A Software MTD Technique of Multipath Execution Protection
Shaomang Huang, Jianfeng Pan · 2020
Attackers exploit vulnerabilities to attack target software relying on accurate mastery of its code implementation details and exact prediction of its runtime state transitions. Especially, when and where a sensitive pointer is allocated, what struct a sensitive object is and how to hijack the victim program's execution flow. Software randomization technique, based on the idea of moving target defense, introduces uncertainty into the target program and offers probabilistic protection similar to cryptography. In this paper we present the multipath execution, a software randomization technique based on LLVM framework. Multipath execution is designed and implemented to achieve not only randomness of memory layout and diversity of binary files, but also randomness of program code paths executed, which is unique in our work. The processed software shows uncertainty from static and dynamic aspects, which makes it difficult to analyze and attack. Both qualitative and quantitative assessments illustrate the effectiveness of our method.