arrow
Return

A meta-model for software protections and reverse engineering attacks

delete2019-04-01
delete19
delete
OA
AI
C
Cataldo Basile
D
Daniele Canavese
L
Leonardo Regano
P
Paolo Falcarin *
B
Bjorn De Sutter
DOI:10.1016/j.jss.2018.12.025delete
deleteOriginal
deleteShare
deleteSave
View PDF
Abstract

Abstract

En 中文
Software protection techniques are used to protect valuable software assets against man-at-the-end attacks. Those attacks include reverse engineering to steal confidential assets, and tampering to break the software's integrity in unauthorized ways. While their ultimate aims are the original assets, attackers also target the protections along their attack path. To allow both humans and tools to reason about the strength of available protections (and combinations thereof) against potential attacks on concrete applications and their assets, i.e., to assess the true strength of layered protections, all relevant and available knowledge on the relations between the relevant aspects of protections, attacks, applications, and assets need to be collected, structured, and formalized. This paper presents a software protection meta-model that can be instantiated to construct a formal knowledge base that holds precisely that information. The presented meta-model is validated against existing models and taxonomies in the domain of software protection, and by means of prototype tools that we developed to help non-modelling-expert software defenders with populating a knowledge base and with extracting and inferring practically useful information from it. All discussed tools are available as open source, and we evaluate their use as part of a software protection work flow on an open source application and industrial use cases. (C) 2019 Elsevier Inc. All rights reserved.
Keywords:
Software protection
Security knowledge base
Decision support
Attack modelling
Reverse engineering
Meta-model
AI Summary

AI Summary

Key information extracted from the uploaded paper, including a brief overview, abstract, background, key highlights, visual analysis, and future outlook.

Journal

Journal of Systems and Software cover
Journal of Systems and Software
IF:
4.1
Papers:
5.4K
Citations:
8.4K

Organization

G
Ghent University
Scholars:
5.2W
Papers: 4.5W
Citations: 5.5W
U
University of East London
Scholars:
1.1K
Papers: 1.1K
Citations: 1.0K
P
Polytechnic University of Turin
Scholars:
1.3W
Papers: 1.3W
Citations: 1.3W
researcher View more organizations