Function redirection method and device, equipment and storage medium

By controlling the dynamic library of target process link redirection, the impact of function redirection on process operation is solved, the information acquisition without code modification is achieved, and the feasibility and efficiency of function redirection is improved.

CN120335895APending Publication Date: 2025-07-18HANGZHOU CHANGCHUAN TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510397781.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-28
Publication Date
2025-07-18

AI Technical Summary

Technical Problem

In the prior art, function redirection requires changes to the objective function, which affects the process operation and makes it difficult to obtain relevant information quickly.

Method used

By starting the redirecting process, controlling the target process resources, linking the redirecting dynamic library, determining the function address and binding the redirecting function, function redirection is realized.

Benefits of technology

You can obtain relevant information without modifying the source code of the objective function, improve the feasibility and efficiency of function redirection, and keep the process running normally.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120335895A_ABST
    Figure CN120335895A_ABST
Patent Text Reader

Abstract

The invention discloses a function redirection method and device, equipment and a storage medium, a redirection process is started, the redirection process is used for controlling process resources of a target process, and the target process is used for executing a target function needing to be redirected; controlling the target process to link a redirection dynamic library based on the redirection process, the redirection dynamic library comprising a redirection function, and the redirection function being a function executed by the redirected target process; the function address of the target function is determined through the linked redirection dynamic library, and the function address is bound with the redirection function so as to redirect the target function into the redirection function, that is, the redirection process is executed through the linked redirection dynamic library, so that related operation information of the target function is easy to obtain, and the operation efficiency is improved. And the source code of the target function is prevented from being changed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of computer technologies, and in particular, to a function redirection method, apparatus, device, and storage medium. Background Art

[0002] During the running of a process, there is a need to redirect the target function to be executed by the process. Redirecting the target function means executing another function when the process executes the target function.

[0003] During the function redirection process, it is necessary to obtain the execution-related information of the target function. In the related art, the target function can be modified, and the corresponding logic for obtaining information can be added to the target function to obtain the execution-related information. This method requires modifying the original target function, and the way of obtaining information is inconvenient and easily affects the running of the process. Summary of the Invention

[0004] Embodiments of the present disclosure provide a function redirection method, apparatus, device, and storage medium to solve the above technical problems to a certain extent.

[0005] In one aspect of the embodiments of the present disclosure, a function redirection method is provided, including:

[0006] Starting a redirection process, where the redirection process is used to control the process resources of a target process, and the target process is a process for executing a target function to be redirected;

[0007] Based on the redirection process, controlling the target process to link a redirection dynamic library, where the redirection dynamic library includes a redirection function, and the redirection function is the function executed by the target process after redirection;

[0008] Determining the function address of the target function through the linked redirection dynamic library, and binding the function address to the redirection function to redirect the target function to the redirection function.

[0009] In another aspect of the embodiments of the present disclosure, a function redirection apparatus is provided, including:

[0010] A process startup module, configured to start a redirection process, where the redirection process is used to control the process resources of a target process, and the target process is a process for executing a target function to be redirected;

[0011] A dynamic library linking module, configured to control the target process to link a redirection dynamic library based on the redirection process, where the redirection dynamic library includes a redirection function, and the redirection function is the function executed by the target process after redirection;

[0012] A function redirection module, which is used to determine the function address of the target function through the linked redirection dynamic library, and bind the function address to the redirected function, so as to redirect the target function to the redirected function.

[0013] Another aspect of the embodiments of the present disclosure provides an electronic device, including:

[0014] A memory, which is used to store a computer program;

[0015] A processor, which is used to execute the computer program stored in the memory, and when the computer program is executed, the function redirection method described in any of the above embodiments is implemented.

[0016] Another aspect of the embodiments of the present disclosure provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the function redirection method described in any of the above embodiments is implemented.

[0017] Another aspect of the embodiments of the present disclosure provides a computer program product, including a computer program, and when the computer program is executed by a processor, the function redirection method described in any of the above embodiments is implemented.

[0018] Next, through the drawings and embodiments, the technical solutions of the present disclosure will be described in further detail.

[0019] In the embodiments of the present disclosure, a redirection process that can control the process resources of the target process is used to control the target process to link to the redirection dynamic library. The linked redirection dynamic library determines the function address of the target function to be redirected in the target process, and binds the function address to the redirected function, so as to redirect the target function to be executed by the target process to the redirected function. Since the redirection dynamic library is linked by the target process, the linked redirection dynamic library is easy to obtain the relevant running information of the target function, and the relevant information can be obtained without changing the source code of the target function, and it can be plug-and-play, which can improve the feasibility and efficiency of function redirection. In addition, the redirection process independent of the target process controls the target process to link to the redirection dynamic library, that is, during the running process of the target process, the redirection dynamic library is linked to the target process through an invasive method, and during this process, the normal running of the target process can be maintained, avoiding the impact on the running of the target process. BRIEF DESCRIPTION OF THE DRAWINGS

[0020] The drawings constituting a part of the specification depict the embodiments of the present disclosure and, together with the description, are used to explain the principles of the present disclosure.

