Electronic device providing a security solution using dynamic binding technique and the controlling method thereof

KR103024978B1Active Publication Date: 2026-09-29AHNLAB INC
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
KR1020240095273
Authority / Receiving Office
KR · KR
Patent Type
Patents
Current Assignee / Owner
Filing Date
2024-07-18
Publication Date
2026-09-29
Estimated Expiration
2044-07-18

Smart Images

  • Figure 112024078363265-PAT00004_ABST
    Figure 112024078363265-PAT00004_ABST
Patent Text Reader

Abstract

An electronic device is disclosed that provides a security solution using a dynamic binding technique. The electronic device according to the present disclosure includes a memory that stores at least one instruction and one or more processors connected to the memory that execute at least one instruction. When the execution of a program is requested, the processor searches for and obtains an encrypted security logic that matches the program, decrypts the obtained security logic to obtain an original security logic, applies a dynamic binding technique to the obtained original security logic to identify a modified execution function name corresponding to the original execution function name, and can execute the program based on the modified execution function name.
Need to check novelty before this filing date? Find Prior Art

Description

Technology Field

[0001] The present disclosure relates to a security solution using dynamic binding techniques, and more specifically, to a technology that enhances the level of security by applying Automated Moving Target Defense (AMTD) whenever a program is executed and changing the name of the execution function. Background Technology

[0002] Due to limitations in the binary structure of Java-based executable programs including APKs (Android Application Packages), the execution flow and the names of the executed functions (methods) can be identified very simply through static analysis.

[0003] An attacker can reveal attack vectors through dynamic analysis following static analysis, and through static analysis, the attacker can identify the function that is the attack point, hook the attack point, or insert a breakpoint.

[0004] Automated Moving Target Defense (AMTD) is a security strategy that utilizes a technology to continuously change a system's attack surface, making it difficult for attackers to detect and exploit vulnerabilities. It is typically used to address the problem that fixed system configurations can be more easily analyzed and attacked by attackers.

[0005] A dex file is a file created by converting a .class file into bytecode so that the Android virtual machine can recognize it. A dex file is divided into a header and sections and contains executable program code.

[0006] A common method used to enhance the security of Dex files, which allow for easy identification of code execution flow or functions through static analysis, is to pack the Dex file. Packing a Dex file consists of obfuscation and encryption, and can be described as a structure where the encrypted code is decrypted and loaded during the subsequent execution process. Specifically, obfuscation involves generating multiple dummy codes and dummy keys to make it difficult to identify which code is being decrypted and used. The problem to be solved

[0007] The execution function portion of a running program can become a vulnerability for attackers, and there is a problem in that security can weaken over time if the logic or patterns of the execution function are exposed to attackers.

[0008] Therefore, to block the attack vector, it is necessary to neutralize the logic used during the initial attack by changing the name of the function executed every time.

[0009] If function names are generated anew every time, the function used as an attack point during the initial attack will have its name changed for subsequent attacks, requiring the attacker to identify the function name again at runtime to execute the same attack logic. This process significantly increases the complexity of analysis tools, which can provide both static and dynamic defenses simultaneously.

[0010] The purposes of the present disclosure are not limited to those mentioned above, and other purposes and advantages of the present disclosure not mentioned may be understood from the following description and will be more clearly understood from the embodiments of the present disclosure. Furthermore, it will be readily apparent that the purposes and advantages of the present disclosure can be realized by the means and combinations thereof set forth in the claims. means of solving the problem

[0011] An electronic device providing a security solution using a dynamic binding technique according to the present embodiment includes: a memory storing at least one instruction; and one or more processors connected to the memory and executing the at least one instruction. When the execution of a program is requested, the processor searches for and obtains an encrypted security logic that matches the program, decrypts the obtained security logic to obtain an original security logic, applies a dynamic binding technique to the obtained original security logic to identify a modified execution function name corresponding to the original execution function name, and executes the program based on the modified execution function name.

