Binary program dynamic analysis method based on process hollowing-out technology
Through the dynamic analysis method supported by process hollowing technology and kernel modules, the flexibility and memory interference problems of dynamic fine-grained analysis on the Windows platform are solved, and efficient and flexible binary program analysis is achieved, suitable for large applications and malicious code analysis.
Patent Information
- Application Number
- CN202510556008.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-29
- Publication Date
- 2025-07-11
- Estimated Expiration
- 2045-04-29
AI Technical Summary
The existing technology dynamic fine-grained analysis method on the Windows platform is insufficient flexibility, making it difficult to directly deploy in the target system, and has a great impact on memory allocation, resulting in inconsistent analysis results.
Using process hollowing technology and kernel module support, an analysis environment is built in an independent hollowing process, simplifying shadow memory allocation and management, and aiding analysis thread synchronization through kernel modules to reduce the impact on the target program.
Improves the performance and flexibility of dynamic binary analysis, can be directly deployed in real target environments, simplifies the complexity of the analysis framework, reduces performance overhead, and is suitable for analysis of large applications and malicious code.
Smart Images

Figure CN120296736A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of software security analysis, and particularly relates to a dynamic analysis method for binary programs based on process hollowing technology. Background Art
[0002] Nowadays, network attack activities occur frequently. The main culprits are various vulnerable applications and malicious programs delivered to target systems. With the increase of software security policies, simple program analysis has become difficult to discover potential security vulnerabilities or threats. More fine-grained and logically rich analysis methods are important requirements in various scenarios. Similarly, for malicious programs, attackers are also using more concealed obfuscation means to hide the true executed functions. Security personnel and automated analysis platforms need to conduct more detailed analysis of malicious code, rather than just obtaining the basic behaviors of the program through function interception. For example, some malicious codes on the Windows system use system-unpublished interfaces to call system functions to avoid traditional function-hooking-based detection methods. Moreover, for many years, security researchers have been studying dynamic fine-grained analysis methods, represented by dynamic data flow analysis or dynamic taint analysis, and have achieved many results. At the same time, they also face some challenges, such as: the need to improve analysis performance, adapt to new analysis environments, meet special customized analysis requirements, rely on the support of virtualization technology, etc.
[0003] Existing technical solutions focus on constructing new analysis solutions, but mainly based on or oriented to the Linux system environment. In fact, the demand for program and malicious code analysis on the Windows platform is greater, but the relevant supporting technical methods are insufficient. These solutions mainly rely on virtualization methods, lack flexibility during deployment, and are difficult to directly deploy and implement analysis in the target system. There are also studies on application-layer dynamic instrumentation methods, and more efficient and in-depth analysis methods are constructed based on this. However, they fail to fully exploit the characteristics of the operating system and still have deficiencies in terms of practicality. In addition, with the popularization of the 64-bit system environment, the scale of program code has increased, and more memory space is occupied during operation, which also brings new challenges to the design and implementation of the analysis framework.
[0004] Performing fine-grained program dynamic analysis requires instrumenting the target program, which may affect its normal operation. In particular, the large allocation of shadow memory will affect the virtual memory space layout of the target process. These large occupancies will change the memory address allocation positions normally used by the target program, which may cause changes in the execution process of the application program. For example, some exploit programs use the heap spraying technique to perform memory layout to achieve the goal of code execution, and there are also differences in the heap spraying ranges of different samples. Therefore, when performing dynamic analysis on special application programs such as some software with large memory occupancy and exploit programs, if too many interfering factors are introduced into the target process space, it is easy to cause conflicts in memory address allocation and other situations, resulting in the execution result of the program being inconsistent with the expectation. Summary of the Invention
[0005] The object of the present invention is to provide a dynamic program analysis method based on the process hollowing technology in view of the problems existing in the above-mentioned prior art, further expanding the decoupled analysis idea, supporting through the introduction of a kernel module, and constructing analysis code in an independent hollowed process to improve the analysis performance and flexibility and reduce the impact on the normal execution of the target program. A new memory allocation and management scheme for dynamic fine-grained binary analysis is proposed. By constructing the memory layout required for dynamic data flow analysis in the hollowed process, the difficulty of shadow memory allocation and storage is simplified, and the dynamic fine-grained binary analysis ability is further improved. In the analysis of binary programs, the application of the present invention can especially expand the applicable scope of dynamic analysis and improve the analysis performance.
