
Automated Software Diversity
Morgan and Claypool Life Sciences (Publisher)
Published on 30. December 2015
Book
Paperback/Softback
88 pages
978-1-62705-734-9 (ISBN)
Description
Whereas user-facing applications are often written in modern languages, the firmware, operating system, support libraries, and virtual machines that underpin just about any modern computer system are still written in low-level languages that value flexibility and performance over convenience and safety. Programming errors in low-level code are often exploitable and can, in the worst case, give adversaries unfettered access to the compromised host system.
This book provides an introduction to and overview of automatic software diversity techniques that, in one way or another, use randomization to greatly increase the difficulty of exploiting the vast amounts of low-level code in existence. Diversity-based defenses are motivated by the observation that a single attack will fail against multiple targets with unique attack surfaces. We introduce the many, often complementary, ways that one can diversify attack surfaces and provide an accessible guide to more than two decades worth of research on the topic. We also discuss techniques used in conjunction with diversity to prevent accidental disclosure of randomized program aspects and present an in-depth case study of one of our own diversification solutions.
This book provides an introduction to and overview of automatic software diversity techniques that, in one way or another, use randomization to greatly increase the difficulty of exploiting the vast amounts of low-level code in existence. Diversity-based defenses are motivated by the observation that a single attack will fail against multiple targets with unique attack surfaces. We introduce the many, often complementary, ways that one can diversify attack surfaces and provide an accessible guide to more than two decades worth of research on the topic. We also discuss techniques used in conjunction with diversity to prevent accidental disclosure of randomized program aspects and present an in-depth case study of one of our own diversification solutions.
More details
Series
Language
English
Place of publication
San Rafael, CA
United States
Publishing group
Morgan & Claypool Publishers
Target group
College/higher education
Professional and scholarly
Dimensions
Height: 235 mm
Width: 187 mm
Weight
333 gr
ISBN-13
978-1-62705-734-9 (9781627057349)
Copyright in bibliographic data and cover images is held by Nielsen Book Services Limited or by the publishers or by their respective licensors: all rights reserved.
Schweitzer Classification
Content
- Preface
- Acknowledgments
- Introduction
- Attacking and Defending
- What to Diversify
- When to Diversify
- Case Study: Compile-time Diversification
- Information Leakage Resilience
- Advanced Topics
- Bibliography
- Authors' Biographies
- Acknowledgments
- Introduction
- Attacking and Defending
- What to Diversify
- When to Diversify
- Case Study: Compile-time Diversification
- Information Leakage Resilience
- Advanced Topics
- Bibliography
- Authors' Biographies