An OEP positioning and automatic identification method of a de-shelling point in an anti-virus de-shelling scene

CN122413430BActive Publication Date: 2026-09-18BEIJING JIANGMIN XINKE TECH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610801437.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2026-06-04
Publication Date
2026-09-18
Estimated Expiration
2046-06-04

AI Technical Summary

Technical Problem

[0003]针对脱壳场景下的原始入口点定位,现有的技术方案主要通过基于特定壳代码特征的识别方案,该方案通过人工分析或机器学习提取特定壳的运行规律与结束特征来设定判定规则,该方案受限于一对一的规则匹配逻辑,在面对层出不穷的新型未知壳或变种壳时,往往无法命中规则,适应性与扩展性较差

Benefits of technology

1、本发明中,通过捕捉脱壳完成后程序本体在初始化阶段相对固定的编译器侧特征,提升了针对未知壳与变种壳的泛化适应能力,使其不依赖于特定外壳内部的运行逻辑与解密规则进行脱壳点判定,能够绕过外壳层面的混淆手段,无论外壳如何变化更新,均能通过统一的底层标准实现脱壳点的定位,有效提高脱壳系统对新型加壳样本的识别能力。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122413430B_ABST
    Figure CN122413430B_ABST
Patent Text Reader

Abstract

The application provides an OEP positioning and automatic identification method in an antiviral unshelling scene, belongs to the technical field of computer data processing, and is used to improve the identification ability of an unshelling system on new shell samples. By capturing the relatively fixed compiler side features of the program body after unshelling is completed in the initialization stage, the generalization adaptability to unknown shells and variant shells is improved, the unshelling point is determined without depending on the running logic and decryption rules in the specific shell, the shell layer confusion means can be bypassed, the unshelling point can be positioned through a unified bottom standard regardless of how the shell changes and updates, and the identification ability of the unshelling system on new shell samples is effectively improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of computer data processing technology, and in particular to a method for OEP location and automatic identification of unpacking points in anti-virus unpacking scenarios. Background Technology

[0002] In the fields of antivirus and malware analysis, executable files are typically encapsulated by various packing tools or obfuscation techniques to hide their true program logic and code structure. To recover the original, analyzable code, a security system needs to execute the packed file in a controlled, simulated environment and accurately locate the point where the program has finished unpacking and is about to enter the protected main code—the Original Entry Point (OEP). The accuracy of OEP location directly affects the reliability of subsequent malware sample detection, sandbox analysis, and code reconstruction.

[0003] For the original entry point location in the unpacking scenario, the existing technical solutions mainly use identification schemes based on the characteristics of specific shell codes. These schemes extract the operating rules and termination characteristics of specific shells through manual analysis or machine learning to set judgment rules. However, this scheme is limited by one-to-one rule matching logic, and often fails to match the rules when faced with a constant stream of new and unknown shells or variant shells, resulting in poor adaptability and scalability.

[0004] In feature matching schemes based on compiler entry instruction codes, fixed instruction codes of various compilers are collected at the original entry point as unpacking features. However, due to the wide variety of compilers and the fact that the form of entry instruction codes generated by the same compiler can change under different compilation optimization options, the method of simply relying on instruction code fragment comparison is prone to missed detections and feature failures, resulting in insufficient localization stability. In order to cover various compilation situations, the number of instruction codes that need to be collected is too large, which leads to the unpacking system needing to carry a bloated feature library, increasing the system's resource overhead, and there is room for improvement. Summary of the Invention

[0005] This invention provides a method for OEP location and automatic identification of unpacking points in anti-virus unpacking scenarios, in order to improve the unpacking system's ability to identify new packed samples.

[0006] To achieve the above objectives, the present invention adopts the following technical solution: Firstly, a method for OEP location and automatic identification of unpacking points in antivirus unpacking scenarios is provided, including: The packed file is sent into a controlled micro sandbox environment for simulated execution, and jump behavior is monitored in the execution flow of the simulated execution. In response to detecting a feature signal indicating the completion of unpacking through the jump behavior, the jump target position that generated the feature signal is obtained; Starting from the jump target position, an instruction sequence is collected, and an execution log at the candidate original entry point is generated based on the collected instruction sequence; Extract the segment register access sequence, application programming interface call sequence, and abnormal instruction sequence used to exclude shell code interference from the execution log, and concatenate the segment register access sequence, application programming interface call sequence, and abnormal instruction sequence to form a structured feature set; Perform a fuzzy hash operation on the structured feature set to generate a compact hash string; Map the compact hash string to a candidate feature vector in numerical format; Calculate the cosine similarity between the candidate feature vector and each fingerprint vector in the known compiler fingerprint vector library; In response to the cosine similarity being greater than or equal to a similarity threshold used to balance recall and precision, the current jump target location is determined to be the true original entry point.

