instruction repair according to claim 1, characterized in that The writing of the target repair instruction and the second jump instruction into the first memory in sequence includes: Write an audit instruction, the target repair instruction, and the second jump instruction into the first memory in sequence, where the audit instruction is used to output a vulnerability protection warning log.
6. The hot patch processing method based on instruction repair according to claim 1, characterized in that The hot patching processing method based on instruction repair further includes: Apply for a second memory and write the original vulnerability instruction into the second memory.
7. A hot patch processing device based on instruction repair, characterized in that The hot patching processing method based on instruction repair is applied to a client, and the hot patching processing device based on instruction repair includes: A rule parsing module, configured to obtain the hot patching rule of the target vulnerability sent by the server and parse and obtain the target repair instruction matching the terminal from the hot patching rule; An instruction repair module, configured to, when it is determined to repair the target vulnerability, obtain the instruction length of the first jump instruction and determine the original vulnerability instruction to be overwritten according to the instruction length; apply for a first memory and write the target repair instruction and the second jump instruction into the first memory in sequence, where the second jump instruction is used to jump to the start address of the next function instruction of the original vulnerability instruction; modify the original vulnerability instruction into a first jump instruction, where the first jump instruction is used to jump to the first memory.
8. A computer program product, characterized in that, It includes computer-readable instructions, and when the computer-readable instructions run on an electronic device, the electronic device is enabled to implement the hot patching processing method based on instruction repair as described in any one of claims 1 to 6.
9. An electronic device, characterized in that, It includes at least one processor and a memory connected to the processor, where: The memory is used to store a computer program; The processor is configured to execute the computer program so that the electronic device can implement the hot patching processing method based on instruction repair as described in any one of claims 1 to 6.
10. A computer storage medium, characterized in that, The storage medium carries one or more computer programs, and when the one or more computer programs are executed by an electronic device, the electronic device can be enabled to implement the hot patching processing method based on instruction repair as described in any one of claims 1 to 6.
Citation Information
Cited By
Industrial control vulnerability repair system based on node dynamic upgrade
CN122365513A