Anti-debugging method and device for ios system

By modifying the kernel data structure at the kernel level of the iOS system, bypassing anti-debug protection, the problem of user-state operations being easily detected is solved, and more stable and hidden debugger attachment and state adjustment is achieved, enhancing system compatibility and security.

CN120337209APending Publication Date: 2025-07-18BEIJING ZHI YOU WANG AN TECH CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202510382887.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-28
Publication Date
2025-07-18

AI Technical Summary

Technical Problem

The anti-reverse debugging technology of the existing iOS system mainly relies on user-state operations, which are easy to be detected, and lacks stability and real-time performance. The Hook operation introduces additional performance overhead, affecting the normal operation of the target process and system stability.

Method used

By obtaining the kernel read and write permissions of the iOS system, directly modify the kernel data structure such as proc structure and task_struct, clear or modify the relevant flag bits to bypass anti-debugging protection, and monitor the debugger requests in real time for dynamic adjustments, and restore the original protection state after debugging.

Benefits of technology

It realizes more efficient and hidden debugger attachment, improves the stability and compatibility of the debugging process, reduces dependence on jailbreak or specific high-privileged operations, and avoids long-term exposure of system security vulnerabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120337209A_ABST
    Figure CN120337209A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of computer security, and particularly relates to an anti-debugging method and device for an ios system. The method comprises the steps of obtaining kernel read-write permission of an ios system, positioning a kernel data structure of a target process, and modifying the kernel data structure of the target process to bypass anti-debugging protection; monitoring a preset event in real time, and dynamically adjusting the state of the target process in the debugging process of the debugger in response to the event so as to facilitate debugging; and after the debugging is finished or the debugger is disconnected, recovering the original anti-debugging protection state of the target process. The invention provides the anti-debugging method of the ios system, which is more difficult to detect, more stable and lower in system overhead.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure belongs to the field of computer security technology, and particularly relates to an anti-anti-debugging method and device for an iOS system. Background Art

[0002] To prevent applications from being reverse engineered, debugged, or tampered with, modern software systems generally adopt anti-debugging technologies to prevent debuggers from debugging target processes (such as by checking system calls, flag detection, etc.). However, in scenarios such as security assessment, vulnerability analysis, and privacy detection, the debugging function is essential, which has given rise to anti-anti-debugging technologies, that is, finding ways to bypass anti-debugging protection so that the debugger can normally attach to and analyze the process.

[0003] On the iOS platform, traditional anti-debugging protection measures often rely on user-space protection mechanisms, such as setting specific flags (e.g., P_LNOATTACH) at the application level and preventing debugger attachment by hooking system APIs or monitoring system calls. Existing anti-anti-debugging technologies also mainly focus on the user space, such as dynamic library injection and API Hook. Auxiliary debugging modules are loaded using dynamic injection means, and key APIs (such as ptrace, sysctl, etc.) are hooked when the target process starts to detect and intervene in debugger debugging requests. By clearing or forging anti-debugging flags (e.g., modifying the P_LNOATTACH flag), the debugger can attach to the target process.

[0004] However, since the operations are limited to the user space, it is easy to capture features and the stability is poor. The existing solutions perform dynamic library injection and API Hook in the user space, and their operations are easily captured by system integrity detection or anti-debugging mechanisms; due to relying on hooking key APIs in the user space, these methods may not be timely or stable enough when dealing with dynamic changes in the process state. System updates or adjustments to security policies may render existing hook methods ineffective, thus affecting the success rate of debugger attachment. Hook operations introduce additional runtime overhead, which may affect the normal operation of the target process and even cause system instability or abnormal behavior in some cases. Summary of the Invention

[0005] In view of the above problems, various embodiments of the present disclosure propose an anti-anti-debugging solution for the iOS system by modifying kernel-level data structures.

[0006] The first aspect of the embodiments of the present disclosure provides an anti-anti-debugging method for an iOS system, including:

[0007] Obtain the kernel read-write permission of the iOS system, locate the kernel data structure of the target process, and modify the kernel data structure of the target process to bypass anti-debugging protection;

[0008] Monitor preset events in real time, and dynamically adjust the state of the target process during the debugging process of the debugger in response to the events to facilitate debugging;

[0009] After the debugging ends or the debugger disconnects, restore the original anti-debugging protection state of the target process.

