arrow
返回

Enhance virtual-machine-based code obfuscation security through dynamic bytecode scheduling

delete2018-05-01
delete20
delete
OA
AI
K
Kaiyuan Kuang
Z
Zhanyong Tang *
X
Xiaoqing Gong
D
Dingyi Fang
X
Xiaojiang Chen
Z
Zheng Wang
DOI:10.1016/j.cose.2018.01.008delete
delete原文链接
delete分享
delete收藏
查看原文
摘要

摘要

En 中文
Code virtualization built upon virtual machine (VM) technologies is emerging as a viable method for implementing code obfuscation to protect programs against unauthorized analysis. State-of-the-art VM-based protection approaches use a fixed scheduling structure where the program always follows a single, deterministic execution path for the same input. Such approaches, however, are vulnerable in certain scenarios where the attacker can reuse knowledge extracted from previously seen software to crack applications protected with the same obfuscation scheme. This paper presents DSVMP, a novel VM-based code obfuscation approach for software protection. DSVMP brings together two techniques to provide stronger code protection than prior VM-based approaches. Firstly, it uses a dynamic instruction scheduler to randomly direct the program to execute different paths without violating the correctness across different runs. By randomly choosing the program execution path, the application exposes diverse behavior, making it much more difficult for an attacker to reuse the knowledge collected from previous runs or similar applications to launch an attack. Secondly, it employs multiple VMs to further obfuscate the mapping from VM opcode to native machine instructions, so that the same opcode could be mapped to different native instructions at runtime, making code analysis even harder. We have implemented DSVMP in a prototype system and evaluated it using a set of widely used applications. Experimental results show that DSVMP provides stronger protection with comparable runtime overhead and code size, when it is compared to two commercial VM-based code obfuscation tools. (C) 2018 The Author(s). Published by Elsevier Ltd.
Keyword:
Software protection
Program diversity
Obfuscation
Code security
Instruction virtualization
Dynamic scheduling
Reverse engineering
Cumulative attack
Code virtualization
Code obfuscation
AI总结

AI总结

对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。

期刊

C
Computers and Security
IF:
5.4
论文数:
4.6K
被引数:
1.4W

机构

L
Lancaster University
学者数:
9.5K
论文数: 1.1W
被引数: 1.7W
N
northwest university xi'an
学者数:
1.8W
论文数: 1.2W
被引数: 22
引用论文

引用论文