[0012] The above processor can encrypt security logic to obtain encrypted security logic and insert the obtained encrypted security logic into the program to be executed.

[0013] The above processor can identify a modified execution function name corresponding to the original execution function name by applying the Automated Moving Target Defense (AMTD) technique to the acquired original security logic.

[0014] The processor can identify a string table corresponding to the original execution function name included in the dex file, identify first data which is an item to be modified and included in the string table, generate second data by randomly modifying the string corresponding to the first data, and update the dex file based on the generated second data.

[0015] The string table above includes a plurality of items sorted in alphabetical order and a string corresponding to each of the plurality of items, and the processor can add data corresponding to a new string to the string table to recalculate the entire index and offset, and update the dex file based on the result of recalculating the entire index and offset.

[0016] The above string table includes a plurality of items sorted in alphabetical order and a string corresponding to each of the plurality of items, and the processor can generate second data corresponding to the name of the modified execution function by randomly modifying a part of the string corresponding to the first data so that the sorting order within the string table of the first data does not change.

[0017] The processor can identify whether the updated dex file contains an error, and if the updated dex file does not contain an error, load the updated dex file and execute the program based on the execution function name included in the updated dex file.

[0018] The processor can recalculate a checksum to identify whether the updated dex file contains an error, and identify whether the updated dex file contains an error based on the result of recalculating the checksum.

[0019] If the updated dex file does not contain errors, the processor can load the updated dex file using a dex class loader and delete the updated dex file.

[0020] A control method for an electronic device providing a security solution using a dynamic binding technique according to one embodiment of the present disclosure may include: a step of searching for and obtaining an encrypted security logic that matches the program when the execution of the program is requested; a step of decrypting the obtained security logic to obtain an original security logic; a step of applying a dynamic binding technique to the obtained original security logic to identify a modified execution function name corresponding to the original execution function name; and a step of executing the program based on the modified execution function name.

[0021] A non-transient computer-readable recording medium according to one embodiment of the present disclosure may store at least one instruction that is executed by a processor of an electronic device to perform a control method of said electronic device. Effects of the invention

[0022] One method to block attack vectors by applying the AMTD technique is to change the name of the function that is executed every time, which allows the logic used by the attacker during the initial attack to be neutralized.

[0023] If function names are generated anew every time, the function used as an attack point during the initial attack will have its name changed for subsequent attacks, requiring the attacker to identify the function name again at runtime to execute the same attack logic. This process significantly increases the complexity of analysis tools, which can provide both static and dynamic defenses simultaneously. Brief explanation of the drawing

[0024] Aspects, features, and advantages of specific embodiments of the present disclosure will become more apparent from the following description with reference to the accompanying drawings. FIG. 1 is a block diagram illustrating the configuration of an electronic device according to one embodiment of the present disclosure. FIG. 2 is a flowchart for explaining the operation of an electronic device according to one embodiment of the present disclosure. FIG. 3 is a block diagram illustrating each module included in a processor according to one embodiment of the present disclosure. FIG. 4 is a block diagram illustrating a preprocessing process according to one embodiment of the present disclosure. FIG. 5 is a block diagram illustrating the process of executing a program by obtaining a modified execution function name by applying AMTD when executing a program, according to one embodiment of the present disclosure. FIG. 6 is a block diagram illustrating the process of changing a string table according to one embodiment of the present disclosure. Specific details for implementing the invention

[0025] The embodiments described herein are subject to various modifications and may have various forms; therefore, specific embodiments are illustrated in the drawings and described in detail. However, this is not intended to limit the scope of specific embodiments and should be understood to include various modifications, equivalents, and / or alternatives to the embodiments of the present disclosure. In relation to the description of the drawings, similar reference numerals may be used for similar components.

[0026] In describing the present disclosure, if it is determined that a detailed description of related known functions or configurations could unnecessarily obscure the essence of the present disclosure, such detailed description is omitted.