[0010] In some embodiments of the present disclosure, obtaining the memory read and write permissions of the iOS system includes:

[0011] Obtaining the kernel read and write permissions of the iOS system through jailbreaking technology; or

[0012] Obtaining the kernel read and write permissions of the iOS system by loading a specific kernel module; or

[0013] Obtaining temporary kernel read and write permissions of the iOS system through vulnerabilities in the iOS system kernel.

[0014] In some embodiments of the present disclosure, locating the kernel data structure of the target process includes:

[0015] Traverse the kernel process linked list maintained by the kernel, search for the data structure of the target process, and locate the memory address and key fields of the data structure, where the data structure is a proc structure or a task_struct, and the key fields include at least a flag bit and a process identifier.

[0016] In some embodiments of the present disclosure, modifying the kernel data structure of the target process to bypass anti-debugging protection includes:

[0017] In the proc structure of the target process, clear the prohibited attachment debug flag bit to lift the kernel's restriction on debugger attachment, where the prohibited attachment debug flag bit is the P_LNOATTACH flag; and

[0018] Modify the process debug status flag in the proc structure to forcibly mark the target process as the "allowed to debug" state, where the process debug status flag is the p_lflag field.

[0019] In some embodiments of the present disclosure, modifying the kernel data structure of the target process to bypass anti-debugging protection includes:

[0020] Modify the debug protection flag in the task_struct structure; or

[0021] Perform local patching on the key functions for debug attachment detection in the kernel to mask or redirect anti-debugging detection.

[0022] In some embodiments of the present disclosure, the real-time monitoring of a preset event and the response to the event include:

[0023] Real-time listening to the debugging requests of a debugger through an integrated debugger interaction tool, where the debugger interaction tool is an lldb-rpc-server; or

[0024] Real-time monitoring of kernel logs or independent monitoring of kernel drivers to detect debugging requests of the debugger; or

[0025] Real-time monitoring of system event notifications to detect debugging requests of the debugger.

[0026] In some embodiments of the present disclosure, the dynamic adjustment of the state of the target process during the debugger debugging in response to the event includes:

[0027] In response to the debugging request, immediately verify the debugging status flag of the target process. If the debugging status flag is not allowed to debug, reset it to allowed to debug; and

[0028] In response to the debugging request, dynamically adjust the process state of the target process according to preset rules, where the dynamic adjustment includes suspension and pause.

[0029] In some embodiments of the present disclosure, restoring the original anti-debugging protection state of the target process after the debugging ends or the debugger disconnects includes:

[0030] When it is detected that the debugging ends or the debugger disconnects, automatically detect the anti-debugging protection state of the target process and restore it to not allowed to debug; or

[0031] Every preset time interval, automatically detect the anti-debugging protection state of the target process and restore it to not allowed to debug; or

[0032] In response to a preset event, detect the anti-debugging protection state of the target process and restore it to not allowed to debug.

[0033] In some embodiments of the present disclosure, modifying the kernel data structure of the target process to bypass anti-debugging protection further includes:

[0034] At the kernel level, hijack the system call used to detect the debugger attachment, and replace the system call with a function that returns preset data to indirectly bypass the anti-debugging mechanism.

[0035] The second aspect of the embodiments of the present disclosure provides an anti-anti-debugging device for an ios system, including:

[0036] Modification module, used to obtain the kernel read and write permissions of the iOS system, locate the kernel data structure of the target process, and modify the kernel data structure of the target process to bypass the anti-debugging protection;

[0037] Adjustment module, used to monitor preset events in real time, and dynamically adjust the state of the target process during the debugging process of the debugger in response to the event to facilitate debugging;

[0038] Recovery module, used to restore the original anti-debugging protection state of the target process after the debugging ends or the debugger disconnects.

[0039] In summary, the anti-anti-debugging methods and devices for the iOS system provided by the embodiments of the present disclosure achieve bypassing anti-debugging protection through kernel-level data structure modification. Compared with traditional user-mode hook methods, they are not easily monitored and detected by the system, thereby improving the concealment of debugger attachment; because the data structure is directly operated at the kernel layer, it can respond to debugger attachment requests in real time and adjust the process state in a timely manner to ensure the stability of the state during the debugging process; at the same time, because the dependence on jailbreaking or specific high-privilege operations is reduced, in different versions of the iOS system, only slight parameter adjustments are required according to the kernel data structure to achieve the same debugging breakthrough effect, thereby enhancing compatibility; after the debugging is completed, the anti-debugging flag is automatically restored, which not only meets the debugging requirements but also does not expose system security vulnerabilities for a long time. BRIEF DESCRIPTION OF THE DRAWINGS

