Tamper-Tolerant Software: Modeling and Implementation

Tamper-Tolerant Software: Modeling and Implementation
复制标题

DOI:
10.1007/978-3-642-04846-3_9
复制
发表时间:
2009-10
期刊:
2013 14th International Workshop on Microprocessor Test and Verification
影响因子:
--
通讯作者:
Mariusz H. Jakubowski;C. Saw;R. Venkatesan
Mariusz H. Jakubowski;C. Saw;R. Venkatesan
中科院分区:
其他
文献类型:
--
作者:
Mariusz H. Jakubowski;C. Saw;R. Venkatesan

文献摘要

被引文献

相似文献

常见的软件保护系统试图检测对受保护应用程序的恶意观察和修改。在检测到篡改后,反黑客代码可能会导致崩溃或逐渐失效,使应用程序无法使用或麻烦。这样的响应旨在使攻击复杂化,但也给开发人员和最终用户带来了问题,特别是当错误或其他问题意外地调用反篡改措施时。要解决这些问题,另一种方法是检测和修复恶意更改。本文提出了一种将程序转换为防篡改版本的方案,该方案使用自校正操作作为对攻击的响应。该方法结合了容错和软件安全领域的技术,通过代码个性化和冗余对程序进行转换。我们还描述了通过纠错、延迟响应和检查点来增强安全性。为了进行安全分析,我们采用了基于图的攻击和防御模型,在软件防篡改的背景下。这有助于估计在实际场景中破坏我们的方案的难度。
Common software-protection systems attempt to detect malicious observation and modification of protected applications. Upon tamper detection, anti-hacking code may produce a crash or gradual failure, rendering the application unusable or troublesome. Such a response is designed to complicate attacks, but has also caused problems for developers and end users, particularly when bugs or other problems invoke anti-tampering measures accidentally. To address these issues, an alternative approach is to detect and fix malicious changes. This paper presents a scheme to transform programs into tamper-tolerant versions that use self-correcting operation as a response against attacks. Combining techniques from the fields of fault tolerance and software security, the approach transforms programs via code individualization and redundancy. We also describe security enhancements through error correction, delayed responses and checkpointing. For security analysis, we adapt a graph-based model of attacks and defenses in the context of software tamper-resistance. This helps to estimate the difficulty of breaking our scheme in practical scenarios.