loading...
 This Article 
   
 Share 
   
 Bibliographic References 
   
 Add to: 
 
Digg
Furl
Spurl
Blink
Simpy
Google
Del.icio.us
Y!MyWeb
 
 Search 
   
19th IEEE Computer Security Foundations Workshop (CSFW'06)
Independence From Obfuscation: A Semantic Framework for Dive
Venice, Italy
July 05-July 07
ISBN: 0-7695-2615-2
Riccardo Pucella, Northeastern University, USA
Fred B. Schneider, Cornell University, USA
A set of replicas is diverse to the extent that all implement the same functionality but differ in their implementation details. Diverse replicas are less prone to having vulnerabilities in common, because attacks typically depend on memory layout and/or instruction-sequence specifics. Recent work advocates using mechanical means, such as program rewriting, to create such diversity. A correspondence between the specific transformations being employed and the attacks they defend against is often provided, but little has been said about the overall effectiveness of diversity per se in defending against attacks. With this broader goal in mind, we here give a precise characterization of attacks, applicable to viewing diversity as a defense, and also show how mechanically-generated diversity compares to a wellunderstood defense: strong typing.
Citation:
Riccardo Pucella, Fred B. Schneider, "Independence From Obfuscation: A Semantic Framework for Dive," csfw, pp.230-241, 19th IEEE Computer Security Foundations Workshop (CSFW'06), 2006
Usage of this product signifies your acceptance of the Terms of Use.