节点文献
应用改进哨兵的软件攻击威胁自感知方法
A Method of Software Self-sensing Attack Threats by the Improved Guard
【摘要】 运行态软件处于开放复杂的白盒攻击环境中,面临严重的逆向分析安全问题.动态保护是为软件提供持久保护的新思想,而使软件具有全面的感知白盒攻击环境中攻击威胁的能力是探索动态保护的关键.本文提出一种应用改进哨兵的运行态软件攻击威胁自感知方法.首先对攻击威胁进行分类与特征提取;其次设计相应的改进哨兵,使其具有感知并传递不同攻击威胁信息的能力;然后分析待保护软件的依赖关系并确定感知区域集;最后依据最小覆盖模型进行哨兵布局.此外,通过详细地实例分析及实验验证了本文方法的可行性与实用性.该方法有助于更深入挖掘攻击与保护间的关系,为进一步研究动态保护奠定基础.
【Abstract】 Software run in the open complex white box attack environment and thus faced with serious reverse analysis problems. Dynamic protection is a new idea to provide long-lasting protection,and making the running software had ability to comprehensive sense the attack threats is the key to explore dynamic protection. A method of software self-sensing based on the improved guard is proposed in this paper. Firstly,classify and extract the features of attack threats; Secondly,design the corresponding improved guards,which have the ability to sense and transmit attack threat information; Then analyze the software dependencies of being protected software and determine the sensed areas; Finally in accordance with minimum cover and multi-level gateway model,layout for the chosen guards. In addition,verified the feasibility and practicability of the method in this paper through a case analysis in detail. This method is helpful to dig the relationship between attack and protection and also lays the foundation for researching on dynamic protection further.
【Key words】 software guard; attack threat; sensing; dynamic protection; code blocks dependency;
- 【文献出处】 小型微型计算机系统 ,Journal of Chinese Computer Systems , 编辑部邮箱 ,2014年07期
- 【分类号】TP311.52;TP309
- 【被引频次】6
- 【下载频次】53