• DocumentCode
    153559
  • Title

    SoK: Automated Software Diversity

  • Author

    Larsen, Per ; Homescu, Andrei ; Brunthaler, Stefan ; Franz, Michael

  • Author_Institution
    Univ. of California, Irvine, Irvine, CA, USA
  • fYear
    2014
  • fDate
    18-21 May 2014
  • Firstpage
    276
  • Lastpage
    291
  • Abstract
    The idea of automatic software diversity is at least two decades old. The deficiencies of currently deployed defenses and the transition to online software distribution (the "App store" model) for traditional and mobile computers has revived the interest in automatic software diversity. Consequently, the literature on diversity grew by more than two dozen papers since 2008. Diversity offers several unique properties. Unlike other defenses, it introduces uncertainty in the target. Precise knowledge of the target software provides the underpinning for a wide range of attacks. This makes diversity a broad rather than narrowly focused defense mechanism. Second, diversity offers probabilistic protection similar to cryptography-attacks may succeed by chance so implementations must offer high entropy. Finally, the design space of diversifying program transformations is large. As a result, researchers have proposed multiple approaches to software diversity that vary with respect to threat models, security, performance, and practicality. In this paper, we systematically study the state-of-the-art in software diversity and highlight fundamental trade-offs between fully automated approaches. We also point to open areas and unresolved challenges. These include "hybrid solutions", error reporting, patching, and implementation disclosure attacks on diversified software.
  • Keywords
    cryptography; mobile computing; probability; software performance evaluation; App store model; SoK; automated software diversity; cryptography; error reporting; implementation disclosure attacks; mobile computers; online software distribution; patching attacks; probabilistic protection; program transformations; software attacks; Encoding; Layout; Monitoring; Operating systems; Registers; Security;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Security and Privacy (SP), 2014 IEEE Symposium on
  • Conference_Location
    San Jose, CA
  • ISSN
    1081-6011
  • Type

    conf

  • DOI
    10.1109/SP.2014.25
  • Filename
    6956570