[0027] Additionally, the following embodiments may be modified in various other forms, and the scope of the technical concept of the present disclosure is not limited to the following embodiments. Rather, these embodiments are provided to make the present disclosure more faithful and complete and to fully convey the technical concept of the present disclosure to those skilled in the art.

[0028] The terms used in this disclosure are used merely to describe specific embodiments and are not intended to limit the scope of the rights. The singular expression includes the plural expression unless the context clearly indicates otherwise.

[0029] In the present disclosure, expressions such as “have,” “may have,” “include,” or “may include” indicate the presence of such features (e.g., numerical values, functions, actions, or components such as parts) and do not exclude the presence of additional features.

[0030] In the present disclosure, expressions such as “A or B,” “at least one of A or / and B,” or “one or more of A or / and B” may include all possible combinations of items listed together. For example, “A or B,” “at least one of A and B,” or “at least one of A or B” may refer to cases including (1) at least one A, (2) at least one B, or (3) both at least one A and at least one B.

[0031] Expressions such as "first," "second," "first," or "second" used in this disclosure may modify various components regardless of order and / or importance, and are used only to distinguish one component from another and do not limit said components.

[0032] Where it is stated that a component (e.g., Component 1) is "(operatively or communicatively) coupled with / to" or "connected to" another component (e.g., Component 2), it should be understood that the component may be directly connected to the other component or connected through the other component (e.g., Component 3).

[0033] On the other hand, when it is stated that a certain component (e.g., a first component) is "directly connected" or "directly coupled" to another component (e.g., a second component), it may be understood that no other component (e.g., a third component) exists between the certain component and the other component.

[0034] As used in this disclosure, the expression “configured to” may be replaced, depending on the context, with, for example, “suitable for,” “having the capacity to,” “designed to,” “adapted to,” “made to,” or “capable of.” The term “configured to” may not necessarily mean only “specifically designed to” in hardware.

[0035] Instead, in some situations, the expression “device configured to do something” may mean that the device is “capable of doing something” together with other devices or components. For example, the phrase “processor configured (or set) to perform A, B, and C” may mean a dedicated processor for performing those operations (e.g., an embedded processor), or a generic-purpose processor (e.g., a CPU or application processor) capable of performing those operations by executing one or more software programs stored in a memory device.

[0036] In the embodiments, a 'module' or 'part' performs at least one function or operation and may be implemented in hardware or software, or a combination of hardware and software. Additionally, a plurality of 'modules' or a plurality of 'parts' may be integrated into at least one module and implemented by at least one processor, except for the 'module' or 'part' that needs to be implemented in specific hardware.

[0037] Meanwhile, the various elements and areas in the drawings are depicted schematically. Accordingly, the technical concept of the present invention is not limited by the relative sizes or spacing depicted in the attached drawings.

[0038] Hereinafter, embodiments according to the present disclosure are described in detail with reference to the attached drawings so that those skilled in the art can easily implement them.

[0039] The electronic device (100) may be capable of executing programs, code, applications, application software, etc., and performing computational operations on data, information, signals, etc.

[0040] The electronic device (100) may include, for example, at least one of a computing device, a computing device, a desktop PC, a smartphone, a tablet PC, a laptop PC, a netbook computer, a mobile device, and a wearable device, but is not limited thereto.

[0041] The electronic device (100) may be, for example, a server which is a computer that provides services to clients over a network. The server may be an FTP server, a web server, a database server, or a cloud server, and the server may be built with an operating system such as Linux.

[0042] A server can include different functions and is not necessarily a single device; it can be distributed across multiple devices, and each function can be implemented.

[0043] An electronic device (100) according to one embodiment of the present disclosure is not limited to the above-described device, and the electronic device (100) may be implemented as an electronic device (100) having two or more functions of the above-described devices.

[0044] FIG. 1 is a block diagram illustrating the configuration of an electronic device (100) according to one embodiment of the present disclosure.