[0006] The technical solution for achieving the object of the present invention is: a dynamic program analysis method based on the process hollowing technology, the method comprising the following steps:
[0007] Step 1, according to the actual analysis scenario and target, construct and configure a basic analysis host program, construct analysis task check function code and define user interaction interfaces therein, and after completion, compile and generate a new analysis host program, which will be mapped into the hollowed process.
[0008] Step 2, in view of the characteristics of the target program to be analyzed and specific analysis requirements, construct a dynamic link library module to be loaded by the instrumentation tool, and construct corresponding analysis functions based on the interfaces provided by the general instrumentation tool during construction, including execution code tracing, runtime information recording, and analysis code construction.
[0009] Step 3, start the target program to be analyzed through the general instrumentation tool, create an instrumentation process where the target program actually runs, and this process will load the dynamic link library module constructed in Step 2 during startup to complete functions such as memory allocation during program operation and instrumentation of the target program.
[0010] Step 4, based on Step 3, the functional modules in the instrumentation tool will create a hollowing process and simultaneously load the new analyzed host program constructed in Step 1, and the analysis code will run in the context of this process.
[0011] Step 5, based on Step 4, after the hollowing process runs, it continues to load the pre-compiled and constructed kernel driver module to assist in the subsequent analysis environment initialization and program analysis processes, and then it will start the analysis environment initialization process, including creating analysis threads, saving the running state, and adjusting the memory layout of the hollowing process, etc.
[0012] Step 6, execute the analysis code corresponding to the target program in the hollowing process, and then the kernel module is responsible for notifying the analysis thread to start executing the analysis code. The analysis thread executes the analysis code pre-constructed in Step 2 and loops to obtain runtime information and subsequent analysis code to complete the entire program analysis process.
[0013] Step 7, during the execution and analysis of the target program, when the target program executes a system call related to a synchronization event, the kernel module will switch the buffer of the current thread to accelerate the analysis process and alleviate the analysis synchronization problem in a multi-threaded scenario.
[0014] Step 8, after the analysis code corresponding to the target program is executed, it triggers an analysis task set in Step 2. For the analysis tasks that need to be checked, after the target program completes the analysis tasks, it will enter the kernel module, and the kernel module checks and outputs the analysis results.
[0015] Compared with the prior art, the significant advantages of the present invention are as follows:
[0016] (1) The present invention uses the process hollowing technology and kernel technology to achieve dynamic binary program analysis, expands the ability of dynamic binary analysis, and realizes automatic in-depth analysis of application programs sensitive to memory allocation and memory layout.
[0017] (2) The present invention proposes a memory management scheme for dynamic fine-grained analysis, simplifies the complexity of shadow memory and analysis code management, and further improves the analysis performance of binary programs.
[0018] (3) The present invention can directly analyze binary programs without performing optimization operations such as preprocessing the program code, has good versatility, and can also be applied in combination with other program analysis optimization methods.
[0019] (4) The present invention can integrate the functions of existing instrumentation tools, without changing the original tools being reused, can reuse the rich interfaces provided by multiple mature analysis platforms, simplifies the complexity of the framework, and can be quickly applied in practice.
[0020] (5) The present invention can be directly deployed and implemented in a real target environment, and has better flexibility and lower performance overhead, and also avoids introducing the overhead of anti-virtualization detection. Description of the Drawings
[0021] Figure 1 It is a framework diagram of the binary program dynamic analysis method based on the process hollowing technology of the present invention.
[0022] Figure 2 It is a flowchart for initializing the analysis environment constructed in an embodiment.
[0023] Figure 3 It is a layout diagram of the memory spaces of the processes of each module constructed in an embodiment.
[0024] Figure 4 It is a diagram of the experimental results of the performance evaluation and comparison of the binary dynamic program analysis framework constructed in an embodiment. Detailed Embodiment
[0025] In order to make the objectives, technical solutions and advantages of the present application clearer, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.