[0007] Optionally, the detection of a feature signal indicating the completion of uncoating through the jump behavior includes at least one of the following: A code page attribute switching behavior was detected in the execution flow; An unconditional jump behavior that satisfies the offset constraint was detected in the execution flow; Execution behavior is performed after a memory write is detected in the execution flow.

[0008] Optionally, extracting the abnormal instruction sequence from the execution log to exclude interference from shell code includes: Identify breakpoint instructions in the execution log that meet the quantity limit, and treat these breakpoint instructions as the sequence of abnormal instructions; or... The execution log is identified to contain instructions that contain self-modifying write behavior, and these instructions are designated as the abnormal instruction sequence.

[0009] Optionally, the segment register access sequence includes the access location and order of the data segment register or the additional segment register; The application programming interface call sequence includes the order and relative offset of the initialization functions being called.

[0010] Optionally, calculating the cosine similarity between the candidate feature vector and each fingerprint vector in the known compiler fingerprint vector library includes: Extract each component of the first dimension of the candidate feature vector, and extract each component of the second dimension of each fingerprint vector; Based on each component of the first dimension and each component of the second dimension, calculate the cosine value of the angle between the candidate feature vector and each fingerprint vector. The cosine value is used as the cosine similarity.

[0011] Optionally, the similarity threshold used to balance recall and precision is determined in the following way: Simulated recognition operations were performed on a dataset containing labeled and shielded samples by applying different candidate similarity parameters. The precision and recall of the recognition results were statistically analyzed for each candidate similarity parameter. The harmonic mean is calculated based on the precision and recall to obtain a comprehensive evaluation index for each candidate similarity parameter; A candidate similarity parameter is selected that makes the comprehensive evaluation index reach its maximum value, and this candidate similarity parameter is used as the similarity threshold used to balance recall and precision.

[0012] Secondly, a device for OEP positioning and automatic identification of unpacking points in anti-virus unpacking scenarios is provided, configured to include: The simulation execution module is used to send the packed file into a controlled micro sandbox environment for simulated execution, and to monitor jump behavior in the execution flow of the simulated execution; The log generation module is configured to, in response to detecting a feature signal indicating the completion of unpacking through the jump behavior, obtain the jump target position that generated the feature signal; and collect an instruction sequence from the jump target position, and generate an execution log at the candidate original entry point based on the collected instruction sequence. The feature extraction module is used to extract the segment register access sequence, application programming interface call sequence, and abnormal instruction sequence for eliminating shell code interference from the execution log, and to form a structured feature set based on the segment register access sequence, the application programming interface call sequence, and the abnormal instruction sequence. A feature vectorization module is used to perform fuzzy hashing on the structured feature set to generate a compact hash string; and to map the compact hash string into a candidate feature vector in numerical format; The similarity calculation module is used to calculate the cosine similarity between the candidate feature vector and each fingerprint vector in the known compiler fingerprint vector library.

[0013] Also includes: The unpacking point determination module is used to determine the current jump target position as the true original entry point in response to the cosine similarity being greater than or equal to the similarity threshold used to balance recall and precision.

[0014] Thirdly, an electronic device is provided, comprising: a processor and a memory; the memory is used to store a computer program, which, when executed by the processor, causes the electronic device to perform the OEP location and automatic identification of unpacking point in the anti-virus unpacking scenario described in the first aspect.

[0015] In one possible design, the electronic device described in the third aspect may further include a transceiver. This transceiver may be a transceiver circuit or an interface circuit. The transceiver can be used for communication between the electronic device described in the third aspect and other electronic devices.

[0016] In the embodiments of the present invention, the electronic device described in the third aspect may be a terminal, or a chip (system) or other component or assembly disposed in the terminal, or a system containing the terminal.

[0017] Fourthly, a computer-readable storage medium is provided, comprising: a computer program or instructions; when the computer program or instructions are run on a computer, the computer causes the computer to perform the OEP location and automatic identification of unpacking point method in the anti-virus unpacking scenario described in the first aspect.

