SOFTWARE SECURITY THROUGH TARGETTED DIVERSIFICATION

Gert Merckx, Nessim Kisserli · 2006

In this thesis we will discuss the concept of diversification as a means of strengthening a software population. More specifically, we will study the impact the creation of a diverse software population has on the applicability of automated software attacks. Diversity is a relatively unexplored area in the field of computer security, but has great potential for the field of software security. Numerous automated attacks intrinsically assume total homogeneity within specific software distributions, this makes them very susceptible to diversification. This thesis will present a way to break this homogeneity by introducing diversity among application instances. In Chapter 1 we will introduce the ever-growing problem of digital piracy and we will provide the reader with some required background information and terminology. The concepts of copy protection, security code and software security will be clarified. Furthermore, we will offer the reader an overview of commonly used copy protection schemes. Chapter 2 introduces the reader to the world of cracking. We will discuss the four stages of the cracking process and analyze the characteristics and creation of automated attacks. The cracks will be classified and discussed in detail. We will study to what extent several distribution channels contribute to the harmfull effect of automated cracks. In Chapter 3 the state-of-the-art countermeasures against cracking will be briefly discussed. Chapter 4 evaluates the countermeasures discussed in Chapter 3 and introduces the concept of diversification. We will present a straightforward additional security layer based on diversity that thwarts automated attempts to modify the application. Based on this approach an extension is proposed that targets a larger fraction of today’s automated attacks. In Chapter 5 an implementation of the proposed scheme is discussed. It employs genetic programming techniques to create diversity among the software population. Subsequently, we attempt to anticipate the sophisticated future attacks required to circumvent our scheme, and present possible extensions for thwarting them.. Chapter 6 will summarize and evaluate the implemented scheme.

Read the paper · More papers on PaperTik