The Instruction Separation Framework against Man-At-The-End Attacks: Protect What is Mattered On-the-Fly

Jiaxuan Wu, Wei-Yang Chiu, Peichen Liu, Weizhi Meng, Wenjuan Li · 2023

Man-At-The-End (MATE) attack is constantly discussed in the information security research field. Though many detection and mitigation methods have been proposed in software protection (SP) industry, it is still considered as an open challenge in many aspects. For example, existing tools and consultation services are always costly and opaque. This lack of transparency raises concerns regarding whether the companies are adequately grasping the risks. In response to this kind of industry challenge, in this work, we aim to propose a new perspective of method to resolve multiple variations at a time – named The Instruction Separation Framework (ISF). It consists of four important techniques: the program instrumentation, the user mode monitor, kernel mode hooks, and the execution module. The aim of our framework is to provide foundational runtime software integrity against primary MATE attacks, such as binary patching, code injection, and memory hooking. More specifically, we first survey several state-of-the-art approaches on defending MATE attacks, and then demonstrate how our framework can achieve the goal by securing critical functions and data of the program on-the-fly. Finally, we discuss the trade-off between protection completeness and the runtime overhead.

Read the paper · More papers on PaperTik