[0045] Referring to FIG. 1, it may include a memory (110) and a processor (120), but is not limited thereto, and may further include other configurations, such as a communication interface that performs a communication connection with an external device to transmit and receive information, data, etc., a user interface that receives user commands, a display that outputs a calculation process, data, information, etc. as visual information to the user, or may omit some configurations.

[0046] The memory (110) stores various programs or data temporarily or non-temporarily and transmits the stored information to the processor (120) upon the call of the processor (120). Additionally, the memory (110) can store various information required for the operation, processing, or control operation of the processor (120) in an electronic format.

[0047] The memory (110) may include, for example, at least one of a main memory and an auxiliary memory. The main memory may be implemented using a semiconductor storage medium such as ROM and / or RAM. The ROM may include, for example, a conventional ROM, EPROM, EEPROM and / or MASK-ROM. The RAM may include, for example, a DRAM and / or SRAM. The auxiliary memory may be implemented using at least one storage medium capable of storing data permanently or semi-permanently, such as a flash memory device, an SD (Secure Digital) card, a solid state drive (SSD), a hard disk drive (HDD), an optical recording medium such as a magnetic drum, a compact disc (CD), a DVD, or a laser disc, a magnetic tape, a magneto-optical disc and / or a floppy disk.

[0048] The memory (110) can store instructions for various modules required to provide a security solution using a dynamic binding technique.

[0049] The memory (110) can store security logic (21) (or security code) that is to be hidden, and can store encryption keys, decryption keys, symmetric keys, etc. that encrypt the security logic (21).

[0050] The memory (110) can store AMTD execution logic (22), specifically, decoding logic (22-1), AMTD application logic (22-2), and dynamic loading and execution logic (22-3). Additionally, the memory (110) can store obfuscation information for obfuscating the AMTD execution logic (22).

[0051] Memory (110) can store a program (APK) to be executed, a dex file corresponding to the program to be executed, and various execution functions included in the dex file. In addition, memory (110) can store a string table (40) (Sting table).

[0052] In addition, memory (110) can store information about the dex class loader used to load the dex file.

[0053] The processor (120) controls the overall operation of the electronic device (100). Specifically, the processor (120) is connected to the configuration of the electronic device (100) including the memory (110) as described above, and can control the overall operation of the electronic device (100) by executing at least one instruction stored in the memory (110) as described above. In particular, the processor (120) can be implemented as a single processor as well as as a plurality of processors.

[0054] The processor (120) may be implemented in various ways. For example, one or more processors (120) may include one or more of a CPU (Central Processing Unit), GPU (Graphics Processing Unit), APU (Accelerated Processing Unit), MIC (Many Integrated Core), DSP (Digital Signal Processor), NPU (Neural Processing Unit), hardware accelerator, or machine learning accelerator. One or more processors (120) may control one or any combination of other components of the electronic device (100) and may perform operations or data processing related to communication. One or more processors (120) may execute one or more programs or instructions stored in memory (110). For example, one or more processors (120) may perform a method according to one embodiment of the present disclosure by executing one or more instructions stored in memory (110).

[0055] In the case where the method according to one embodiment of the present disclosure includes a plurality of operations, the plurality of operations may be performed by one processor (120) or by a plurality of processors (120). For example, when a first operation, a second operation, and a third operation are performed by the method according to one embodiment, the first operation, the second operation, and the third operation may all be performed by a first processor, or the first operation and the second operation may be performed by a first processor (e.g., a general-purpose processor) and the third operation may be performed by a second processor (e.g., an artificial intelligence dedicated processor).

