首页> 外国专利> PROCESS WRAPPING METHOD FOR EVADING ANTI-ANALYSIS OF NATIVE CODES, RECORDING MEDIUM AND DEVICE FOR PERFORMING THE METHOD

PROCESS WRAPPING METHOD FOR EVADING ANTI-ANALYSIS OF NATIVE CODES, RECORDING MEDIUM AND DEVICE FOR PERFORMING THE METHOD

机译:用于删除本机代码,记录介质和设备的抗分析的过程包装方法,用于执行方法

摘要

A process wrapping method for bypassing native code analysis prevention includes: receiving an execution command to be executed in an application from an Android framework when the application is started; extracting metadata about strings and methods from the compiled OAT file using the oatdump tool existing inside the Android framework; determining whether analysis prevention technology is applied by comparing the information of the DB based on the transmitted execution command and the extracted metadata; modifying the execution command based on the determined information when the analysis prevention technology is applied; and transmitting the modified execution command back to the Android framework. Accordingly, it is possible to provide an environment in which malicious applications to which analysis prevention technologies are applied can be easily analyzed.
机译:用于绕过本机代码分析预防的过程包装方法包括:在应用程序启动时从Android框架中接收要在应用程序中执行的执行命令;使用Android框架内存的oatdump工具从编译的oat文件中提取关于字符串和方法的元数据;确定是否通过基于发送的执行命令和提取的元数据进行比较DB的信息来应用分析防范技术;基于应用分析防范技术时,根据所确定的信息修改执行命令;并将修改后的执行命令发送回Android框架。因此,可以提供一种环境,其中可以容易地分析应用分析预防技术的恶意应用。

著录项

  • 公开/公告号KR102271273B1

    专利类型

  • 公开/公告日2021-06-29

    原文格式PDF

  • 申请/专利权人

    申请/专利号KR1020200161386

  • 发明设计人 이정현;신용구;

    申请日2020-11-26

  • 分类号G06F21/56;G06F8/74;

  • 国家 KR

  • 入库时间 2022-08-24 19:51:28

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号