[0040] The features and advantages of the present disclosure will be more clearly understood by referring to the accompanying drawings. The drawings are schematic and should not be construed as imposing any limitation on the present disclosure. In the drawings:

[0041] Figure 1 is the overall framework diagram of the anti-anti-debugging algorithm based on iOS kernel-level data structure modification shown in the present disclosure;

[0042] Figure 2 is the flowchart of an anti-anti-debugging method for an iOS system shown in some embodiments of the present disclosure;

[0043] Figure 3 is the schematic diagram of modifying the data structure of the kernel in some embodiments of the present disclosure;

[0044] Figure 4 is the schematic diagram of an anti-anti-debugging device for an iOS system shown in some embodiments of the present disclosure. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0045] In the following detailed description, numerous specific details are set forth by way of examples in order to provide a thorough understanding of the relevant disclosures. However, it will be apparent to those of ordinary skill in the art that the present disclosure may be practiced without these details. It should be understood that the terms "system", "device", "unit", and / or "module" used in the present disclosure are a means of distinguishing between different components, elements, parts, or assemblies at different levels in a sequential arrangement. However, if other expressions can achieve the same purpose, these terms may be replaced by other expressions.

[0046] It should be understood that when a device, unit, or module is referred to as being "on", "connected to", or "coupled to" another device, unit, or module, it can be directly on, connected to, or coupled to or communicate with the other device, unit, or module, or there may be intermediate devices, units, or modules, unless the context clearly indicates an exception. For example, the term "and / or" used in the present disclosure includes any and all combinations of one or more of the associated listed items.

[0047] The terms used in the present disclosure are only for the purpose of describing specific embodiments and are not intended to limit the scope of the present disclosure. As shown in the specification and claims of the present disclosure, unless the context clearly indicates an exception, words such as "a", "an", "one", and / or "the" are not specifically singular and may also include the plural. Generally speaking, the terms "comprising" and "including" only indicate the inclusion of the features, wholes, steps, operations, elements, and / or components that have been clearly identified, and such expressions do not constitute an exclusive listing, and other features, wholes, steps, operations, elements, and / or components may also be included.

[0048] Referring to the following description and the accompanying drawings, these or other features and characteristics of the present disclosure, the operating methods, the functions of the relevant elements of the structure, the combination of parts, and the economy of manufacture can be better understood, where the description and the drawings form a part of the specification. However, it should be clearly understood that the drawings are only for the purpose of illustration and description and are not intended to limit the scope of protection of the present disclosure. It can be understood that the drawings are not drawn to scale.

[0049] A variety of structure diagrams are used in the present disclosure to illustrate various variations according to the embodiments of the present disclosure. It should be understood that the structures before or below are not used to limit the present disclosure. The scope of protection of the present disclosure is subject to the claims.

[0050] With the popularity of mobile devices and smartphones, the security of mobile operating systems (such as iOS) has received increasing attention. To prevent applications from being reverse-engineered, debugged, or tampered with, modern software systems generally adopt anti-debugging technologies. These technologies are usually implemented in the user space, and prevent the debugger from debugging the target process (such as by checking system calls, flag detection, etc.) by detecting debugger attachment, hooking key APIs, setting anti-debugging flag bits, etc. However, in scenarios such as security assessment, vulnerability analysis, and privacy detection, the debugging function is essential, which has given rise to anti-anti-debugging technologies, that is, finding ways to bypass anti-debugging protection so that the debugger can attach and analyze the process normally.

[0051] On the iOS platform, traditional anti-debugging protection measures often rely on protection mechanisms in the user space, such as setting specific flag bits (such as P_LNOATTACH) at the application level, and preventing debugger attachment by hooking system APIs or monitoring system calls.

[0052] Correspondingly, the existing anti-anti-debugging technologies on the iOS platform mainly focus on the user space, and their implementation schemes are mainly based on dynamic library injection and API Hook: that is, using dynamic injection means to load auxiliary debugging modules, and hooking key APIs (such as ptrace, sysctl, etc.) when the target process starts, detecting and intervening in debugger attachment requests. By clearing or forging anti-debugging flags (such as modifying the P_LNOATTACH flag bit), the debugger can be attached to the target process.

