DocumentCode
3175394
Title
The Problem of Usable Binary Authentication
Author
Wu, Yongzheng ; Yap, Roland H C
Author_Institution
Sch. of Comput., Nat. Univ. of Singapore, Singapore, Singapore
fYear
2010
fDate
9-11 June 2010
Firstpage
34
Lastpage
35
Abstract
Attacks by malware usually work by getting a binary to be executed. Sometimes users are unaware that such binaries are being executed. The end result is that attackers can either compromise a system or get it to fail. One defence against such attacks is to ensure integrity of files [3]. A more comprehensive mechanism is binary authentication (code signing is also a form of binary authentication) which tries to ensure that any binaries loaded by the operating system and software applications are first authenticated [1], [2], i.e. the content of the binary is known and is trusted. To have full protection using binary authentication, it makes sense to have a default deny policy where binaries which do not pass authentication are prevented from executing. However, if an operating system employs mandatory binary authentication for protection purposes, the end result may either be not user friendly or not very usable. In this paper, we discuss the issues and difficulties of making binary authentication usable on the Windows operating system.
Keywords
invasive software; operating systems (computers); Windows operating system; malware; usable binary authentication; Authentication; Computer worms; Databases; Internet; Kernel; Libraries; Operating systems; Protection; Security; Software systems;
fLanguage
English
Publisher
ieee
Conference_Titel
Secure Software Integration and Reliability Improvement Companion (SSIRI-C), 2010 Fourth International Conference on
Conference_Location
Singapore
Print_ISBN
978-1-4244-7644-2
Type
conf
DOI
10.1109/SSIRI-C.2010.19
Filename
5521557
Link To Document