[0018] In summary, the above methods and systems have the following technical effects: 1. In this invention, by capturing the relatively fixed compiler-side features of the program body during the initialization phase after unpacking, the generalization and adaptability to unknown shells and variant shells are improved. This makes it independent of the internal operating logic and decryption rules of a specific shell for determining the unpacking point, and can bypass the obfuscation methods at the shell level. No matter how the shell changes or is updated, the unpacking point can be located through a unified underlying standard, which effectively improves the unpacking system's ability to identify new packed samples.

[0019] 2. In this invention, by abandoning the practice of directly comparing fixed instruction codes that are easily affected by the compilation environment, the segment register access sequence, application programming interface call sequence, and abnormal instruction sequence near the original entry point are used as a structured feature base. Based on the extraction method of behavioral trajectory features, the sensitivity of the detection model to compiler version updates and optimization option changes is reduced, effectively reducing recognition failures or misjudgments caused by subtle changes in instructions.

[0020] 3. In this invention, by effectively controlling the feature library volume and optimizing the comparison efficiency, fuzzy hashing is performed on the extracted multidimensional structured feature set, and it is mapped to a fixed-dimensional numerical vector for cosine similarity calculation. While preserving the distinguishability of different compiler initialization behaviors, it suppresses local fine-grained differences and noise interference in code blocks, transforms the complex instruction library into a low-dimensional feature fingerprint vector library, significantly compresses the storage scale of pre-set samples, alleviates the feature library expansion problem, and ensures the execution efficiency of the system's online inference and matching judgment. Attached Figure Description

[0021] Figure 1 This is a flowchart illustrating the OEP location and automatic unpacking point identification method in the anti-virus unpacking scenario provided by an embodiment of the present invention. Figure 2 This is a schematic diagram of the OEP positioning and automatic unpacking point identification device in the anti-virus unpacking scenario provided in an embodiment of the present invention. Figure 3 This is a schematic diagram of the OEP location and automatic unpacking point identification method in the anti-virus unpacking scenario provided by the embodiments of the present invention. Figure 4 A schematic diagram of the overall operation logic of the OEP location and automatic identification of unpacking point in the anti-virus unpacking scenario provided in this embodiment of the invention; Figure 5 This is a schematic diagram illustrating the feature extraction method for OEP location and automatic identification of unpacking points in an anti-virus unpacking scenario provided in this embodiment of the invention. Figure 6 This is a schematic diagram illustrating the judgment scenario of the OEP location and automatic identification method for unpacking points in the anti-virus unpacking scenario provided in this embodiment of the invention. Detailed Implementation

[0022] The following will be combined with the appendix Figures 1-6 The technical solutions in this invention will be described below.

[0023] In this embodiment of the invention, "predefined" or "preconfigured" can be achieved by pre-saving corresponding codes, tables, or other means that can be used to indicate relevant information in the device. This embodiment of the invention does not limit the specific implementation method. "Saving" can refer to saving in one or more memories. These memories can be separate installations or integrated into the encoder, decoder, processor, or electronic device. Alternatively, some memories can be separately installed, while others are integrated into the decoder, processor, or electronic device. The type of memory can be any form of storage medium, and this embodiment of the invention does not limit this.

[0024] In this embodiment of the invention, descriptions such as "when," "under the circumstances," "if," and "if" all refer to the device making corresponding processing under certain objective circumstances, and are not limited to a specific time. They do not require the device to make a judgment action during implementation, nor do they imply any other limitations.

[0025] In the description of the embodiments of the present invention, unless otherwise stated, " / " indicates that the objects before and after are in an "or" relationship. For example, A / B can represent A or B. "And / or" in the embodiments of the present invention is merely a description of the relationship between the related objects, indicating that three relationships can exist. For example, A and / or B can represent: A alone, A and B simultaneously, and B alone, where A and B can be singular or plural. Furthermore, in the description of the embodiments of the present invention, unless otherwise stated, "multiple" refers to two or more. "At least one of the following" or similar expressions refer to any combination of these items, including any combination of single or plural items. For example, at least one of a, b, or c can represent: a, b, c, ab, ac, bc, or abc, where a, b, and c can be single or multiple. Additionally, to facilitate a clear description of the technical solutions of the embodiments of the present invention, the terms "first" and "second" are used in the embodiments of the present invention to distinguish identical or similar items with essentially the same function and effect. Those skilled in the art will understand that the terms "first," "second," etc., do not limit the quantity or order of execution, and that "first," "second," etc., are not necessarily different. Furthermore, in the embodiments of this invention, words such as "exemplary" or "for example" are used to indicate that something is being described as an example, illustration, or description. Any embodiment or design scheme described as "exemplary" or "for example" in the embodiments of this invention should not be construed as being more preferred or advantageous than other embodiments or design schemes. Specifically, the use of words such as "exemplary" or "for example" is intended to present the relevant concepts in a concrete manner for ease of understanding.