[0026] In one embodiment, in combination with Figure 1 , a binary program dynamic analysis method based on the process hollowing technology is provided, including the following steps:
[0027] Step 1, according to the actual analysis scenario and objective, construct the analysis task check function code and define the interaction interface in the basic host program corresponding to the hollowed process. After completion, compile and generate a new analysis host program. This step specifically includes:
[0028] Step 1.1, construct a basic analysis host program, including the program startup main function, thread initialization function, and analysis task distribution and processing function. When compiling the program, use the static linking method and do not need to link external dynamic link library modules. In the analysis task processing function, the interfaces exported by the kernel module can be called to complete other operations;
[0029] Step 1.2, in the thread initialization function of the basic analysis host program, save the task distribution function address to a specified register. For example: on a 64-bit system, the R15 register can be specified, and on a 32-bit system, it is specified as the ESI register;
[0030] Step 1.3, in the analysis task distribution function of the basic analysis host program, add different analysis task processing functions as needed, and specify a dedicated register to pass the task type. For example, on a 64-bit system, the R10 register can be specified, and on a 32-bit system, it is specified as the EDI register;
[0031] Step 1.4, compile and generate a new analysis host program. During compilation, ignore other default libraries and do not introduce other library functions to avoid interfering with the memory address space. The calls to other system library functions are mainly completed by simple wrapper functions in the program.
[0032] Step 2, based on the characteristics and specific analysis requirements of the target program to be analyzed, build corresponding analysis functions based on the interfaces provided by general-purpose instrumentation tools, such as DynamoRIO, Pin, etc., and then compile and generate a dynamic link library module including the analysis function code. The specific steps include:
[0033] Step 2.1, build the function code to track the execution process of the target program, build instrumentation code for the instructions related to the analysis task, and use the extended thread TLS local storage buffer to save the context registers during thread runtime and the pointer to the record buffer. Optimize in combination with the kernel module during this process to further improve the efficiency of recording runtime information;
[0034] Step 2.2, build the target program runtime information recording code to record the memory address information associated with the analysis instructions, including the flag register and register values that are difficult to statically determine, such as the value of the cl register in the shift instruction shlrbx,cl. Use simple instructions such as LEA and MOV to complete the value fetching in the recording code, and insert relevant code before the original execution instruction;
[0035] Step 2.3, when instrumenting and building the code to record runtime information, build the corresponding analysis code in units of program basic blocks at the same time. Insert the recording code into the target program code in units of program basic blocks, and generate the analysis code corresponding to the basic blocks. For each analyzed instruction, if there is runtime recording information, then recording code will be added to it during execution, and operations to fetch data from the buffer will be built in the corresponding analysis code to maintain the corresponding relationship of data access between the two parts.
[0036] Step 2.4, for each basic block of the program execution, build function code, and insert code at the beginning of its instruction during runtime to record the address of the built analysis code, so that when the analysis thread reads the record buffer, it can directly obtain the analysis code corresponding to the next basic block.
[0037] Step 2.5, construct the link code when the analysis code is executed, and specify in the analysis code that the register points to the next position in the buffer waiting to be read. For example: in a 64-bit system, the RBX register can be specified. In the analysis code, after the data is fetched, read again to determine whether the fetched value is a valid analysis code address. In this way, when an exception occurs during the execution of the analysis thread, the kernel module will handle it and complete the switching of the recording buffer, enabling the analysis code to continue execution.
[0038] Step 2.6, insert task setting and checking code at the function position related to the analysis task, and use the instrumentation tool to construct instruction-level task function call code to trigger the execution of the actual analysis task. For each analysis task, generate a simple function call instruction during instrumentation and save the generated code address to the recording buffer. The code saves the task type to be called, the passed parameters, etc. to registers or pushes them onto the thread stack, and then calls the location register where the save function is located. For example: use the R10 register to pass the task type, and use the R15 register as the call target address, which is consistent with the setting in Step 1.2.
[0039] Step 3, start the target program to be analyzed through the general instrumentation tool, and create the process actually executed by the target program, that is, the instrumented process. This process will load the dynamic link library module constructed in Step 2 when starting, and complete functions such as memory allocation and target program execution tracking.
[0040] Step 4, based on Step 3, the functional module in the instrumentation tool will create a hollow process and simultaneously load and map the new executable analysis host program constructed in Step 1. The analysis code will run in the environment of this process.
[0041] Step 5, based on Step 4, after the hollow process runs, it will continue to load the pre-compiled and constructed kernel module to assist in the subsequent analysis environment initialization and program analysis processes, and then start the analysis environment initialization process.