[0021] Referring to the drawings, the present disclosure can be more clearly understood according to the following detailed description, wherein:

[0022] Figure 1 It is a schematic flowchart of a function redirection method provided by an exemplary embodiment of the present disclosure;

[0023] Figure 2 It is a schematic flowchart of a process for redirecting a dynamic library link provided by an exemplary embodiment of the present disclosure;

[0024] Figure 3 It is a schematic flowchart of a process for redirecting a dynamic library link provided by another exemplary embodiment of the present disclosure;

[0025] Figure 4 It is a schematic flowchart of a process for uninstalling a redirected dynamic library provided by an exemplary embodiment of the present disclosure;

[0026] Figure 5 It is a schematic flowchart of a process for determining a function address provided by an exemplary embodiment of the present disclosure;

[0027] Figure 6 It is a schematic flowchart of a redirection binding process provided by an exemplary embodiment of the present disclosure;

[0028] Figure 7 It is a schematic flowchart of a redirection binding process provided by another exemplary embodiment of the present disclosure;

[0029] Figure 8 It is a schematic diagram of the structure of a function redirection device provided by an exemplary embodiment of the disclosure;

[0030] Figure 9 It is a schematic diagram of the structure of an electronic device provided by an exemplary embodiment of the disclosure. Detailed implementation manners

[0031] Now, various exemplary embodiments of the present disclosure will be described in detail with reference to the accompanying drawings. It should be noted that: Unless otherwise specifically stated, the relative arrangements of components and steps, numerical expressions, and values set forth in these embodiments do not limit the scope of the present disclosure.

[0032] Those skilled in the art can understand that terms such as "first" and "second" in the embodiments of the present disclosure are only used to distinguish different steps, devices, or modules, etc., and neither represent any specific technical meaning nor indicate an inevitable logical order between them.

[0033] It should also be understood that in the embodiments of the present disclosure, "a plurality of" may refer to two or more, and "at least one" may refer to one, two, or more.

[0034] It should also be understood that for any component, data, or structure mentioned in the embodiments of the present disclosure, without clear limitation or contrary indication in the context, it can generally be understood as one or more.

[0035] In addition, the term "and / or" in the present disclosure is merely a description of the association relationship between associated objects, indicating that there can be three relationships. For example, A and / or B can represent three situations: A exists alone, A and B exist simultaneously, and B exists alone. In addition, the character " / " in the present disclosure generally represents an "or" relationship between the associated objects before and after.

[0036] It should also be understood that the descriptions of the various embodiments in the present disclosure emphasize the differences between the various embodiments, and their similarities or similarities can be referred to each other. For the sake of brevity, they will not be elaborated one by one.

[0037] At the same time, it should be understood that for the convenience of description, the sizes of the various parts shown in the drawings are not drawn in actual proportional relationship.

[0038] The following description of at least one exemplary embodiment is actually merely illustrative and in no way constitutes any limitation to the present disclosure and its application or use.

[0039] Techniques, methods, and devices known to those of ordinary skill in the relevant art may not be discussed in detail, but where appropriate, the techniques, methods, and devices should be regarded as part of the specification.

[0040] It should be noted that like reference numerals and letters denote like items in the following figures, and thus, once an item is defined in one figure, it does not need to be further discussed in subsequent figures.

[0041] The embodiments of the present disclosure can be applied to electronic devices such as terminal devices, computer systems, servers, etc., which can operate with many other general or special computing system environments or configurations. Examples of well-known terminal devices, computing systems, environments, and / or configurations suitable for use with electronic devices such as terminal devices, computer systems, servers, etc. include, but are not limited to: personal computer systems, server computer systems, thin clients, thick clients, handheld or laptop devices, microprocessor-based systems, set-top boxes, programmable consumer electronics, network personal computers, small computer systems, large computer systems, and distributed cloud computing technology environments including any of the above systems, and so on.

[0042] Electronic devices such as terminal devices, computer systems, and servers can be described in the general context of computer system-executable instructions (such as program modules) executed by a computer system. Generally, program modules can include routines, programs, target programs, components, logics, data structures, etc., which perform specific tasks or implement specific abstract data types. The computer system / server can be implemented in a distributed cloud computing environment, where tasks are executed by remote processing devices linked through a communication network. In a distributed cloud computing environment, program modules can be located on local or remote computing system storage media including storage devices.

[0043] Function redirection refers to the process of redirecting a target function to be executed by a target process to another function, so that when the target process executes the target function, it executes the other function. For example, if the target function is function A and the redirected function is function B, after redirecting function A to function B, the target process will execute function B.

[0044] In the related art, it is necessary to modify and recompile the original function (i.e., the target function to be redirected) to obtain information related to the function operation. This method will affect the original process (i.e., the target process for executing the target function), and the feasibility of self-modifying the original function is relatively poor, and the way of obtaining information is inconvenient.

[0045] In the embodiments of the present disclosure, during the operation of the original process, a redirecting process can link a redirected dynamic link library (DLL) (hereinafter simply referred to as the redirected dynamic library in the following embodiments) to the original process, and obtain information related to the target function through the linked redirected dynamic library, which is convenient for information acquisition and can reduce the impact on the operation of the original target process.

[0046] As Figure 1 shown, it shows a flowchart of a function redirection method provided by an exemplary embodiment of the present disclosure. This method can be used for the above-mentioned electronic devices, and this method includes steps 110-130:

[0047] Step 110, start a redirecting process, where the redirecting process is used to control the process resources of a target process, and the target process is a process for executing a target function to be redirected.

[0048] The redirecting process is independent of the target process, and the redirecting process is used to start the redirecting process. Optionally, the redirecting process can be created in real time or pre-created. In a possible implementation manner, after starting the redirecting process, the redirecting process can obtain the process resources of the target process to control the process resources of the target process, so as to control the target process to link the redirected dynamic library. Optionally, the process resources of the target process can be the handle resources of the target process.

[0049] The target function is the function to be redirected and is the function to be executed in the target process. Optionally, the target function can be a pre-configured function to be redirected or a function to be redirected specified in real time.

[0050] Step 120: Based on the redirection process, control the target process to link to the redirection dynamic library. The redirection dynamic library includes redirection functions, and the redirection function is the function executed by the target process after redirection.