[0056] One or more processors (120) may be implemented as a single-core processor including one core, or as one or more multicore processors including multiple cores (e.g., homogeneous multicore or heterogeneous multicore). When one or more processors (120) are implemented as multicore processors, each of the multiple cores included in the multicore processor may include internal processor memory such as on-chip memory (110), and a common cache shared by the multiple cores may be included in the multicore processor (120). Additionally, each of the multiple cores included in the multicore processor (120) (or some of the multiple cores) may independently read and execute program instructions for implementing a method according to one embodiment of the present disclosure, or all (or some) of the multiple cores may be linked together to read and execute program instructions for implementing a method according to one embodiment of the present disclosure.

[0057] When a method according to one embodiment of the present disclosure includes a plurality of operations, the plurality of operations may be performed by one of the plurality of cores included in a multi-core processor, or may be performed by a plurality of cores. For example, when a first operation, a second operation, and a third operation are performed by a method according to one embodiment, the first operation, the second operation, and the third operation may all be performed by a first core included in a multi-core processor, or the first operation and the second operation may be performed by a first core included in a multi-core processor and the third operation may be performed by a second core included in a multi-core processor.

[0058] In embodiments of the present disclosure, the processor (120) may mean a system-on-chip (SoC) in which one or more processors (120) and other electronic components are integrated, a single-core processor, a multi-core processor, or a core included in a single-core processor or a multi-core processor, wherein the core may be implemented as a CPU, GPU, APU, MIC, DSP, NPU, hardware accelerator, or machine learning accelerator, but the embodiments of the present disclosure are not limited thereto.

[0059] The processor (120) can perform control operations of the electronic device (100) as follows by being connected to memory (110) and executing at least one instruction.

[0060] FIG. 2 is a flowchart for explaining the operation of an electronic device (100) according to one embodiment of the present disclosure.

[0061] Referring to FIG. 2, when the execution of a program is requested, the processor (120) can search for and obtain encrypted security logic (21) that matches the program (S210).

[0062] The processor (120) can decrypt the acquired security logic (21) to obtain the original security logic (21) (S220).

[0063] The processor (120) can identify a modified execution function name corresponding to the original execution function name by applying a dynamic binding technique to the acquired original security logic (21) (S230).

[0064] The processor (120) can execute a program based on a variant execution function name (S240).

[0065] The general control operation of the processor (120) described above can be implemented through detailed modules that may be included in the processor (120) as shown in FIG. 3.

[0066] FIG. 3 is a block diagram illustrating each module included in a processor (120) according to one embodiment of the present disclosure.

[0067] Referring to FIG. 3, the processor (120) may include a preprocessing module (121) and an AMTD module (122).

[0068] The preprocessing module (121) may include a security logic encryption module (121-1) and a security logic insertion module (121-2).

[0069] The processor (120) can control the security logic encryption module (121-1) to encrypt the security logic (21) (or security code) that is to be hidden.

[0070] The processor (120) can control the security logic insertion module (121-2) to insert encrypted security logic (21) into the execution program (30) (APK). Here, the insertion location is predefined and subsequently refers to the predefined location when loaded into the execution program (30) (APK).

[0071] In addition, when considering a general Java program, the executable program (30) may be named as a set of Java classes including a Jar, rather than targeting an APK.

[0072] The AMTD module (122) may include a security logic decryption module (122-1), an executable file modification module (122-2), a modified executable file execution module (122-3), and an AMTD execution logic insertion module (122-4).

[0073] The processor (120) can control the security logic decryption module (122-1) to decrypt the encrypted security logic (21) (or security code) inserted into the execution program (30).

[0074] The processor (120) can control the executable file modification module (122-2) to perform random number-based modification on the security logic (21) (or security code) included in the executable file, i.e., the executable program (30). Specifically, the processor (120) can control the executable file modification module (122-2) to obtain a modified executable function name by modifying the executable function name (method name) included in the dex file of the executable program (30).

[0075] The processor (120) can control the modified executable file execution module (122-3) to execute the modified executable program (30). The processor (120) can control the modified executable file execution module (122-3) to load the dex file included in the modified executable program (30) using a dex class loader.