[0042] In one embodiment, in combination with Figure 2 , the specific initialization steps include:
[0043] Step 5.1, construct the kernel module, register system callbacks using the kernel module, and create synchronization objects to monitor and manage the processes and thread activities in the user state. The kernel module is implemented as a driver program that runs after being loaded by the application layer program, including the monitoring function of the target process and the analysis process behaviors, and handling the analysis event synchronization between the two. Among them, during the tracking of the instrumented process, directly use the function call characteristics to obtain the memory allocation status of the instrumented process without modifying the instrumentation tool.
[0044] Step 5.2, during the hollowing process, create several analysis threads waiting to execute analysis tasks, manage them using a thread pool, and suspend the analysis threads. The analysis threads will wait for subsequent notifications from the kernel module to execute specific analysis tasks;
[0045] Step 5.3, when all analysis threads are created, the kernel module saves the status of the process control block PEB structure of the hollowing process and all analysis thread control block TEB structures in the kernel space buffer;
[0046] Step 5.4, the kernel module starts a new initialization thread, traverses the address space of the hollowing process through the memory management functions exported by the system, and releases the allocated virtual memory address segments in the process space, but retains the code area loaded at program startup;
[0047] Step 5.5, allocate a memory space shared with the hollowing process in the instrumentation process, mainly used to record data during the running of the target program. This part of the buffer is transparent to the instrumentation tool and does not require the target program and the instrumentation tool to participate in management;
[0048] Step 5.6, when the memory allocation required for the instrumentation tool itself during operation is completed, the new initialization thread starts to re - adjust the memory layout in the hollowing process. The program code part corresponds to the memory area occupied by the instrumentation tool code in the instrumentation process. Part of the space is reserved for analysis tasks and can be freely allocated during analysis, corresponding to the memory space reserved for the instrumentation tool in the instrumentation process. The analysis buffer is allocated by the kernel module at the start of the initialization process. In one embodiment, in combination with Figure 3 , the memory layout design specifically includes:
[0049] (1) The memory address space occupied by the instrumentation tool module. In the hollowing process, this part of the space is used to map the newly developed analysis host program code by the user, including thread scheduling code and analysis status check code;
[0050] (2) The memory address space for the instrumentation process to allocate and cache instrumentation code. In the container process, the memory related to analysis is allocated from this part of the space. The instrumentation tool allocates a part of it to store shared analysis code for generating and saving analysis code during instrumentation;
[0051] (3) The record buffer allocated by the kernel module. The physical pages corresponding to this part of the virtual memory are mapped to the same virtual address in the hollowing process. This part of the virtual memory address is pre - allocated at the startup of the target process, and a fixed space is allocated from it when the target thread starts;
[0052] (4) The shadow memory required for dynamic data flow analysis. The kernel module tracks the memory allocation situation, and for the allocation submitted by the target program, synchronously submits and allocates the corresponding address space in the hollowed process, keeping in sync with the target program in terms of page allocation.
[0053] Step 5.7: Reallocate the TEB and Stack spaces for all analysis threads. For the pre-created task threads, first use a small global array as the temporary Stack space. This part of the memory is allocated in the program code segment and is not affected during process hollowing. In this way, when the analysis threads are rescheduled and return to the user code, the original user-mode Stack space still exists.
[0054] Step 5.8: After the analysis threads start executing the actual analysis code, stack space switching will be performed. In this way, the threads will use the newly allocated larger Stack buffer when executing the analysis tasks, ensuring that the subsequent analysis tasks can be completed normally.
[0055] Step 6: Execute the analysis code corresponding to the target program in the hollowed process. After the buffer is filled during the execution of the target program or before the target thread exits, the kernel module is responsible for notifying the analysis threads to start executing the analysis code. The analysis threads execute the analysis code pre-constructed in Step 2 and obtain the runtime information and the next analysis code from the record buffer, thus completing the analysis of the entire program.
[0056] Step 7: During the execution and analysis of the target program, the kernel module continuously filters the system call process. When the target program executes a system call related to a synchronization event, a new buffer will be switched for the current thread of the target program to record runtime information, thereby accelerating the analysis process and alleviating the analysis synchronization problem in a multi-threaded scenario.
[0057] Step 8: The analysis code corresponding to the target program is executed and triggers the analysis tasks. These analysis tasks are set in Step 2. During the execution, multiple analysis tasks may be set. For each analysis task that needs to be checked, after the target program completes the analysis task, its execution will enter the kernel module, and then the kernel module will check and output the analysis results.
