Method to Evaluate Software Protection Based on Attack Modeling

Huaijun Wang, Dingyi Fang, Ni Wang, Zhanyong Tang, Chen Feng, Yuanxiang Gu · 2013

Software protection technologies are used widely to avoid malicious activities on software. However, how to evaluate the effectiveness of them is still an unsolved problem. Until now, most evaluations are based on the analysis of the individual protection technique itself, and cannot directly prove and measure whether the security goal is achieved. This paper presents a new evaluation method considering attack cost as the metric to evaluate the effectiveness of software protection under the circumstances of fulfilling assumptions that all software can be attacked successfully. By analyzing relevant attacking information, through an entire software attack process, we deduce an approach to calculate attack cost with attack model SAMMPN (Software Attack Model based on Marked Petri Net). Moreover, we also present a case study to verify the feasibility and reasonableness. This work could help to improve the effectiveness evaluation of software protection, and contribute to the development of software protection research.

Read the paper · More papers on PaperTik