Extending an application with security code using intermediate level obfuscation technique

Dmitriy Dunaev, László Lengyel · 2013

Software piracy in general is the illegal copying, distribution, or use of software. The problem of mislicensing, unauthorized reproduction, or misuse of software has to be solved to successfully counteract software piracy. Such copy-protection and misuse-protection mechanism as a dongle is often used with expensive packages and vertical market software. Dongles mostly appear as two-interface security tokens with transient data flow that does not interfere with other dongle functions and a pull communication that reads security data from the dongle. Without the dongle, the software may run only in a restricted mode, or not at all. The potential weakness of dongles lies in the implementation of communication between a dongle and a copycontrolled software, e.g. if a dongle-check code is localized and a protection algorithm is revealed, the reverse engineer can modify the application to bypass the dongle check. The presented paper offers a solution to the problem of localizing a donglecheck code by offering a technique of adding a security code to an already existing application. The focus is set on intermediate level obfuscation that is used to protect software from reverse engineering and analysis.

Read the paper · More papers on PaperTik