[0058] The method of the present invention can solve problems such as process space interference faced in the actual application layer environment. It can be directly deployed and run in the target operating system without relying on virtualization features. By introducing the support of kernel modules, the analysis memory management strategy is optimized, the performance of dynamic data flow analysis is improved, and the impact on the target program is reduced by executing the analysis in a new context using hollow processes, ensuring that the analysis of programs sensitive to memory allocation can be carried out. Compared with other methods, the analysis method of the present invention has better flexibility and lower performance overhead, and improves the applicable scope of the analysis. Figure 4 The following is the performance experimental result of the method of the present invention based on benchmark programs. Compared with the classical method, this method can reduce the impact on the target program and greatly improve the performance of dynamic fine-grained analysis.
[0059] In summary, the binary program dynamic analysis method based on the process hollowing technology proposed by the present invention can achieve efficient dynamic analysis of binary programs such as large application programs, exploit programs, and malicious codes. The main idea is to use kernel modules to transparently expand the functions of the existing program instrumentation framework, and based on the idea of decoupled analysis, construct a fine-grained analysis environment in an independent hollow process. Further, a new shadow memory allocation scheme is designed to improve the management and utilization efficiency of memory state analysis, and further improve the analysis ability of dynamic binary programs. The method of the present invention helps to enhance the effectiveness and adaptability of binary code analysis.
[0060] The above shows and describes the basic principles, main features and advantages of the present invention. Those skilled in the art should understand that the present invention is not limited by the above embodiments. The above embodiments and the descriptions in the specification only illustrate the principles of the present invention. Without departing from the spirit and scope of the present invention, any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present invention shall be included in the protection scope of the present invention.
Claims
1. A dynamic analysis method for binary programs based on process hollowing technology, characterized in that, It includes the following steps: Step 1: According to the actual analysis scenario and objectives, construct and configure a basic analysis host program, build analysis task checking function code and define user interaction interfaces therein, and after completion, compile and generate a new analysis host program; Step 2: For the characteristics of the target program to be analyzed and specific analysis requirements, construct the dynamic link library module to be loaded by the instrumentation tool. When constructing, build the corresponding analysis functions based on the interfaces provided by the general instrumentation tool, including performing code tracing, recording runtime information, and building analysis code; Step 3: Start the target program to be analyzed through the general instrumentation tool, create the instrumentation process where the target program actually runs. The instrumentation process loads the dynamic link library module constructed in Step 2 when starting, and completes the memory allocation during program operation and the target program instrumentation function; Step 4: The functional module in the instrumentation tool creates a hollow process, and at the same time loads and maps the new analysis host program constructed in Step 1, and the analysis code runs in the hollow process environment; Step 5: After the hollow process runs, it continues to load the pre-compiled and constructed kernel module to assist in the subsequent analysis environment initialization and program analysis process, and then starts the analysis environment initialization process, including creating analysis threads, saving the running state, and adjusting the memory layout of the hollow process; Step 6: Execute the analysis code corresponding to the target program in the hollow process, and then the kernel module is responsible for notifying the analysis thread to start executing the analysis code. The analysis thread executes the analysis code pre-constructed in Step 2, and loops to obtain runtime information and subsequent analysis code to complete the entire program analysis process; Step 7: During the execution and analysis of the target program, when the target program executes a system call related to a synchronization event, the kernel module switches the buffer of the current thread to accelerate the analysis process and alleviate the analysis synchronization problem in a multi-threaded scenario; Step 8: The analysis task is triggered after the execution of the analysis code corresponding to the target program. The analysis task is set in Step 2. For the analysis tasks that need to be checked, after the target program completes the analysis task, it will enter the kernel module, and the kernel module checks and outputs the analysis results.
2. The binary program dynamic analysis method based on the process hollowing technology according to claim 1, characterized in that, In Step 1, the new analysis host program includes a program main function, a thread initialization function, and an analysis task distribution and processing function. The specific construction method includes: Step 1.1: Construct a basic analysis host program. When compiling the program, use the static link method and do not need to link external dynamic link library modules. Call the interfaces exported by the kernel module in the analysis task processing function to complete other operations; Step 1.2: In the thread initialization function of the basic analysis host program, save the address of the task distribution function to a specified register; Step 1.3: In the analysis task distribution function of the basic analysis host program, add different analysis task processing functions as needed, and specify a dedicated register to pass the task type; Step 1.4: Compile and generate a new analysis host program. When compiling, ignore other default libraries and do not introduce other library functions. The calls to other system library functions are completed by simple wrapper functions in the program.