[0051] A DLL is a shared function library that contains functions and data that can be used by multiple programs simultaneously, that is, multiple programs can use the functions and data in the same DLL at the same time. Linking a DLL to a process means loading the functions and data contained in the DLL into the address space of the process during program execution, enabling the process to call the functions defined in the DLL or access the resource data it contains.

[0052] The redirection dynamic library (redirection DLL) includes multiple defined functions, among which there are redirection functions. Linking the redirection dynamic library to the target process enables the target process to call the redirection functions and achieve function redirection.

[0053] After starting the redirection process, the redirection process can be used to control the target process to link to the redirection dynamic library. In a possible implementation, the path of the redirection dynamic library can be written into the memory space corresponding to the target process through the redirection process, and then the target process is controlled to link to the redirection dynamic library based on the path of the redirection dynamic library in the memory space.

[0054] By controlling the target process to link to the redirection dynamic library through the redirection process, the target process can autonomously link to the redirection dynamic library, thereby facilitating the redirection dynamic library to obtain information in the target process, that is, it is easy to obtain function operation information of the target function to be redirected, such as execution time, execution thread id, function variable information, etc.

[0055] Step 130: Determine the function address of the target function through the linked redirection dynamic library, and bind the function address to the redirection function to redirect the target function to the redirection function.

[0056] After controlling the target process to link to the redirection dynamic library, the redirection dynamic library can determine the target function to be redirected and determine the function address of the target function. The function address refers to the actual address of the function in the process address space of the target process, and the target process realizes the call and execution of the target function based on the function address.

[0057] In a possible implementation, after the target process links to the redirected dynamic library, the entry function of the redirected dynamic library (such as the DllMain function) will be executed to determine the target function to be redirected, determine the function address of the target function, and bind the function address to the redirected function.

[0058] Optionally, the target function can be an exported function or a non-exported function. An exported function refers to a function in a DLL, shared library, or shared module that can be called by an external program. If the target function is an exported function, the function address of the target function can be queried based on the export table. A non-exported function is a function for internal use only and cannot be directly called by an external program. If the target function is a non-exported function, the function address of the target function needs to be calculated.

[0059] After determining the function address of the target function, the function address of the target function is bound to the redirected function, so that the target process calls and executes the redirected function based on the function address, completing the process of redirecting the target function to the redirected function.

[0060] In the embodiments of the present disclosure, a redirected process that can control the process resources of the target process is used to control the target process to link to the redirected dynamic library. The redirected dynamic library linked determines the function address of the target function to be redirected in the target process, and binds the function address to the redirected function, thereby redirecting the target function to be executed by the target process to the redirected function. Since the redirected dynamic library is linked by the target process, the linked redirected dynamic library is easy to obtain the relevant running information of the target function, and the relevant information can be obtained without changing the source code of the target function, and it can be plug-and-play, which can improve the feasibility and efficiency of function redirection. In addition, the redirected process independent of the target process controls the target process to link to the redirected dynamic library, that is, during the running of the target process, the redirected dynamic library is linked to the target process by an intrusive method, and the normal running of the target process can be maintained during this process, avoiding the impact on the running of the target process.

[0061] In a possible implementation, the redirected process can be controlled to obtain the process handle of the target process to write the corresponding path of the redirected dynamic library into the memory of the target process. As Figure 2 shown, step 120 above further includes the following steps 210-230:

[0062] Step 210, obtain the process handle of the target process through the redirected process.

[0063] A process handle is a special data structure used to identify and operate on a process. The process object can be accessed and operated through the process handle. By obtaining the process handle of the target process, the memory space of the target process can be accessed to write the redirected dynamic library into the memory space of the target process.

[0064] In a possible implementation, obtaining the process handle of the target process may include the following steps:

[0065] Step 2101, perform a process snapshot through a redirected process to obtain a process snapshot list.

[0066] The process snapshot is used to snapshot all current processes. By snapshotting all current processes through a redirected process, a process snapshot list is obtained. Among them, the process snapshot list contains the process information of all current processes. Optionally, the process information includes the process name and the process ID (pid).

[0067] Step 2102, query the process ID of the target process from the process snapshot list.

[0068] In a possible implementation, the target process may be found in the process snapshot list according to the process name of the target process. After the target process is found, the corresponding process ID can be obtained to obtain the process pid of the target process.

[0069] Step 2103, based on the process ID, obtain the process handle of the target process.

[0070] Optionally, based on the process pid of the target process, obtain the process handle of the target process to open the target process. For example, the process handle of the target process can be obtained by calling a function for opening a process (such as the OpenProcess function).

[0071] Step 220, based on the process handle, write the path of the redirected dynamic library into the target memory of the target process.

[0072] After obtaining the process handle of the target process, the memory space of the target process can be accessed. In a possible implementation, target memory can be applied for in the target process to store the path of the redirected dynamic library to be linked. After applying for the target memory, write the path of the redirected dynamic library into the target memory.

[0073] Optionally, a function for allocating memory (such as the VirtualAllocEx function) can be called to allocate memory for the path of the redirected dynamic library, that is, call a function for allocating memory to apply for target memory to store the path of the redirected dynamic library.

[0074] Optionally, after applying for the target memory, a function for writing data into the process memory (such as the WriteProcessMemory function) can be called to write the path of the redirected dynamic library into the target memory.

[0075] Step 230, create a first thread in the target process based on the target memory, so that the target process links the redirected dynamic library by calling the first thread.

[0076] In a possible implementation, controlling the target process to link the redirected dynamic library can be achieved by creating a thread in the target process. A thread is the unit of execution in a process, and a thread corresponds to a task to be executed. Optionally, one thread can correspond to one execution task. By creating a thread for linking the redirected dynamic library, the linking of the redirected dynamic library can be completed.