[0026] The network architecture and business scenarios described in the embodiments of this invention are for the purpose of more clearly illustrating the technical solutions of the embodiments of this invention, and do not constitute a limitation on the technical solutions provided by the embodiments of this invention. As those skilled in the art will know, with the evolution of network architecture and the emergence of new business scenarios, the technical solutions provided by the embodiments of this invention are also applicable to similar technical problems.

[0027] Figure 1 This is a flowchart illustrating the method provided in an embodiment of the present invention. This method for OEP location and automatic identification of the unpacking point in an anti-virus unpacking scenario can be applied to corresponding control terminals. The specific process is as follows: The packed file is sent into a controlled micro sandbox environment for simulated execution, and jump behavior is monitored in the execution flow of the simulated execution. In response to detecting a feature signal indicating the completion of unpacking through the jump behavior, the jump target position that generated the feature signal is obtained; Starting from the jump target position, an instruction sequence is collected, and an execution log at the candidate original entry point is generated based on the collected instruction sequence; Extract the segment register access sequence, application programming interface call sequence, and abnormal instruction sequence used to exclude shell code interference from the execution log, and concatenate the segment register access sequence, application programming interface call sequence, and abnormal instruction sequence to form a structured feature set; Perform a fuzzy hash operation on the structured feature set to generate a compact hash string; Map the compact hash string to a candidate feature vector in numerical format; Calculate the cosine similarity between the candidate feature vector and each fingerprint vector in the known compiler fingerprint vector library; In response to the cosine similarity being greater than or equal to a similarity threshold used to balance recall and precision, the current jump target location is determined to be the true original entry point.

[0028] Specifically, by extracting the structured behavioral trajectory of the program at the unpacking boundary rather than the specific instruction machine code, an entry detection mechanism that does not rely on specific shell rules is constructed. This can effectively reduce the interference of instruction form mutations caused by compiler iterations or optimization option fine-tuning, making the judgment benchmark more robust. By introducing fuzzy hashing and vectorized mapping, not only are subtle noises at the code level eliminated, but the amount of feature data that needs to be compared is also compressed, thereby improving the scanning efficiency and generalized recognition success rate when facing unknown packed variants in anti-virus scenarios.

[0029] Specifically, the following three types of structured features are extracted from the execution log by segmentation: Segment register access sequence — records the location and order in which segment registers such as FS / GS are accessed. These accesses have a strong regularity in the compiler startup code. API call sequence – recording the order and relative offset of typical initialization functions such as GetVersion, HeapCreate, GetCommandLineA, and GetEnvironmentStringsA being called; Reject set features—mark abnormal features such as a large number of breakpoint instructions (INT 3) or self-modifying write behavior in the log to exclude interference from shell code.

[0030] The above features are all expressed in the form of structured traces rather than raw opcode bytes, thus having a natural robustness to changes in compiler optimization options.

[0031] Where f1 = segment register access sequence characteristics, f2 = API call sequence characteristics, and f3 = rejection set characteristics. Fuzzy hashing vectorization: The extracted three feature sets are concatenated and then subjected to fuzzy hashing (FuzzyHash / ssdeep-like algorithms) to generate a compact hash string that allows for approximate matching. This hash string is then mapped to a fixed-dimensional numerical vector (i.e., the compiler fingerprint vector). The introduction of fuzzy hashing ensures that minor noise generated by the same compiler at different optimization levels or among slightly different samples does not affect the overall similarity, effectively reducing the feature library size and false positive rate.

[0032] ; Where LCS(A,B) is the longest common subsequence of two hash strings, and |·| represents the length; the higher the score, the more similar the two instruction sequences are; The generated fingerprint vector, along with its corresponding compiler type label, is written into the feature library for the discrimination module to perform online querying and matching in unpacking scenarios. The feature library supports grouping and indexing by compiler type to accelerate retrieval.

[0033] Furthermore, the feature is that the detection of the characteristic signal indicating the completion of unpacking through the jump behavior includes at least one of the following: A code page attribute switching behavior was detected in the execution flow; An unconditional jump behavior that satisfies the offset constraint was detected in the execution flow; Execution behavior is performed after a memory write is detected in the execution flow.