[0076] However, if the program execution environment is a general Java program environment rather than an Android environment, the DeX class loader may be replaced with URLClassLoader. Additionally, if there is a separate class loader provided by the platform, that class loader may be used.

[0077] The processor (120) can control the AMTD execution logic insertion module (122-4) to insert the AMTD execution logic (22) into the executable program (30) (APK). In a standard Java program, it can be inserted into an executable file format other than an APK. In this case, one can expect an output with the same extension as the input (e.g., input a jar and output a jar).

[0078] The general control operation of the processor (120) and the control operation of the detailed modules and configurations of the processor (120) are as described above.

[0079] Below, the control operation of the processor (120) in more detail is explained together with FIGS. 3 to 6.

[0080] FIG. 4 is a block diagram illustrating a preprocessing process according to one embodiment of the present disclosure.

[0081] Referring to FIG. 4, the processor (120) can insert security logic (21) and AMTD execution logic (22) into the execution program (30) (APK) to which it is applied through a preprocessing process.

[0082] The executable program (30) may be an app, application, or application software that runs in an Android environment, but is not limited thereto, and may mean a computer language-based program that can run in various operating systems, environments, etc.

[0083] The processor (120) can encrypt the security logic (21) (or security code) to obtain the encrypted security logic (21) and insert the obtained encrypted security logic (21) (or security code) into the program to be executed. Here, the encryption method may be a symmetric key encryption method, but is not limited thereto.

[0084] Here, the security logic (21) may be a target for concealment or protection from external attacks. For example, as shown in FIG. 3, 'initialize' (21-1), 'startCheck' (21-2), etc. may be examples of the security logic (21).

[0085] When the encrypted security logic is located in the executable program (30) to which it is applied, file.txt is located in an arbitrary directory such as assets rather than in the code area, and since it does not have a dex extension, the logic may not be exposed in the decompiler.

[0086] When encrypted security logic (21) is inserted into the target execution program (30), the processor (120) can insert AMTD execution logic (22) into the execution program (30) to decrypt and execute the encrypted security logic (21).

[0087] Automated Moving Target Defense (AMTD) is a security strategy that utilizes a technology to continuously change a system's attack surface, making it difficult for attackers to detect and exploit vulnerabilities. It is typically used to address the problem that fixed system configurations can be more easily analyzed and attacked by attackers.

[0088] This corresponds to the AMTD execution logic (22) as illustrated in FIG. 2 and may consist of a set of class files for performing decoding, AMTD application, dynamic loading, and execution. The processor (120) may obfuscate the AMTD execution logic (22) and insert it into the target execution program (30).

[0089] The processor (120) can place obfuscated AMTD execution logic (22) so that it starts first during execution in the lifecycle of the execution program (30).

[0090] Once the above-described preprocessing process is completed, when the program is executed, a modified execution function name can be obtained using the AMTD technique as shown in Figures 5 and 6 below, thereby maintaining a high level of security against external attackers.

[0091] FIG. 5 is a block diagram illustrating the process of executing a program by obtaining a modified execution function name by applying AMTD when executing a program, according to one embodiment of the present disclosure.

[0092] Referring to FIG. 5, when the execution of a program is requested, the processor (120) can search for and obtain encrypted security logic (21) that matches the program.

[0093] The processor (120) can decrypt the acquired security logic (21) to obtain the original security logic (21). Here, the security logic (21) may be in a state where dynamic loading is impossible because it is loaded only into memory (110) in the form of file data.

[0094] The processor (120) can identify a modified execution function name corresponding to the original execution function name by applying a dynamic binding technique to the acquired original security logic (21).

[0095] More specifically, the processor (120) can identify a modified execution function name corresponding to the original execution function name by applying the AMTD technique to the acquired original security logic (21).

[0096] FIG. 6 is a block diagram illustrating the process of changing a string table (40) according to one embodiment of the present disclosure.