[0053] However, the anti-anti-debugging technologies based on the user space have the following disadvantages:

[0054] Prone to detection and bypass:

[0055] The existing solutions perform dynamic library injection and API Hook in the user space, and their operations are easily captured by system integrity detection or anti-debugging mechanisms. Once detected, the debugger attachment process may be intervened or blocked, resulting in the debugger operation being unable to proceed smoothly.

[0056] Lack of stability and real-time performance:

[0057] Due to relying on hooking key APIs in the user space, such methods may not be timely or stable enough when dealing with dynamic changes in the process state. System updates or adjustments to security policies may render existing hooking methods ineffective, thus affecting the success rate of debugger attachment.

[0058] Extra performance overhead and system interference:

[0059] The Hook operation will introduce additional runtime overhead, which may affect the normal operation of the target process, and even cause system instability or abnormal behavior in some cases.

[0060] To solve the above problems, the present disclosure proposes a method based on modifying the iOS kernel-level data structure, which directly controls the process debugging state at the kernel level, thereby bypassing the existing anti-debugging protection mechanism and achieving more efficient and reliable debugger attachment and security detection functions. The overall framework of the anti-anti-debugging algorithm based on modifying the iOS kernel-level data structure shown in the present disclosure is as Figure 1 shown. In some embodiments, the process of the anti-anti-debugging method of the ios system is Figure 2 shown, and specifically includes the following steps:

[0061] S210, obtain the kernel read and write permissions of the ios system, locate the kernel data structure of the target process, and modify the kernel data structure of the target process to bypass the anti-debugging protection.

[0062] The present disclosure needs to obtain the kernel-level permissions of the device (such as tfp0) so that the kernel memory can be directly accessed and modified subsequently.

[0063] In some embodiments of the present disclosure, the kernel read and write permissions are obtained through jailbreaking technology or loading specific kernel modules. Then, the system kernel interface is called to verify whether the permission acquisition is successful.

[0064] In other embodiments, privilege escalation is performed by exploiting known vulnerabilities (or zero-day vulnerabilities) for the iOS kernel, and temporary kernel read and write permissions are obtained by exploiting the vulnerabilities, so as to achieve the purpose of modifying the kernel data structure while eliminating the dependence on jailbreaking or specific kernel modules.

[0065] After obtaining the read and write permissions for the system kernel, the data structure of the kernel can be modified. Figure 3 is a schematic diagram of modifying the data structure of the kernel in some embodiments of the present disclosure.

[0066] As Figure 3 shown, in some embodiments of the present disclosure, modifying the data structure of the kernel includes:

[0067] First, traverse the process list in the kernel (such as the kernproc list) and locate the kernel data structure of the target process (such as the proc structure or task_struct) to accurately locate the target process data structure to be modified, providing a basis for modification for subsequent modules.

[0068] The specific method is:

[0069] 1. Directly read the memory through the kernel permissions to obtain the starting address of the process list.

[0070] 2. Traverse each node in the linked list and extract key information including PID, parent PID, debug flags (such as p_lflag), etc.

[0071] Then modify the kernel data structure of the target process to bypass the anti-debug protection, enabling the debugger to attach to the process without being detected. Specifically:

[0072] 1. Clear the anti-debug flag:

[0073] Through kernel memory write operations, clear the P_LNOATTACH flag used for anti-debug protection in the proc structure.

[0074] 2. Modify the debug flag:

[0075] Adjust other flag bits in the p_lflag field to an allowed state for the debugger to attach as needed.

[0076] Forgery of process information:

[0077] When necessary, modify the PID or parent PID of the process so that the target process does not seem to have the risk of being debugged when being monitored.

[0078] Description of key parameters:

[0079] The P_LNOATTACH flag: The value depends on the specific iOS version, and precise bit operations (such as bitwise AND / OR operations) are required when modifying.

[0080] The p_lflag field: Directly reflects the debug protection status of the process, and the debug permission status of the process can be immediately changed by modifying this field.

[0081] In some other embodiments of the present disclosure, modifying the kernel data structure includes:

[0082] 1. Directly modify the debug protection flag in the task_struct structure. Or

[0083] 2. Perform local patching on the key functions for debug attach detection in the kernel to mask or redirect anti-debug detection.