[0034] Specifically: Three typical dynamic execution flow anomaly modes are used to indicate the completion of unpacking. The system will only trigger the subsequent feature vector collection and calculation process when it detects a change in execution permissions or memory attributes from write to execute, an unconditional jump across the scope of a regular function call, or an operation that is executed immediately after the code segment has been tampered with. The determination of unpacking completion is converged on several representative shell code handover behaviors, avoiding the sandbox blindly extracting features throughout the entire program simulation lifecycle. This targeted interception strategy filters out obfuscated jumps and irrelevant decryption loops within the packed program, ensuring that the extracted execution logs are close to the original entry area of ​​the real program, reducing the computational load of subsequent comparison stages and reducing misjudgments caused by early disguised entry points.

[0035] Furthermore, the step of extracting the abnormal instruction sequence from the execution log to exclude interference from shell code includes: Identify breakpoint instructions in the execution log that meet the quantity limit, and treat these breakpoint instructions as the sequence of abnormal instructions; or: The execution log is identified to contain instructions that contain self-modifying write behavior, and these instructions are designated as the abnormal instruction sequence.

[0036] Specifically: The abnormal instruction sequences in the structured feature set are formed by the system searching the execution log for breakpoint triggering instructions that exceed the requirements of normal program logic, or searching for non-standard execution fragments that have self-modification and writing characteristics when extracting features. The special instruction behaviors that are screened out will be used as independent dimensions and compiled into the structured feature set for the final fuzzy hash dimensionality reduction. By transforming the traces of anti-analysis and countermeasures into auxiliary features for locating the real entry point, since packed programs often leave a large number of anti-debugging breakpoints or code self-decoding traces before handing over control, aggregating these anomalies into features can remove the interference of residual packer code on the real compiler fingerprint and cross-verify the particularity of the current execution stage from the side, thereby enhancing the robustness of the unpacking point identification model against obfuscation methods.

[0037] Furthermore, the segment register access sequence includes the access location and order of the data segment register or the additional segment register; The application programming interface call sequence includes the order and relative offset of the initialization functions being called.

[0038] Specifically: When processing segment registers, the focus is on extracting the absolute location and timing of accesses to specific data segments or additional segment registers. When processing interface calls, the order in which low-level functions such as operating system environment initialization are called and their relative distances in the execution flow are recorded. This allows the constructed fingerprint model to depict the inherent construction behavior skeleton of various compilers during the startup phase. Since different compilers have stable and exclusive patterns of requesting low-level segment space and system environment when generating initialization code, locking these location and order relationships can ignore register reuse or irrelevant instruction insertion caused by compiler optimization, thereby ensuring that the generated comparison vector has high fidelity and targeted distinguishing ability. Furthermore, calculating the cosine similarity between the candidate feature vector and each fingerprint vector in the known compiler fingerprint vector library includes: Extract each component of the first dimension of the candidate feature vector, and extract each component of the second dimension of each fingerprint vector; Based on each component of the first dimension and each component of the second dimension, calculate the cosine value of the angle between the candidate feature vector and each fingerprint vector. The cosine value is used as the cosine similarity.

[0039] Specifically: The packed file is also executed in a controlled simulation using a mini sandbox. Unlike the feature module, here it is necessary to dynamically monitor the jump behavior of the execution flow during execution. Whenever a possible unpacking completion signal is detected (such as code page attribute switching, unconditional jump with large offset, or execution after memory write, etc., which are typical shell end features), about 1,000 instructions are collected again from the jump target position to generate the execution log at the candidate OEP.

[0040] For the feature extraction and vectorization of candidate positions, the execution logs collected at the candidate OEP are processed in the same way as the feature extraction module. The segment register access sequence, API call sequence and rejection set features are extracted in sequence, and a fixed-dimensional candidate feature vector is generated by fuzzy hashing. This step does not require writing the results to the feature library, but only retains them in memory for subsequent comparison. The cosine similarity calculation in the feature comparison process involves first separating the numerical components of each dimension from the candidate feature vectors extracted online and the baseline fingerprint vectors stored in the feature library. These decomposed numerical components are then used for spatial geometric operations to calculate the cosine of the angle between the candidate vector and each baseline vector in multidimensional space. The core calculation logic follows the formula: in Candidate vectors, Let Aᵢ and Bᵢ be the fingerprint vectors in the feature library, where Aᵢ and Bᵢ are the components of each dimension, and n is the vector dimension; θ is the angle between the two vectors, cos(θ) ∈ [0, 1], and the closer the value is to 1, the more similar they are. The determination is as follows: Where T∈(0,1) is the preset similarity threshold, and ⟺ means "if and only if", where the variables represent the numerical components of the candidate vector and the fingerprint vector in each dimension. The cosine value is used to measure the degree of matching between the two. By transforming the code behavior trajectory into the vector angle operation in multi-dimensional space, the comparison error caused by the difference in the absolute length of the instruction sequence is eliminated. The mechanism of judging similarity based on the consistency of spatial direction can still evaluate the inherent consistency between the candidate position and the known compiler behavior even when the absolute value of the feature is shifted due to the internal code expansion of the packed program, thus improving the fault tolerance rate of the matching algorithm for abnormal instruction injection.