[0077] Optionally, a first thread can be created in the target process, and the parameter includes the memory address of the target memory (i.e., the memory address corresponding to the redirected dynamic library), so as to pass the memory address of the target memory as a parameter to the function for loading the redirected dynamic library to complete the linking of the redirected dynamic library function.

[0078] Optionally, a function for creating a thread (such as the CreateRemoteThread function) can be called to create the first thread, so that the target process links the redirected dynamic library by executing the first thread.

[0079] In a possible implementation, as Figure 3 shown, the process of controlling the target process to link the redirected dynamic library through the redirected process includes the following steps 310-370:

[0080] Step 310, start the redirected process, and obtain a process snapshot list by executing a process snapshot through the redirected process.

[0081] Step 320, traverse the process snapshot list to find whether the target process exists. If it exists, execute Step 330; if not, end.

[0082] Step 330, obtain the process pid of the target process according to the process name of the target process.

[0083] Step 340, open the target process according to the process pid of the target process.

[0084] Step 350, call a function for allocating memory to apply for the target memory in the target process to inject the path of the redirected dynamic library.

[0085] Step 360, call a function for writing data to the process memory to write the path of the redirected dynamic library into the target memory.

[0086] Step 370, call a function for creating a thread to create the first thread to control the target process to link the redirected dynamic library.

[0087] Among them, the implementation manners of steps 310-370 can refer to the above embodiments and will not be elaborated here.

[0088] In the embodiments of the present disclosure, the target process is opened by a redirecting process, the redirected dynamic library is written into the memory space of the target process, and a thread for linking the redirected dynamic library is created in the target process, so that the target process links the redirected dynamic library. Initiating the link by the target process can make it easy for the redirected dynamic library to obtain information in the target process, such as information related to the operation of the target function. In addition, when there is a redirection requirement, the target process can be controlled by the redirecting process to link the redirected dynamic library, which can be plug-and-play.

[0089] In a possible implementation manner, the redirected dynamic library is pluggable, that is, it can be plugged and played or unplugged and stopped immediately. When there is no longer a redirection requirement, the redirected dynamic library can be unloaded to achieve redirection unbinding. Optionally, the redirection unbinding can be performed by remotely unloading the redirected dynamic library. As Figure 4 shown, the process of unloading the redirected dynamic library includes the following steps:

[0090] Step 410, obtain the process handle of the target process through the redirecting process.

[0091] Among them, the implementation manner of step 410 can refer to step 210 above and will not be elaborated here.

[0092] Step 420, find the dynamic library handle corresponding to the redirected dynamic library based on the process handle.

[0093] In a possible implementation manner, the memory space of the target process can be accessed based on the process handle, and the dynamic library handle corresponding to the redirected dynamic library is found in the memory space. Optionally, traversal can be performed based on the name of the redirected dynamic library to find the dynamic library handle corresponding to the redirected dynamic library.

[0094] Step 430, create a second thread in the target process based on the dynamic library handle, so that the target process unloads the redirected dynamic library by executing the second thread.

[0095] In a possible implementation manner, unloading the redirected dynamic library can be achieved by creating a thread in the target process. Optionally, a second thread for unloading the redirected dynamic library is created, so that the target process unloads the redirected dynamic library by executing the second thread.

[0096] Optionally, a second thread can be created in the target process based on the dynamic library handle, that is, the parameter includes the dynamic library handle, to unload the redirected dynamic library based on the dynamic library handle.

[0097] In a possible implementation manner, after successfully unloading the redirected dynamic library, the applied thread resources can be released to avoid resource occupation.

[0098] In this embodiment, when there is a redirection requirement, the target process can be controlled by the redirection process to link to the redirection dynamic library. When there is no longer a redirection requirement after the redirection ends, the redirection dynamic library linked by the target process can be unloaded by the redirection process. During this process, the normal operation of the target process can be maintained, the impact on the target process can be reduced, and the pluggability of the redirection dynamic library can be achieved, which can be plugged in and used immediately, and unplugged and stopped immediately.

[0099] In addition, when there is no redirection requirement, unloading the redirection dynamic library can avoid continuous occupation of the resources of the target process and waste of resources.

[0100] Optionally, the target function to be redirected can be an exported function or a non-exported function. When determining the function address of the target function, in response to the target function being an exported function, the function address of the target function is queried from the target dynamic library where the target function is located. The target dynamic library is the DLL to which the target function belongs. In a possible implementation manner, when the target function is an exported function, a function for obtaining the function address (such as the GetProcAddress function) can be called to obtain the function address of the target function.

[0101] In response to the target function being a non-exported function, the function address of the target function is determined based on the base address of the target dynamic library and the function offset of the non-exported function.

[0102] In a possible implementation manner, the function address of the target function is calculated based on a static address and a dynamic address. Here, the dynamic address is the base address of the target dynamic library (also referred to as the target DLL), and the base address of the target dynamic library is the base address allocated when the target process links to it. The dynamic address is the function offset of the target function, and the function offset refers to the offset of the position of the target function in the target DLL relative to the base address of the target DLL, which can be described by the Relative Virtual Address (RVA). Among them, the base address allocated to the target DLL is not fixed, but the function offset (i.e., RVA) corresponding to the target function remains unchanged. The base address of the target DLL can be obtained first, and the function address of the target function is calculated based on the base address of the target DLL and the RVA of the target function. Optionally, a function for obtaining the module handle (such as the GetModuleHandle function) can be used to obtain the handle of the target DLL in the target process to obtain the base address of the target DLL (which can also be called the handle).

[0103] In a possible implementation manner, as Figure 5 shown, determining the function address of a non-exported function includes the following steps:

[0104] Step 510, obtain the preferred loading address of the target dynamic library and the virtual address of the target function.