[0097] Referring to FIG. 6, the processor (120) can identify a string table (40) (String Table) corresponding to the original execution function name included in the dex file.

[0098] A DeX file is a file that converts a .class file into bytecode so that it can be recognized by an Android virtual machine. The DeX file is divided into a header and sections and contains program code to be executed. The processor (120) can identify the logic, code, strings, data, etc. contained in the DeX file to identify the execution function of the program to be executed.

[0099] When considering a general Java program, there is no need to consider the dex format here, and instead the processor (120) can directly access the class file and change its name.

[0100] The DeX file format is used only in the Android environment, and since the string table (40) is used at this time, the string table (40) is not used in Java programs that are not in the general Android environment.

[0101] The processor (120) can identify first data (50-1, 50-2), which is included in the string table (40) and is an item to be modified. Here, the first data (50-1, 50-2) may be data corresponding to the security logic (21) to be hidden.

[0102] The processor (120) can generate second data (51-1, 51-2) by randomly modifying a string corresponding to the first data (50-1, 50-2), and can update the dex file based on the generated second data (51-1, 51-2).

[0103] Here, the processor acquires a plurality of second data (51-1, 51-2) and can identify one of the second data (51-1, 51-2) as a modified execution function name.

[0104] And, the string table (40) may include a plurality of items arranged in alphabetical order and a string corresponding to each of the plurality of items.

[0105] The processor (120) can recalculate the entire index and offset by adding data corresponding to the new string to the string table (40), and update the dex file based on the result of recalculating the entire index and offset.

[0106] The processor (120) can generate second data (51-1, 51-2) by randomly modifying a part of the string corresponding to the first data (50-1, 50-2) so that the sorting order within the string table (40) of the first data (50-1, 50-2) does not change.

[0107] The processor (120) can identify the modified execution function name corresponding to the updated dex file and the generated second data (51-1, 51-2) as described above, and execute the program.

[0108] According to various embodiments, since there is no string table (40) that separately stores execution function names (method names) on platforms other than Android, the process of the processor (120) modifying, changing, or transforming execution function names (method names) in a general Java program can be implemented by accessing each class file, finding the string containing the target execution function name (method name), and performing a find & replace process. In this way, the processor (120) can change all strings containing the corresponding execution function name (method name), just as the string table (40) was modified, changed, or transformed in Android.

[0109] The processor (120) identifies whether the updated dex file contains errors, and if the updated dex file does not contain errors, it can load the updated dex file.

[0110] Specifically, the processor (120) can recalculate a checksum to identify whether the updated dex file contains errors, and can identify whether the updated dex file contains errors based on the result of the checksum recalculation. The checksum can be calculated as an adler32 value for the dex file data.

[0111] If the updated dex file does not contain errors, the processor (120) can load the updated dex file using a dex class loader and delete the updated dex file.

[0112] The processor (120) can execute a program based on the execution function name included in the updated dex file.

[0113] As described above, by applying the AMTD technique to block attack vectors for programs running in an Android environment, the name of the function executed each time is changed, thereby neutralizing the logic used by the attacker during the initial attack.

[0114] If function names are generated anew every time, the function used as an attack point during the initial attack will have its name changed for subsequent attacks, requiring the attacker to identify the function name again at runtime to execute the same attack logic. This process significantly increases the complexity of analysis tools, which can provide both static and dynamic defenses simultaneously.

[0115] According to one embodiment, the method according to the various embodiments disclosed herein may be provided by being included in a computer program product. The computer program product may be traded between a seller and a buyer as a product. The computer program product may be distributed in the form of a device-readable storage medium (e.g., compact disc read-only memory (CD-ROM)), or distributed online (e.g., download or upload) through an application store (e.g., Play Store™) or directly between two user devices (e.g., smartphones). In the case of online distribution, at least a portion of the computer program product (e.g., downloadable app) may be temporarily stored or temporarily created on a device-readable storage medium, such as the memory of a manufacturer's server, an application store's server, or a relay server.