[0041] Furthermore, the similarity threshold used to balance recall and precision is determined in the following way: Simulated recognition operations were performed on a dataset containing labeled and shielded samples by applying different candidate similarity parameters. The precision and recall of the recognition results were statistically analyzed for each candidate similarity parameter. The harmonic mean is calculated based on the precision and recall to obtain a comprehensive evaluation index for each candidate similarity parameter; A candidate similarity parameter is selected that makes the comprehensive evaluation index reach its maximum value, and this candidate similarity parameter is used as the similarity threshold used to balance recall and precision.

[0042] In the offline generation process of the similarity threshold used for adjudication, a batch of packed sample files with pre-marked actual unpacking locations are used to iterate through and test multiple alternative similarity threshold values. The number of successfully retrieved entry points and the number of incorrectly identified entry points for each alternative value are recorded and counted, and then the precision (P) and recall (R) are calculated respectively. Subsequently, the system calculates the harmonic mean using the following formula: Where P (precision) = number of correctly identified OEPs / total number of OEPs, R (recall) = number of correctly identified OEPs / total number of true OEPs; TP = true positives, FP = false positives, FN = false negatives; F1 ∈ [0,1], the larger the better. The performance results of these two dimensions are transformed into a single comprehensive evaluation score. Finally, the parameter that maximizes the evaluation score is locked as the judgment threshold for formal deployment. This provides an adaptive parameter tuning mechanism for the shell removal recognition system, avoiding the limitations of manually setting thresholds based on experience. The optimization process guided by the harmonic mean forces the system to find the optimal point between not missing true entry points and not falsely reporting entry points. This ensures that the matching model deployed in actual combat can maintain a balanced detection quality when facing complex shells, guaranteeing the engineering practical value of the solution.

[0043] Another embodiment also includes an OEP positioning and automatic unpacking point identification device in anti-virus unpacking scenarios, configured to include: The simulation execution module is used to send the packed file into a controlled micro sandbox environment for simulated execution, and to monitor jump behavior in the execution flow of the simulated execution; The log generation module is configured to, in response to detecting a feature signal indicating the completion of unpacking through the jump behavior, obtain the jump target position that generated the feature signal; and collect an instruction sequence from the jump target position, and generate an execution log at the candidate original entry point based on the collected instruction sequence. The feature extraction module is used to extract the segment register access sequence, application programming interface call sequence, and abnormal instruction sequence for eliminating shell code interference from the execution log, and to form a structured feature set based on the segment register access sequence, the application programming interface call sequence, and the abnormal instruction sequence. A feature vectorization module is used to perform fuzzy hashing on the structured feature set to generate a compact hash string; and to map the compact hash string into a candidate feature vector in numerical format; The similarity calculation module is used to calculate the cosine similarity between the candidate feature vector and each fingerprint vector in the known compiler fingerprint vector library.

[0044] The basic underlying engineering parameters of the virus unpacking system are configured as follows: Sandbox dynamic simulation execution command limit window: 1000 commands.

[0045] Segment register monitoring set: Specifically designed to monitor data segments or additional segment registers with strong regular initialization patterns, specifically limited to the FS register and GS register.

[0046] Initialize the Application Programming Interface (API) standard identification list: including GetVersion, HeapCreate, GetCommandLineA, and GetEnvironmentStringsA.

[0047] Exception instructions and rejection set characteristics: include breakpoint instruction INT 3 (opcode 0xCC) and memory self-modification / write behavior.

[0048] Feature space dimension: 5-dimensional numerical vector. Similarity threshold T used to determine the original entry point: 0.85.

[0049] This embodiment simulates the complete derivation process of unpacking and locating the original entry point (OEP) of an executable file encrypted with an unknown variant shell.

[0050] The packed file was input into a controlled micro sandbox environment for simulated execution, and its jump behavior in the execution flow was monitored in real time. When the program dynamically executed to memory address 0x004015A0, the control flow monitoring module detected an unconditional large offset jump instruction JMP 0x00412000, and this jump was accompanied by a switch of the memory page attribute from "writable" to "executable". The system captured this characteristic signal and determined the jump target location 0x00412000 as a candidate original entry point.