[0105] Optionally, the function offset can be determined based on the preferred loading address of the target dynamic library and the virtual address of the target function. The preferred loading address (ImageBase) is the preset address where the target dynamic library is mapped to the process address space, and the virtual address (Virtual Address, VA) is the preset address where the target function is located in the target dynamic library. The preferred loading address can also be referred to as the preferred base address, which is the ideal memory address where the target DLL is mapped to the process address space and is a pre-set base address. The virtual address is the pre-set address of the target function in the target DLL. The difference between the two is the function offset of the target function.

[0106] In a possible implementation, the preferred loading address of the target DLL and the function address of the target function can be queried in the dynamic library table corresponding to the target DLL. Optionally, the dynamic library table can be a symbol table. Exemplarily, the preferred loading address of the target DLL and the virtual address of the target function are obtained through the nm - C command. Among them, the nm - C command is used to display symbol information in target files such as.o files or executable files, and - C can decode the symbol name into a user - level name. In a C++ program, the function name decoration can be converted to the original function name. Optionally, the dynamic library table corresponding to the target DLL where the target function is located can be exported through the nm - C command, and the preferred loading address of the target DLL can be queried in the exported file (nm file). In addition, the virtual address of the target function can be found in the exported file based on the function name of the target function. The function name of the target function refers to the name of the target function in the nm file.

[0107] Step 520: Determine the function offset based on the difference between the virtual address and the preferred loading address.

[0108] After obtaining the preferred loading address and the virtual address, the difference between the virtual address and the preferred loading address can be determined as the function offset, that is, RVA = VA - ImageBase.

[0109] Step 530: Determine the function address of the target function based on the sum of the function offset and the base address.

[0110] The sum of the function offset and the base address is determined as the function address of the target function, which is the actual address of the target function in the target process. The function address of the target function can be Handle + RVA. In this way, the actual address of the target function in the target process can be calculated, that is, the function address of the non - exported function can be obtained to perform subsequent binding and redirection operations.

[0111] In this embodiment, when the target function is an exported function, the corresponding function address can be directly queried. When the target function is a non-exported function, the base address and function offset of the non-exported function can be obtained, so as to determine the function address of the non-exported function based on the function base address and function offset, and the function address of any type of function can be determined, realizing the redirection of any type of function.

[0112] After determining the function address of the target function, the function address of the target function can be bound to the redirection function. In a possible implementation manner, redirection is implemented through a hook (Hook) during redirection. The function pointer of the target function and the Hook function (i.e., the above-mentioned redirection function, which is the function actually executed after redirection) can be obtained. The function pointer of the target function points to the function address of the target function, and then the target function is bound to the Hook function to achieve redirection.

[0113] In a possible implementation manner, the Detour method is used for redirection binding, and the binding process includes the following steps:

[0114] Step (1), initialize the internal data structure using the first initialization function to prepare for hooking.

[0115] The first initialization function is used to initialize the transaction environment, that is, the redirection binding environment. Exemplarily, the first initialization function can be the DetourTransactionBegin function, and the DetourTransactionBegin function can be used to create an atomic transaction environment and initialize the internal linked list structure to record subsequent binding operations.

[0116] Step (2), specify the thread participating in the hook using the first refresh thread function.

[0117] Optionally, the thread participating in the hook can be the current thread. The first refresh thread function can be used to suspend the thread participating in the hook. Exemplarily, the thread participating in the hook is suspended through the DetourUpdateThread function, and the task corresponding to the thread is paused to ensure the smooth execution of the binding.

[0118] Step (3), bind the target function pointer to the redirection function using the binding function.

[0119] The binding function is a functional function for function binding. Exemplarily, the binding function can be the DetourAttach function, and the DetourAttach function is used to bind the target function pointer to the redirection function.

[0120] Step (4), commit the hook transaction using the first transaction commit function.

[0121] The first transaction commit function is a function used to commit all the modification contents included in the transaction queue. Exemplarily, the first transaction commit function can be the DetourTranscationCommit function. By using the DetourTranscationCommit function to commit all the modifications included in the transaction queue, write them into the memory instructions, and resume the suspended threads.

[0122] After the redirection binding, when there is no redirection requirement, unbinding can also be performed. In a possible implementation manner, the Detour method is used for redirection unbinding, and the unbinding process includes the following steps:

[0123] Step (1), initialize the internal data structure by using the second initialization function to prepare for hooking.

[0124] The second initialization function is used to initialize the transaction environment, that is, the unbinding environment. Optionally, the second initialization function during the unbinding process can be the same as or different from the first initialization function used in the above binding process. Exemplarily, the second initialization function can be the DetourTransactionBegin function.

[0125] Step (2), specify the thread participating in the hook by using the second refresh thread function.

[0126] Optionally, the thread participating in the hook can be the current thread. The second refresh thread function can be used to suspend the thread participating in the hook. The second refresh thread function can be the same as or different from the first refresh thread function above. Exemplarily, the second refresh thread function can be the DetourUpdateThread function.

[0127] Step (3), unbind the target function pointer from the redirection function by using the unbinding function.

[0128] The unbinding function is a functional function for function unbinding. Exemplarily, the unbinding function can be the DetourDettach function. Use the DetourDettach function to unbind the target function pointer from the redirection function.

[0129] Step (4), commit the hook transaction by using the second transaction commit function.

[0130] The second transaction commit function is a function used to commit all the modification contents included in the transaction queue. Optionally, the second transaction commit function can be the same as or different from the first transaction commit function. Exemplarily, the second transaction commit function can be the DetourTranscationCommit function.

