arrow
Return

Source Code Transformations for Improving Security of Time-bounded K-variant Systems

delete2021-09-01
delete2
PRE
AI
B
Berk Bekiroglu *
B
Bogdan Korel
DOI:10.1016/j.infsof.2021.106601delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Context: Source code transformation techniques can improve the security of systems against memory exploitation attacks. As such, the chance of exploitation of security vulnerabilities can be decreased by using different controlled source code transformation techniques. In K-variant architecture, multiple variants of a program are generated through a controlled source code transformation to improve the security of systems. Objective: To investigate the effectiveness and practicality of source code program transformations in improving the security of time-bounded K-variant systems for memory exploitation attacks. Method: The effectiveness of program transformations in improving the security of time-bounded K-variant systems is experimentally investigated for different memory attacks. Results: The results suggest that generating multiple variants using the presented transformations significantly improves the survivability of time-bounded K-variant systems under memory exploitation attacks. Conclusion: We conclude that generating multi-variants in time-bounded K-variant systems in accordance with the presented program transformations may improve the security of time-bounded K-variant systems significantly for memory exploitation attacks with a reasonable cost and overhead.
Keywords:
K-variant architecture
System security
Multiple variant architecture
Source code transformation
Memory exploitation attacks

Journal

Information and Software Technology cover
Information and Software Technology
IF:
4.3
Papers:
3.7K
Citations:
7.7K

Organization

I
Illinois Institute of Technology
Scholars:
3.8K
Papers: 3.9K
Citations: 4.2K