[0051] Starting from the target jump location 0x00412000, the sandbox continues to track and record the subsequent 1000 instruction trajectories, generating execution logs at candidate original entry points.

[0052] Next, the feature extraction module performs multi-dimensional feature extraction on the execution log. The specific data tracking records are as follows: segment register access sequence features. Within 1000 instructions, two accesses to the FS register and zero accesses to the GS register were recorded. These access locations and sequences were converted into a structured trajectory descriptor, denoted as feature components. .

[0053] Application Programming Interface Call Sequence Characteristics In the instruction stream, calls to GetVersion, HeapCreate, and GetCommandLineA were detected sequentially. These calls were converted into sequence descriptors and denoted as feature components. .

[0054] Rejection set features Within the log coverage area, no breakpoint instruction with opcode 0xCC was detected, nor was any self-modifying memory write behavior found. The exception was marked as cleared and converted to a descriptor as a characteristic component. .

[0055] The feature extraction module concatenates the above feature components to form a structured feature set. .

[0056] Subsequently, the feature vectorization module performs fuzzy hashing on the structured feature set F to generate a compact hash string, and maps it to candidate feature vectors in 5-dimensional numerical format. .

[0057] The calculated value of the candidate feature vector is as follows: At this point, the system searches a known compiler fingerprint vector library. This library stores baseline fingerprint vectors for the target standard compiler. Its value is: The similarity calculation module calculates the similarity based on the candidate feature vectors. With fingerprint vector The cosine value of the angle between the two can be calculated using the cosine similarity formula described above: First, calculate the inner product (numerator) of the two vectors: Secondly, calculate the candidate feature vectors respectively. and fingerprint vector The square root of the modulus (denominator): Substituting the results of the inner product and modulus calculations into the formula, the final cosine similarity is obtained: Substituting the results of the inner product and modulus calculations into the formula, the final cosine similarity is obtained: The unpacking point determination module compares the calculated cosine similarity value of 0.9961 with a preset similarity threshold. Compare them.

[0058] because The judgment conditions are met. The system makes a final determination: the current jump target location 0x00412000 is the true original entry point (OEP) of the packed file, and the identification is successful, and the program body is unpacked and restored.

[0059] The electronic device provided in this embodiment of the invention, exemplarily, can be a network device, or a chip (system) or other component or assembly that can be disposed in a network device. The electronic device may include a processor. Optionally, the electronic device may also include a memory and / or a transceiver. The processor is coupled to the memory and transceiver, for example, by means of a communication bus connection.

[0060] In the several embodiments provided in this invention, it should be understood that the disclosed systems and methods can also be implemented in other ways. The system and method embodiments described above are merely illustrative. For example, the flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present invention. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than those marked in the drawings. For example, two consecutive blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in a block diagram and / or flowchart, and combinations of blocks in block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or action, or using a combination of dedicated hardware and computer instructions.

[0061] In addition, the functional modules in the various embodiments of the present invention can be integrated together to form an independent part, or each module can exist independently, or two or more modules can be integrated to form an independent part.

[0062] If the aforementioned functions are implemented as software functional modules and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, an electronic device, or a network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention.

[0063] It will be apparent to those skilled in the art that the present invention is not limited to the details of the exemplary embodiments described above, and that the invention can be implemented in other specific forms without departing from its spirit or essential characteristics. Therefore, the embodiments should be considered in all respects as exemplary and non-limiting, and the scope of the invention is defined by the appended claims rather than the foregoing description. Thus, all variations falling within the meaning and scope of equivalents of the claims are intended to be included within the present invention. No reference numerals in the claims should be construed as limiting the scope of the claims.

