ISA2R: Improving software attack and analysis resilience via compiler-level software diversity

Rafael Fedler, Sebastian Banescu, Alexander Pretschner

Publikation: Beitrag in Buch/Bericht/KonferenzbandKonferenzbeitragBegutachtung

2 Zitate (Scopus)

Abstract

The current IT landscape is characterized by software monoculture: All installations of one program version are identical. This leads to a huge return of investment for attackers who can develop a single attack once to compromise millions of hosts worldwide. Software diversity has been proposed as an alternative to software monoculture. In this paper we present a collection of diversification transformations called ISA2R, developed for the low-level virtual machine (LLVM). By diversifying the properties crucial to successful exploitation of a vulnerability, we render exploits that work on one installation of a software ineffective against others. Through this we enable developers to add protective measures automatically during compilation. In contrast to similar existing tools, ISA2R provides protection against a wider range of attacks and is applicable to all programming languages supported by LLVM.

OriginalspracheEnglisch
TitelComputer Safety, Reliability, and Security - 34th International Conference, SAFECOMP 2015, Proceedings
Redakteure/-innenFloor Koornneef, Coen van Gulijk
Herausgeber (Verlag)Springer Verlag
Seiten362-371
Seitenumfang10
ISBN (Print)9783319242545
DOIs
PublikationsstatusVeröffentlicht - 2015
Veranstaltung34th International Conference on Computer Safety, Reliability, and Security, SAFECOMP 2015 - Delft, Niederlande
Dauer: 23 Sept. 201525 Sept. 2015

Publikationsreihe

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Band9337
ISSN (Print)0302-9743
ISSN (elektronisch)1611-3349

Konferenz

Konferenz34th International Conference on Computer Safety, Reliability, and Security, SAFECOMP 2015
Land/GebietNiederlande
OrtDelft
Zeitraum23/09/1525/09/15

Fingerprint

Untersuchen Sie die Forschungsthemen von „ISA2R: Improving software attack and analysis resilience via compiler-level software diversity“. Zusammen bilden sie einen einzigartigen Fingerprint.

Dieses zitieren