Independence from obfuscation: A semantic framework for diversity.

Saved in:
Bibliographic Details
Title: Independence from obfuscation: A semantic framework for diversity.
Authors: Pucella, Riccardo1 riccardo@ccs.neu.edu, Schneider, Fred B.2 fbs@cs.cornell.edu
Source: Journal of Computer Security. 2010, Vol. 18 Issue 5, p701-749. 49p. 11 Diagrams.
Subjects: Replication (Experimental design), Imperative programming, Programmed instruction writing, Memory, Web typography, Layout (Printing)
Abstract: A set of replicas is diverse to the extent that they implement the same functionality but differ in their implementation details. Diverse replicas are less likely to succumb to the same attacks, when attacks depend on memory layout and/or other implementation details. Recent work advocates using mechanical means, such as program rewriting, to create such diversity. A correspondence between the specific transformations being employed and the attacks they defend against is often provided, but little has been said about the overall effectiveness of diversity per se in defending against attacks. With this broader goal in mind, this paper gives a precise characterization of attacks, applicable to viewing diversity as a defense, and also shows how mechanically-generated diversity compares to a well-understood defense: type checking. [ABSTRACT FROM AUTHOR]
Copyright of Journal of Computer Security is the property of Sage Publications Inc. and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract. (Copyright applies to all Abstracts.)
Database: Engineering Source
FullText Links:
  – Type: pdflink
Text:
  Availability: 0
Header DbId: egs
DbLabel: Engineering Source
An: 52929759
AccessLevel: 6
PubType: Academic Journal
PubTypeId: academicJournal
PreciseRelevancyScore: 0
IllustrationInfo
Items – Name: Title
  Label: Title
  Group: Ti
  Data: Independence from obfuscation: A semantic framework for diversity.
– Name: Author
  Label: Authors
  Group: Au
  Data: <searchLink fieldCode="AR" term="%22Pucella%2C+Riccardo%22">Pucella, Riccardo</searchLink><relatesTo>1</relatesTo><i> riccardo@ccs.neu.edu</i><br /><searchLink fieldCode="AR" term="%22Schneider%2C+Fred+B%2E%22">Schneider, Fred B.</searchLink><relatesTo>2</relatesTo><i> fbs@cs.cornell.edu</i>
– Name: TitleSource
  Label: Source
  Group: Src
  Data: <searchLink fieldCode="JN" term="%22Journal+of+Computer+Security%22">Journal of Computer Security</searchLink>. 2010, Vol. 18 Issue 5, p701-749. 49p. 11 Diagrams.
– Name: Subject
  Label: Subjects
  Group: Su
  Data: <searchLink fieldCode="DE" term="%22Replication+%28Experimental+design%29%22">Replication (Experimental design)</searchLink><br /><searchLink fieldCode="DE" term="%22Imperative+programming%22">Imperative programming</searchLink><br /><searchLink fieldCode="DE" term="%22Programmed+instruction+writing%22">Programmed instruction writing</searchLink><br /><searchLink fieldCode="DE" term="%22Memory%22">Memory</searchLink><br /><searchLink fieldCode="DE" term="%22Web+typography%22">Web typography</searchLink><br /><searchLink fieldCode="DE" term="%22Layout+%28Printing%29%22">Layout (Printing)</searchLink>
– Name: Abstract
  Label: Abstract
  Group: Ab
  Data: A set of replicas is diverse to the extent that they implement the same functionality but differ in their implementation details. Diverse replicas are less likely to succumb to the same attacks, when attacks depend on memory layout and/or other implementation details. Recent work advocates using mechanical means, such as program rewriting, to create such diversity. A correspondence between the specific transformations being employed and the attacks they defend against is often provided, but little has been said about the overall effectiveness of diversity per se in defending against attacks. With this broader goal in mind, this paper gives a precise characterization of attacks, applicable to viewing diversity as a defense, and also shows how mechanically-generated diversity compares to a well-understood defense: type checking. [ABSTRACT FROM AUTHOR]
– Name: AbstractSuppliedCopyright
  Label:
  Group: Ab
  Data: <i>Copyright of Journal of Computer Security is the property of Sage Publications Inc. and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract.</i> (Copyright applies to all Abstracts.)
PLink https://search.ebscohost.com/login.aspx?direct=true&site=eds-live&db=egs&AN=52929759
RecordInfo BibRecord:
  BibEntity:
    Identifiers:
      – Type: doi
        Value: 10.3233/JCS-2009-0379
    Languages:
      – Code: eng
        Text: English
    PhysicalDescription:
      Pagination:
        PageCount: 49
        StartPage: 701
    Subjects:
      – SubjectFull: Replication (Experimental design)
        Type: general
      – SubjectFull: Imperative programming
        Type: general
      – SubjectFull: Programmed instruction writing
        Type: general
      – SubjectFull: Memory
        Type: general
      – SubjectFull: Web typography
        Type: general
      – SubjectFull: Layout (Printing)
        Type: general
    Titles:
      – TitleFull: Independence from obfuscation: A semantic framework for diversity.
        Type: main
  BibRelationships:
    HasContributorRelationships:
      – PersonEntity:
          Name:
            NameFull: Pucella, Riccardo
      – PersonEntity:
          Name:
            NameFull: Schneider, Fred B.
    IsPartOfRelationships:
      – BibEntity:
          Dates:
            – D: 01
              M: 08
              Text: 2010
              Type: published
              Y: 2010
          Identifiers:
            – Type: issn-print
              Value: 0926227X
          Numbering:
            – Type: volume
              Value: 18
            – Type: issue
              Value: 5
          Titles:
            – TitleFull: Journal of Computer Security
              Type: main
ResultId 1