[0131] After the redirection binding, relevant information of the target function can be obtained, and the information needs to be transmitted to the specified port to execute the redirection function based on the relevant information of the target function. In a possible implementation manner, to ensure the real-time nature of information transmission, protocols such as Remote Procedure Call (RPC) protocol and GRPC protocol can be used for information transmission. Taking the use of GRPC protocol as an example, when the redirection function obtains the relevant information of the target function, the information can be assigned to the communication structure of GRPC, and the communication structure is transmitted to the specified port to achieve information transmission.

[0132] In a possible implementation manner, the user can achieve custom configuration of target function redirection through a configuration file. The user can pre-configure the target function to be redirected and write it into the configuration file to determine the target function to be redirected based on the configuration file during the redirection process.

[0133] In a possible implementation manner, after linking the redirection dynamic library to the target process, the redirection dynamic library can read the pre-configured configuration information and determine the target function to be redirected based on the configuration information.

[0134] Among them, the configuration information includes information for indicating whether each function needs to be redirected. Optionally, for a function, the configuration information may include the function signature of the function, the enable flag bit (enable bit), the DLL name to which the function belongs, and the name of the function in the nm file. The function signature corresponds to the function pointer, which is convenient for subsequent assignment operations. The enable flag bit is used to indicate whether to perform binding, that is, to indicate whether the function is the target function to be redirected. The DLL name corresponds to the nm file where the function address is located. The name of the function in the nm file (attach_name) is used to find the virtual address of the function in the nm file for calculating the static address of the function (i.e., the function offset).

[0135] In a possible implementation manner, the redirection dynamic library can determine the target function to be redirected according to the configuration information. During this process, the enable flag bits of each function can be read from the configuration information, and in response to the enable flag bit of the function being a preset flag, the function is determined as the target function. Among them, the preset flag is used to indicate that the function is the function to be redirected. Exemplarily, when the enable flag bit is "1", it is determined that the function is the target function, and the process of obtaining the function address of the function and performing binding can be executed.

[0136] In a possible implementation manner, the configuration file to which the configuration information belongs can adopt the Extensible Markup Language (XML) format, and the data in the configuration file is separated from the program code to ensure the maintainability of the program.

[0137] As Figure 6 shown, the process of the redirection dynamic library determining the target function and performing redirection binding may include the following steps:

[0138] Step 610, read the configuration file and obtain the configuration information of the function.

[0139] Step 620, determine whether the enable flag bit of the function is a preset flag. If so, execute Step 630; if not, end.

[0140] Step 630, obtain the function address of the function and bind the function address to the redirected function.

[0141] Among them, the implementation manners of Steps 610-630 can refer to the above embodiments and will not be elaborated here.

[0142] In this embodiment, the target function to be redirected can be specified through the configuration file, realizing the custom configuration of the target function and meeting the redirection requirements of users.

[0143] As Figure 7 shown, it shows a flowchart of the redirection dynamic library performing redirection provided by an exemplary embodiment of the present disclosure. The method includes the following steps 710-7130:

[0144] Step 710, execute the entry function.

[0145] Optionally, the entry function can be the Dllmain function.

[0146] Step 720, determine the target function to be redirected according to the configuration file.

[0147] Step 730, determine whether the target function is a non-exported function. If so, execute Step 740; if not, execute Step 780.

[0148] Step 740, export the dynamic library table of the target DLL where the target function is located to obtain an export file.

[0149] Exemplarily, the dynamic library table can be exported through the nm - C command.

[0150] Step 750, query the preferred loading address of the target DLL and the virtual address of the target function from the export file.

[0151] Step 760, calculate the function offset based on the virtual address and the preferred loading address.

[0152] Step 770, calculate the function address of the target function based on the function offset and the base address of the target function.

[0153] Step 780: Call the function for querying the function address to query the function address of the target function.

[0154] Step 790: Assign the function pointer of the target function to the function address of the target function.

[0155] Step 7100: Initialize the internal data structure using the first initialization function to prepare for Hook.

[0156] Step 7110: Specify the threads participating in Hook using the first thread refreshing function.

[0157] Step 7120: Bind the function pointer of the target function to the redirect function using the binding function.

[0158] Step 7130: Commit the Hook transaction using the first transaction submission function.

[0159] Among them, the implementation manners of steps 710 to 7130 can refer to the above embodiments and will not be elaborated here.

[0160] As Figure 8 shown, it shows a schematic structural diagram of a function redirection device provided by an exemplary embodiment of the present disclosure. The device includes:

[0161] A process startup module 810, configured to start a redirection process for controlling the process resources of a target process, where the target process is a process for executing a target function to be redirected;

[0162] A dynamic library linking module 820, configured to control the target process to link a redirection dynamic library based on the redirection process, where the redirection dynamic library includes a redirection function, and the redirection function is the function executed by the target process after redirection;

[0163] A function redirection module 830, configured to determine the function address of the target function through the linked redirection dynamic library, and bind the function address to the redirection function to redirect the target function to the redirection function.

[0164] In an exemplary embodiment, the dynamic library linking module 820 is further configured to:

[0165] Obtain the process handle of the target process through the redirection process;

[0166] Based on the process handle, write the path corresponding to the redirection dynamic library into the target memory of the target process;

[0167] Create a first thread in the target process based on the target memory, so that the target process links the redirected dynamic library by executing the first thread.

[0168] In an exemplary embodiment, the function redirection module 830 is further configured to:

[0169] In response to the target function being an exported function, query the function address of the target function from the target dynamic library where the target function is located;

[0170] In response to the target function being a non-exported function, determine the function address of the target function based on the base address of the target dynamic library and the function offset of the non-exported function.