[0084] 2 It is not limited to modifying a single data structure field, can be flexibly adjusted according to the specific kernel implementation in different iOS versions, and can also avoid the failure of the solution due to a certain data field being updated by the system.

[0085] S220, Real-time monitor preset events, and in response to the events, dynamically adjust the state of the target process during the debugger debugging process to facilitate debugging.

[0086] In some embodiments of the present disclosure, the debugger attachment request is monitored in real time through the LLDB Remote Procedure Call Server. After the attachment request is detected, it is ensured that the target process status meets the debugger access requirements; if not, the process status is dynamically adjusted as necessary (such as suspended, paused).

[0087] In some embodiments of the present disclosure, a multi-channel monitoring method is introduced. For example, by combining kernel log monitoring, system event notification, and independent kernel driver monitoring, multiple redundancies are achieved. When one channel fails, other channels can still trigger the modification or restoration operation of the kernel data structure.

[0088] S230, after the debugging ends or the debugger disconnects, restore the original anti-debugging protection status of the target process.

[0089] After some embodiments of the present disclosure detect that the debugger disconnects, the p_lflag field of the process is reset back to its original state (add the P_LNOATTACH flag), thereby restoring the original anti-debugging protection status of the target process. The debugging process and status changes are recorded during the process to ensure that the operations are traceable.

[0090] Some other embodiments of the present disclosure introduce a timer or event monitoring mechanism, that is, after a predetermined time interval, or after detecting a certain system security event, the flag in the kernel data structure of the target process is automatically restored to its original state. Thereby preventing the protection from not being restored for a long time due to abnormal situations (such as abnormal termination of the debugger), enhancing the system security, and at the same time increasing the adaptability of the solution.

[0091] Figure 4 It is a schematic diagram of an anti-anti-debugging device for an iOS system shown in some embodiments of the present disclosure. As Figure 4 shown, the anti-anti-debugging device 400 for the iOS system includes a modification module 410, an adjustment module 420, and a restoration module 430. Among them:

[0092] The modification module 410 is used to obtain the kernel read and write permissions of the iOS system, locate the kernel data structure of the target process, and modify the kernel data structure of the target process to bypass the anti-debugging protection;

[0093] The adjustment module 420 is used to monitor preset events in real time, and dynamically adjust the status of the target process during the debugger debugging process in response to the event to facilitate debugging;

[0094] The restoration module 430 is used to restore the original anti-debugging protection status of the target process after the debugging ends or the debugger disconnects.

[0095] In summary, the anti-anti-debugging methods and devices for iOS systems provided by the embodiments of the present disclosure achieve bypassing anti-debugging protection through kernel-level data structure modification. Compared with traditional user-mode hook methods, they are not easily detected by system monitoring, thereby improving the concealment of debugger attachment. Since the data structure is directly operated at the kernel layer, it can respond to debugger attachment requests in real time and adjust the process state in a timely manner to ensure the stability of the state during the debugging process. At the same time, because the dependence on jailbreaking or specific high-privilege operations is reduced, in different versions of the iOS system, only slight parameter adjustments are required according to the kernel data structure to achieve the same debugging breakthrough effect, thereby enhancing compatibility. After the debugging is completed, the anti-debugging flag is automatically restored, which not only meets the debugging requirements but also does not expose system security vulnerabilities for a long time.

[0096] Although the subject matter described herein is provided in the general context of the execution of an operating system and application programs on a computer system, those skilled in the art will recognize that other implementations may also be performed in combination with other types of program modules. Generally, program modules include routines, programs, components, data structures, and other types of structures that perform specific tasks or implement specific abstract data types. Those skilled in the art will understand that the subject matter described herein may be practiced using other computer system configurations, including handheld devices, multiprocessor systems, microprocessor-based or programmable consumer electronics, minicomputers, mainframe computers, etc., and may also be used in a distributed computing environment where tasks are performed by remote processing devices connected through a communication network. In a distributed computing environment, program modules may be located in both local and remote memory storage devices.

[0097] Those of ordinary skill in the art can realize that the units and method steps of the examples described in conjunction with the embodiments disclosed herein can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present disclosure.

[0098] It should be understood that the above specific embodiments of the present disclosure are only for illustrative or explanatory purposes of the principles of the present disclosure and do not constitute a limitation to the present disclosure. Therefore, any modifications, equivalent replacements, improvements, etc. made without departing from the spirit and scope of the present disclosure should be included within the protection scope of the present disclosure. In addition, the appended claims of the present disclosure are intended to cover all changes and modifications that fall within the scope and boundaries of the appended claims, or equivalent forms of such scope and boundaries.