Claims

1. A method for OEP location and automatic identification of unpacking point in antivirus unpacking scenarios, characterized in that, include: The packed file is sent into a controlled micro sandbox environment for simulated execution, and jump behavior is monitored in the execution flow of the simulated execution. In response to detecting a feature signal indicating the completion of unpacking through the jump behavior, the jump target position that generated the feature signal is obtained; Starting from the jump target position, an instruction sequence is collected, and an execution log at the candidate original entry point is generated based on the collected instruction sequence; Extract the segment register access sequence, application programming interface call sequence, and abnormal instruction sequence used to exclude shell code interference from the execution log, and concatenate the segment register access sequence, application programming interface call sequence, and abnormal instruction sequence to form a structured feature set; Perform a fuzzy hash operation on the structured feature set to generate a compact hash string; Map the compact hash string to a candidate feature vector in numerical format; Calculate the cosine similarity between the candidate feature vector and each fingerprint vector in the known compiler fingerprint vector library; In response to the cosine similarity being greater than or equal to a similarity threshold used to balance recall and precision, the current jump target location is determined to be the true original entry point; The step of extracting the abnormal instruction sequence from the execution log to exclude interference from shell code includes: Identify breakpoint instructions in the execution log that meet the quantity limit, and use the breakpoint instructions as the abnormal instruction sequence; Alternatively, identify instructions in the execution log that contain self-modifying write behavior, and designate the instructions containing self-modifying write behavior as the abnormal instruction sequence.

2. The method for OEP location and automatic identification of unpacking point in anti-virus unpacking scenarios according to claim 1, characterized in that, The detection of a characteristic signal indicating the completion of uncoating through the jump behavior includes at least one of the following: A code page attribute switching behavior was detected in the execution flow; An unconditional jump behavior that satisfies the offset constraint was detected in the execution flow; Execution behavior is performed after a memory write is detected in the execution flow.

3. The method for OEP location and automatic identification of unpacking point in anti-virus unpacking scenarios according to claim 1, characterized in that, The segment register access sequence includes the access location and order of the data segment register or the additional segment register; The application programming interface call sequence includes the order and relative offset of the initialization functions being called.

4. The method for OEP location and automatic identification of unpacking point in anti-virus unpacking scenarios according to claim 1, characterized in that, The calculation of the cosine similarity between the candidate feature vector and each fingerprint vector in the known compiler fingerprint vector library includes: Extract each component of the first dimension of the candidate feature vector, and extract each component of the second dimension of each fingerprint vector; Based on each component of the first dimension and each component of the second dimension, calculate the cosine value of the angle between the candidate feature vector and each fingerprint vector. The cosine value is used as the cosine similarity.

5. The method for OEP location and automatic identification of unpacking point in anti-virus unpacking scenarios according to claim 1, characterized in that, The similarity threshold used to balance recall and precision is determined in the following way: Simulated recognition operations were performed on a dataset containing labeled and shielded samples by applying different candidate similarity parameters. The precision and recall of the recognition results were statistically analyzed for each candidate similarity parameter. The harmonic mean is calculated based on the precision and recall to obtain a comprehensive evaluation index for each candidate similarity parameter; A candidate similarity parameter is selected that makes the comprehensive evaluation index reach its maximum value, and this candidate similarity parameter is used as the similarity threshold used to balance recall and precision.

6. A device for OEP positioning and automatic identification of unpacking points in anti-virus unpacking scenarios, characterized in that, Configured to include: The simulation execution module is used to send the packed file into a controlled micro sandbox environment for simulated execution, and to monitor jump behavior in the execution flow of the simulated execution; The log generation module is configured to, in response to detecting a feature signal indicating the completion of unpacking through the jump behavior, obtain the jump target position that generated the feature signal; and collect an instruction sequence from the jump target position, and generate an execution log at the candidate original entry point based on the collected instruction sequence. The feature extraction module is used to extract segment register access sequences, application programming interface call sequences, and abnormal instruction sequences for excluding shell code interference from the execution log, and to form a structured feature set based on the segment register access sequences, application programming interface call sequences, and abnormal instruction sequences; the extraction of abnormal instruction sequences for excluding shell code interference from the execution log includes: identifying breakpoint instructions in the execution log that meet a quantity limit condition, and using the breakpoint instructions as the abnormal instruction sequence; or, identifying instructions in the execution log that contain self-modifying write behavior, and using the instructions containing self-modifying write behavior as the abnormal instruction sequence; A feature vectorization module is used to perform fuzzy hashing on the structured feature set to generate a compact hash string; and to map the compact hash string into a candidate feature vector in numerical format; The similarity calculation module is used to calculate the cosine similarity between the candidate feature vector and each fingerprint vector in the known compiler fingerprint vector library; The unpacking point determination module is used to determine the current jump target position as the true original entry point in response to the cosine similarity being greater than or equal to the similarity threshold used to balance recall and precision.

7. A computer device, characterized in that, It includes a processor and a memory, wherein the memory stores a computer program, which, when executed by the processor, implements the steps of the method as described in any one of claims 1 to 5.

8. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed by a processor, implements the steps of the method as described in any one of claims 1 to 5.