[0171] In an exemplary embodiment, the function redirection module 830 is further configured to:

[0172] Obtain the preferred loading address of the target dynamic library and the virtual address of the target function, where the preferred loading address is a preset address where the target dynamic library is mapped to the process address space, and the virtual address is a preset address of the target function in the target dynamic library;

[0173] Determine the function offset based on the difference between the virtual address and the preferred loading address;

[0174] Determine the function address of the target function based on the sum of the function offset and the base address.

[0175] In an exemplary embodiment, the device further includes a dynamic library unloading module, configured to:

[0176] Obtain the process handle of the target process through the redirected process;

[0177] Find the dynamic library handle corresponding to the redirected dynamic library based on the process handle;

[0178] Create a second thread in the target process based on the dynamic library handle, so that the target process unloads the redirected dynamic library by executing the second thread.

[0179] In an exemplary embodiment, the device further includes a function determination module, configured to:

[0180] Read pre-configured configuration information through the redirected dynamic library, where the configuration information includes information indicating whether each function needs to be redirected;

[0181] Determine the target functions that need to be redirected based on the configuration information.

[0182] In an exemplary embodiment, the function determination module is further configured to:

[0183] Read the enable flag bits of each function from the configuration information;

[0184] In response to the enable flag bit of the function being a preset flag, determine the function as the target function.

[0185] In an exemplary embodiment, the dynamic library link module 820 is further configured to:

[0186] Execute a process snapshot through the redirection process to obtain a process snapshot list;

[0187] Query the process number of the target process from the process snapshot list;

[0188] Based on the process number, obtain the process handle of the target process.

[0189] In the embodiments of the present disclosure, the function redirection device corresponds to the embodiments of the above-mentioned function redirection method of the present disclosure, and the relevant content can be referred to each other, which will not be elaborated here. The beneficial technical effects corresponding to the function redirection device in the embodiments of the present disclosure can be seen in the corresponding beneficial technical effects of the above-mentioned corresponding exemplary method part, which will not be elaborated here.

[0190] In addition, the embodiments of the present disclosure further provide an electronic device, including:

[0191] A memory for storing a computer program;

[0192] A processor for executing the computer program stored in the memory, and when the computer program is executed, implementing the function redirection method according to any one of the above embodiments of the present disclosure.

[0193] Figure 9 is a schematic structural diagram of an electronic device provided by an exemplary embodiment of the present disclosure. As Figure 9 shown, the electronic device includes one or more processors and a memory.

[0194] The processor may be a central processing unit (CPU) or other form of processing unit with data processing capabilities and / or instruction execution capabilities, and may control other components in the electronic device to perform desired functions.

[0195] The memory can store one or more computer program products. The memory can include various forms of computer-readable storage media, such as volatile memory and / or non-volatile memory. The volatile memory can include, for example, random access memory (RAM) and / or cache memory, etc. The non-volatile memory can include, for example, read-only memory (ROM), hard disk, flash memory, etc. One or more computer program products can be stored on the computer-readable storage media, and the processor can run the computer program products to implement the function redirection method of various embodiments of the present disclosure described above and / or other desired functions.

[0196] In one example, the electronic device may further include: an input device and an output device, and these components are interconnected through a bus system and / or other forms of connection mechanisms (not shown).

[0197] In addition, the input device may further include, for example, a keyboard, a mouse, and so on.

[0198] The output device can output various information to the outside, including the determined distance information, direction information, etc. The output device can include, for example, a display, a speaker, a printer, and a communication network and its connected remote output devices, and so on.

[0199] Of course, for simplicity, Figure 9 only some of the components related to the present disclosure in the electronic device are shown, and components such as a bus, an input / output interface, etc. are omitted. In addition, according to specific application scenarios, the electronic device may further include any other appropriate components.

[0200] In addition to the above methods and devices, an embodiment of the present disclosure may also be a computer program product, which includes computer program instructions, and when the computer program instructions are run by a processor, the processor is caused to execute the steps in the function redirection method according to various embodiments of the present disclosure described in the above part of this specification.

[0201] The computer program product can be written in any combination of one or more programming languages for programming code to perform the operations of the embodiments of the present disclosure. The programming languages include object-oriented programming languages, such as Java, C++, etc., and also include conventional procedural programming languages, such as the "C" language or similar programming languages. The program code can be executed completely on the user computing device, partially on the user device, executed as an independent software package, partially on the user computing device and partially on a remote computing device, or completely executed on a remote computing device or server.

[0202] In addition, an embodiment of the present disclosure may also be a computer-readable storage medium having computer program instructions stored thereon, and when the computer program instructions are run by a processor, the processor is caused to execute the steps in the function redirection method according to various embodiments of the present disclosure described in the foregoing part of this specification.

[0203] The computer-readable storage medium may adopt any combination of one or more readable media. The readable media may be a readable signal medium or a readable storage medium. The readable storage medium may, for example, include but is not limited to an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the foregoing. More specific examples (a non-exhaustive list) of the readable storage medium include: an electrical connection having one or more wires, a portable disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0204] The basic principles of the present disclosure have been described above in conjunction with specific embodiments. However, it should be noted that the advantages, benefits, effects, etc. mentioned in the present disclosure are only examples and not limitations, and it cannot be considered that these advantages, benefits, effects, etc. are essential for each embodiment of the present disclosure. In addition, the specific details disclosed above are only for the purposes of illustration and facilitating understanding, and are not limitations. The above details do not limit the present disclosure to necessarily adopt the above specific details for implementation.

[0205] Each embodiment in this specification is described in a progressive manner. The key point of each embodiment is to illustrate the differences from other embodiments. For the same or similar parts among the embodiments, reference may be made to each other. For the system embodiment, since it basically corresponds to the method embodiment, the description is relatively simple, and reference may be made to the partial description of the method embodiment for the relevant parts.