3. The binary program dynamic analysis method based on the process hollowing technology according to claim 1, wherein, In step 2, corresponding analysis functions are constructed based on the interfaces provided by the general dynamic instrumentation tool, specifically including: Step 2.1: Construct function code for tracking the execution process of the target program, construct instrumentation code for instructions related to the analysis task, and combine the kernel module to expand the thread TLS storage buffer to save runtime data; Step 2.2: Construct code for recording runtime information of the target program, record memory address information associated with the analysis instructions, including flag registers and register values that are difficult to statically determine, and insert relevant code before the original execution instructions; Step 2.3: When instrumenting and constructing code for recording runtime information, construct corresponding analysis code in units of program basic blocks at the same time, and maintain the corresponding relationship between the execution code and the analysis code in terms of data access; Step 2.4: For each basic block of the program execution, construct function code, and insert code at the beginning of its instruction during runtime to record the address of the constructed analysis code; Step 2.5: Construct linking code when the analysis code is executed, specify in the analysis code that the register points to the next position in the buffer waiting to be read, and the kernel module completes the handling of execution exceptions; Step 2.6: Insert task setting and checking code at the function positions related to the analysis task, and use the instrumentation tool to construct instruction-level task function call code to trigger the execution of the actual analysis task.
4. The binary program dynamic analysis method based on the process hollowing technology according to claim 1, wherein In step 5, the specific process of initializing the analysis environment includes: Step 5.1: Construct a kernel module, use the kernel module to register system callbacks, create synchronization objects to monitor and manage the activities of user-mode processes and threads, and directly use function call characteristics to obtain the memory allocation status of the instrumented process during the tracking process of the instrumented process without modifying the instrumentation tool; Step 5.2: Create several analysis threads in the hollowed-out process and place them in a suspended state, waiting for subsequent notifications from the kernel module to execute specific analysis tasks; Step 5.3: When all analysis threads are created, the kernel module saves the states of the process control block PEB of the hollowed-out process and all analysis thread control block TEB structures in the kernel space buffer; Step 5.4: The kernel module starts a new initialization thread, traverses the address space of the hollowed-out process through the memory management functions exported by the system, and releases the allocated virtual memory address segments in the process space, retaining the code area loaded at program startup; Step 5.5: Allocate a memory space shared with the hollowed-out process in the instrumented process, record the data during the runtime of the target program, and the buffer does not require the participation of the target program and the instrumentation tool in management; Step 5.6: When the memory allocation required by the instrumentation tool itself during runtime is completed, the new initialization thread starts to re-adjust the memory layout in the hollowed-out process.
5. The binary program dynamic analysis method based on the process hollowing technology according to claim 4, characterized in that During the process of initializing the analysis environment, the kernel thread re-sets the memory layout in the hollowed-out process. The specific layout includes: (1) The memory address space occupied by the instrumentation tool. In the hollowed-out process, this part of the space is used to map the newly developed analysis host program code by the user, including thread scheduling code and analysis status check code; (2) Manage the allocation of the instrumentation process and cache the memory address space for the instrumentation code. In the container process, all memory related to analysis is allocated from this part of the space. The instrumentation tool allocates the shared analysis code storage here to facilitate the generation and saving of the analysis code during instrumentation. (3) The record buffer allocated by the kernel module, whose physical pages corresponding to the virtual memory are mapped to the same virtual address in the hollowing process, is pre-allocated when the target process starts, and a fixed space is allocated from it when the target thread starts. (4) The shadow memory used for dynamic data flow analysis. The kernel module tracks the memory allocation situation, and for the memory allocation submitted by the target program, synchronously submits and allocates the corresponding address space in the hollowing process to keep in sync with the target program in terms of page allocation.
Citation Information
Patent Citations
Malicious code software gene homology analysis method
CN114662111A
Attack simulation method and system for Windows terminal
CN118509238A
In-memory scan for threat detection with binary instrumentation backed generic unpacking, decryption, and deobfuscation
US20240028707A1