Claims

1. An anti-anti-debugging method for iOS system, characterized in that Including: Obtain the kernel read and write permissions of the iOS system, locate the kernel data structure of the target process, and modify the kernel data structure of the target process to bypass the anti-debugging protection; Monitor preset events in real time, and dynamically adjust the state of the target process during the debugging process of the debugger in response to the events to facilitate debugging; After the debugging ends or the debugger disconnects, restore the original anti-debugging protection state of the target process.

2. The method according to claim 1, wherein The obtaining of the memory read and write permissions of the iOS system includes: Obtain the kernel read and write permissions of the iOS system through jailbreaking technology; or Obtain the kernel read and write permissions of the iOS system by loading a specific kernel module; or Obtain temporary kernel read and write permissions of the iOS system through vulnerabilities in the iOS system kernel.

3. The method according to claim 1, wherein The locating of the kernel data structure of the target process includes: Traverse the kernel process linked list maintained by the kernel, search for the data structure of the target process, and locate the memory address and key fields of the data structure, where the data structure is a proc structure or a task_struct, and the key fields include at least a flag bit and a process identifier.

4. The method according to claim 1, wherein The modifying of the kernel data structure of the target process to bypass the anti-debugging protection includes: In the proc structure of the target process, clear the prohibited attachment debug flag bit to lift the kernel's restriction on debugger attachment, where the prohibited attachment debug flag bit is the P_LNOATTACH flag; and Modify the process debug status flag in the proc structure, and forcefully mark the target process as the "allowed to debug" state, where the process debug status flag is the p_lflag field.

5. The method according to claim 3, wherein The modifying of the kernel data structure of the target process to bypass the anti-debugging protection includes: Modify the debug protection flag in the task_struct structure; or Perform local patching on the key functions for debug attachment detection in the kernel to mask or redirect anti-debugging detection.

6. The method according to claim 1, wherein The monitoring of preset events in real time and the response to the events include: Through the integrated debugger interaction tool, listen to the debug requests of the debugger in real time, where the debugger interaction tool is the lldb-rpc-server; or Monitor the kernel log in real time or perform independent monitoring on the kernel driver to detect the debug requests of the debugger; or Monitor the system event notification in real time to detect the debug requests of the debugger.

7. The method according to claim 1, wherein The dynamically adjusting of the state of the target process during the debugging process of the debugger in response to the events includes: In response to the debug request, immediately verify the debug status flag of the target process. If the debug status flag is not allowed to debug, reset it to allowed to debug; and In response to the debug request, dynamically adjust the process state of the target process according to preset rules, where the dynamic adjustment includes suspension and pause.

8. The method according to claim 1, wherein The restoring of the original anti-debugging protection state of the target process after the debugging ends or the debugger disconnects includes: When it is detected that the debugging ends or the debugger disconnects, automatically detect the anti-debugging protection state of the target process and restore it to not allowed to debug; or Every time a preset time interval elapses, automatically detect the anti-debugging protection status of the target process and restore it to disallow debugging; or In response to a preset event, detect the anti-debugging protection status of the target process and restore it to disallow debugging.

9. The method according to claim 1, wherein The modification of the kernel data structure of the target process to bypass anti-debugging protection further includes:[[]] At the kernel level, hijack the system call used to detect the attachment of a debugger, and replace the system call with a function that returns preset data to indirectly bypass the anti-debugging mechanism.

10. An anti-anti-debugging device for iOS system, characterized in that, It includes:[[]] A modification module, which is used to obtain the kernel read and write permissions of the ios system, locate the kernel data structure of the target process, and modify the kernel data structure of the target process to bypass anti-debugging protection; An adjustment module, which is used to monitor preset events in real time, and dynamically adjust the status of the target process during the debugging process of the debugger in response to the event to facilitate debugging; A restoration module, which is used to restore the original anti-debugging protection status of the target process after the debugging ends or the debugger disconnects.

Citation Information

Patent Citations

  • Debugger and debugging method thereof

    CN102346708A

  • Malicious process debugging method and device, electronic equipment and medium

    CN112231198A

  • Kernel tracing in a protected kernel environment

    US20170249236A1