[0206] The block diagrams of the devices, apparatuses, equipment, and systems involved in the present disclosure are only illustrative examples and do not intend to require or imply that they must be connected, arranged, and configured in the manner shown in the block diagrams. As those skilled in the art will recognize, these devices, apparatuses, equipment, and systems can be connected, arranged, and configured in any manner. Words such as "including", "comprising", "having", etc. are open-ended terms, meaning "including but not limited to", and can be used interchangeably with each other. The word "or" and "and" used herein refer to the word "and / or", and can be used interchangeably with each other unless the context clearly indicates otherwise. The word "such as" used herein refers to the phrase "such as but not limited to", and can be used interchangeably with each other.

[0207] The methods and apparatuses of the present disclosure may be implemented in many ways. For example, the methods and apparatuses of the present disclosure may be implemented by software, hardware, firmware, or any combination of software, hardware, and firmware. The above order of steps for the methods is for illustration only. The steps of the methods of the present disclosure are not limited to the specific order described above, unless otherwise specifically stated. In addition, in some embodiments, the present disclosure may also be implemented as a program recorded in a recording medium, and these programs include machine-readable instructions for implementing the methods according to the present disclosure. Therefore, the present disclosure also covers a recording medium storing a program for executing the methods according to the present disclosure.

[0208] It should also be noted that in the apparatuses, devices, and methods of the present disclosure, each component or each step can be decomposed and / or recombined. These decompositions and / or recombinations should be regarded as equivalent solutions of the present disclosure.

[0209] The above description of the disclosed aspects is provided to enable any person skilled in the art to make or use the present disclosure. Various modifications to these aspects will be readily apparent to those skilled in the art, and the general principles defined herein can be applied to other aspects without departing from the scope of the present disclosure. Therefore, the present disclosure is not intended to be limited to the aspects shown herein, but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.

[0210] The above description has been presented for purposes of illustration and description. In addition, this description is not intended to limit the embodiments of the present disclosure to the form disclosed herein. Although several example aspects and embodiments have been discussed above, those skilled in the art will recognize some of their variations, modifications, alterations, additions, and sub-combinations.

Claims

1. A function redirection method, characterized in that, The method includes: Starting a redirection process, where the redirection process is used to control the process resources of a target process, and the target process is a process for executing a target function to be redirected; Based on the redirection process, controlling the target process to link to a redirection dynamic library, where the redirection dynamic library includes a redirection function, and the redirection function is the function executed by the target process after redirection; Determining the function address of the target function through the linked redirection dynamic library, and binding the function address to the redirection function to redirect the target function to the redirection function.

2. The method according to claim 1, characterized in that, The controlling the target process to link to the redirection dynamic library based on the redirection process includes: Obtaining the process handle of the target process through the redirection process; Based on the process handle, writing the path corresponding to the redirection dynamic library into the target memory of the target process; Based on the target memory, creating a first thread in the target process, so that the target process links to the redirection dynamic library by executing the first thread.

3. The method according to claim 1, characterized in that, The determining the function address of the target function includes: In response to the target function being an exported function, querying the function address of the target function from the target dynamic library where the target function is located; In response to the target function being a non-exported function, determining the function address of the target function based on the base address of the target dynamic library and the function offset of the non-exported function.

4. The method according to claim 3, characterized in that, The determining the function address of the target function based on the base address of the target dynamic library and the function offset of the non-exported function includes: Obtaining the preferred loading address of the target dynamic library and the virtual address of the target function, where the preferred loading address is a preset address where the target dynamic library is mapped to the process address space, and the virtual address is the preset address of the target function in the target dynamic library; Determining the function offset based on the difference between the virtual address and the preferred loading address; Determining the function address of the target function based on the sum of the function offset and the base address.

5. The method according to any one of claims 1 to 4, characterized in that After binding the function address to the redirection function, the method further includes: Obtaining the process handle of the target process through the redirection process; Searching for the dynamic library handle corresponding to the redirection dynamic library based on the process handle; Based on the dynamic library handle, creating a second thread in the target process, so that the target process unloads the redirection dynamic library by executing the second thread.

6. The method according to any one of claims 1 to 4, characterized in that After linking the redirection dynamic library to the target process based on the redirection process, the method further includes: Reading pre-configured configuration information through the redirection dynamic library, where the configuration information includes information indicating whether each function needs to be redirected; Based on the configuration information, determining the target function to be redirected.

7. The method according to claim 6, wherein The determining the target function to be redirected based on the configuration information includes: Reading the enable flag bits of each function from the configuration information; In response to the enable flag bit of the function being a preset flag, determining the function as the target function.

8. The method according to claim 2, wherein Obtaining the process handle of the target process through the redirection process includes: Executing a process snapshot through the redirection process to obtain a process snapshot list; Querying the process number of the target process from the process snapshot list; Obtaining the process handle of the target process based on the process number.

9. A function redirection device, characterized in that, The device includes: A process startup module for starting a redirection process, where the redirection process is used to control the process resources of a target process, and the target process is a process for executing a target function that needs to be redirected; A dynamic library linking module for controlling the target process to link a redirection dynamic library based on the redirection process, where the redirection dynamic library includes a redirection function, and the redirection function is the function executed by the target process after redirection; A function redirection module for determining the function address of the target function through the linked redirection dynamic library, and binding the function address to the redirection function to redirect the target function to the redirection function.

10. An electronic device, characterized in that, Includes: A memory for storing a computer program; A processor for executing the computer program stored in the memory, and when the computer program is executed, implementing the function redirection method according to any one of claims 1 to 8 above.

11. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, the function redirection method according to any one of claims 1 to 8 above is implemented.