[0116] Although preferred embodiments of the present disclosure have been illustrated and described above, the present disclosure is not limited to the specific embodiments described above. It is understood that various modifications can be made by those skilled in the art without departing from the essence of the present disclosure as claimed in the claims, and such modifications should not be understood individually from the technical spirit or perspective of the present disclosure. Explanation of the symbols

[0117] 100: Electronic device 110: Memory 120: Processor 121: Preprocessing Module 122: AMTD Module

Claims

Claim 1 An electronic device providing a security solution using a dynamic binding technique comprises: a memory storing at least one instruction; and one or more processors connected to the memory and executing the at least one instruction; wherein, when the execution of a program is requested, the processor searches for and obtains an encrypted security logic that matches the program, decrypts the obtained security logic to obtain an original security logic, applies a dynamic binding technique to the obtained original security logic to identify a modified execution function name corresponding to the original execution function name, executes the program based on the modified execution function name, identifies a string table corresponding to the original execution function name included in the program's execution file, identifies first data which is an item subject to modification included in the string table, generates second data by randomly modifying a string corresponding to the first data, and updates the program's execution file based on the generated second data. Claim 2 An electronic device according to claim 1, wherein the processor encrypts security logic to obtain encrypted security logic and inserts the obtained encrypted security logic into the program to be executed. Claim 3 In claim 1, the processor is an electronic device that identifies a modified execution function name corresponding to the original execution function name by applying the AMTD (Automated Moving Target Defense) technique to the acquired original security logic. Claim 4 An electronic device according to claim 1, characterized in that the executable file of the program is a dex file. Claim 5 An electronic device according to claim 4, wherein the string table comprises a plurality of items sorted in alphabetical order and a string corresponding to each of the plurality of items, and the processor adds data corresponding to a new string to the string table to recalculate the entire index and offset, and updates the dex file based on the result of recalculating the entire index and offset. Claim 6 An electronic device according to claim 4, wherein the processor, the string table comprises a plurality of items sorted in alphabetical order and a string corresponding to each of the plurality of items, and the processor generates second data corresponding to the name of the modified execution function by randomly modifying a part of the string corresponding to the first data so as not to change the sorting order within the string table of the first data. Claim 7 An electronic device according to claim 4, wherein the processor identifies whether the updated dex file contains an error, and if the updated dex file does not contain an error, loads the updated dex file and executes the program based on the name of the execution function included in the updated dex file. Claim 8 An electronic device according to claim 7, wherein the processor recalculates a checksum to identify whether the updated dex file contains an error, and identifies whether the updated dex file contains an error based on the result of the recalculation of the checksum. Claim 9 An electronic device according to claim 7, wherein the processor loads the updated dex file using a Dex Class Loader and deletes the updated dex file if the updated dex file does not contain errors. Claim 10 A control method for an electronic device providing a security solution using a dynamic binding technique, comprising: a step of, when execution of a program is requested, searching for and obtaining an encrypted security logic that matches the program; a step of decrypting the obtained security logic to obtain an original security logic; a step of applying a dynamic binding technique to the obtained original security logic to identify a modified execution function name corresponding to the original execution function name; a step of executing the program based on the modified execution function name; a step of identifying a string table corresponding to the original execution function name included in the program's execution file; a step of identifying a first data that is included in the string table and is an item subject to modification; a step of generating a second data by randomly modifying a string corresponding to the first data; and a step of updating the program's execution file based on the generated second data. Claim 11 A non-transient computer-readable recording medium storing at least one instruction that is executed by a processor of an electronic device to cause the electronic device to perform the control method of claim 11.

Citation Information

Patent Citations

  • Method and apparatus for hiding information of application, and method and apparatus for executing application

    KR1020160137222A

  • Timely randomized memory protection

    US20170364452A1

  • Platform and Method for Automated Moving Target Defense

    US20230328047A1