Software Protection with Code Mobility

Software Protection with Code Mobility
复制标题

具有代码移动性的软件保护

DOI:
--
复制
发表时间:
2015
期刊:
MTD@CCS
影响因子:
--
通讯作者:
B. D. Sutter
B. D. Sutter
中科院分区:
--
文献类型:
--
作者:
Alessandro Cabutto;P. Falcarin;Bert Abrath;Bart Coppens;B. D. Sutter

文献摘要

被引文献

相似文献

二进制代码的分析是末端攻击的常见步骤,以识别对实施攻击至关重要的代码部分,例如识别隐藏在代码中的私钥,识别敏感算法或篡改代码以禁用嵌入在二进制代码中的保护(例如许可证检查或DRM),或以未经授权的方式使用软件。代码移动性可用于通过从部署的软件程序中删除部分代码并在运行时通过从受信任的服务器下载二进制代码块来安装它来阻止代码分析和调试。建议的架构的代码移动性保护下载移动的代码块,这是动态分配在运行时确定的地址;控制转移到和出移动的代码块重写使用暗黑破坏神二进制重写工具。
The analysis of binary code is a common step of Man-At-The-End attacks to identify code sections crucial to implement attacks, such as identifying private key hidden in the code, identifying sensitive algorithms or tamper with the code to disable protections (e.g. license checks or DRM) embedded in binary code, or use the software in an unauthorized manner. Code Mobility can be used to thwart code analysis and debugging by removing parts of the code from the deployed software program and installing it at run-time by downloading binary code blocks from a trusted server. The proposed architecture of the code mobility protection downloads mobile code blocks, which are allocated dynamically at addresses determined at run-time; control transfers into and out of mobile code blocks are rewritten using the Diablo binary-rewriter tool.