
Sistema di protezione per macchine virtuali ARM64 ELF
Sistema di Protezione per Macchine Virtuali ARM64 ELF
Traduce le istruzioni native ARM64 in bytecode VM personalizzato per la protezione del codice a livello di funzione
🇨🇳 中文文档 • Caratteristiche • Architettura • Avvio Rapido • Utilizzo • Licenza
VMPacker è un sistema di Protezione tramite Macchina Virtuale (VM) per eseguibili ARM64 (AArch64) Linux ELF. Decodifica le istruzioni native ARM64 della funzione target in una rappresentazione intermedia, le traduce in bytecode VM personalizzato e inietta un interprete VM incorporato nel file ELF. In esecuzione, le funzioni protette vengono eseguite dall'interprete VM invece che nativamente.
ARM64 Native Code → Decode → Translate → Custom VM Bytecode
↓
Original ELF ← Inject ← VM Interpreter Stub
| Stratto | Tecnica | Descrizione |
|---|---|---|
| Protezione VM | ISA Personalizzata | Opcode mappati casualmente — i reverse engineer non possono identificare direttamente la semantica delle istruzioni |
| OpcodeCryptor | Crittografia opcode per istruzione | enc[pc] = op[pc] ^ (key ^ (pc * 0x9E3779B9)) |
| Inversione Bytecode | Inversione dell'ordine di esecuzione | Istruzioni memorizzate in ordine inverso; l'interprete scorre all'indietro |
| Ingresso Token | Trampolino a 3 istruzioni | Funzione originale sostituita con un ingresso tokenizzato, nascondendo la posizione effettiva del bytecode |
| Dispatch Indiretto | Tabella di salto tramite puntatore a funzione | Riempita a runtime sullo stack, rompendo i riferimenti incrociati di IDA |
![]() |
![]() |
![]() |
| Elenco Funzioni | Analisi e Selezione | Opzioni Protezione |
![]() |
![]() |
|
| Log in Tempo Reale | Protezione Completata |
vmp/
├── cmd/vmpacker/ # CLI entry point
│ ├── main.go # CLI argument parsing + orchestration
│ └── vm_interp.bin # Compiled VM interpreter (GCC, go:embed)
│
├── pkg/ # Go core library
│ ├── arch/arm64/ # ARM64 architecture support
│ │ ├── decoder.go # Table-driven instruction decoder (implements vm.Decoder)
│ │ ├── decode_*.go # Decode pattern tables (DP-IMM/DP-REG/Branch/LdSt)
│ │ ├── translator.go # ARM64 → VM bytecode translator
│ │ ├── tr_alu.go # ALU instruction translation
│ │ ├── tr_branch.go # Branch instruction translation
│ │ ├── tr_loadstore.go # Memory instruction translation
│ │ ├── tr_bitfield.go # Bitfield instruction translation
│ │ └── tr_special.go # Special instructions (ADRP/ADR)
│ ├── vm/ # VM ISA definitions
│ │ ├── types.go # Shared types + interfaces (Decoder/Translator/Packer)
│ │ ├── opcodes.go # 58+ VM opcode definitions (randomly mapped values)
│ │ └── disasm.go # VM bytecode disassembler
│ └── binary/elf/ # ELF binary manipulation
│ ├── packer.go # ELF VMP injection (PT_NOTE hijack, trampoline generation)
│ └── trampoline.go # Trampoline code generation
│
├── stub/ # C VM interpreter (compiled to PIC flat binary)
│ ├── vm_interp_clean.c # Interpreter main loop + entry points
│ ├── vm_types.h # VM CPU context (vm_ctx_t)
│ ├── vm_opcodes.h # C-side opcode definitions (synced with opcodes.go)
│ ├── vm_decode.h # Bytecode read utilities
│ ├── vm_token.h # Token encode/decode + descriptor table
│ ├── vm_dispatch.h # Indirect dispatch jump table
│ ├── vm_crc.h # CRC32 integrity check
│ ├── vm_sections.h # Handler section scattering macros
│ ├── vm_interp.lds # Linker script
│ └── vm_handlers/ # Modular instruction handlers
│ ├── h_alu.h # Arithmetic/logic operations
│ ├── h_mem.h # Memory access
│ ├── h_branch.h # Branch/jump
│ ├── h_cmp.h # Compare/conditional
│ ├── h_mov.h # Data movement
│ ├── h_stack.h # Stack (PUSH/POP)
│ └── h_system.h # System (SVC/MRS/BLR/BR/RET)
│
├── vmp-gui/ # Wails GUI frontend
│ ├── frontend/ # Vue 3 + Element Plus
│ └── backend/ # Go backend bindings
│
└── build/ # Pre-compiled tools + test artifacts
Il progetto utilizza un'architettura modulare guidata da interfacce, che facilita l'estensione a nuove ISA e formati binari:
// Architecture decoder interface — extensible to x86, RISC-V
type Decoder interface {
Decode(raw uint32, offset int) Instruction
InstName(op int) string
}
// Bytecode translator interface
type Translator interface {
Translate(instructions []Instruction) (*TranslateResult, error)
}