Large-Scale Automated Software Diversity—Program Evolution Redux
Andrei Homescu, Todd Jackson, Stephen J. Crane, Stefan Brunthaler, Per Larsen, Michael Franz · IEEE Transactions on Dependable and Secure Computing · 2015
The software monoculture favors attackers over defenders, since it makes all target environments appear similar. Code-reuse attacks, for example, rely on target hosts running identical software. Attackers use this assumption to their advantage by automating parts of creating an attack. This article presents large-scale automated software diversification as a means to shore up this vulnerability implied by our software monoculture. Besides describing an industrial-strength implementation of automated software diversity, we introduce methods to objectively measure the effectiveness of diversity in general, and its potential to eliminate code-reuse attacks in particular.