Image from Google Jackets

Automated Software Diversity / by Per Larsen, Stefan Brunthaler, Lucas Davi, Ahmad-Reza Sadeghi, Michael Franz

By: Larsen, Per, (1980-), autor
Contributor(s): Brunthaler, Stefan, autor | Davi, Lucas, autor | Sadeghi, Ahmad-Reza, autor | Franz, Michael, autor
Material type: materialTypeLabelE-bookSeries: (Synthesis Lectures on Information Security Privacy and Trust, 1945-9750).Publisher: Cham : Springer International Publishing, 2016Edition: 1st edition 2016.Description: 1 recurso en línea (XI, 76 páginas).ISBN: 9783031023460.Subject: Ingeniería del software | Programación matemática | Seguridad informáticaOnline resources: Acceso a este recurso digital (usuarios Universidad Europea de Madrid)Digital Resources
Contents:
Preface -- Acknowledgments -- Introduction -- Attacking and Defending -- What to Diversify -- When to Diversify -- Case Study: Compile-time Diversification -- Information Leakage Resilience -- Advanced Topics -- Bibliography -- Authors' Biographies.
Summary: Whereas user-facing applications are often written in modern languages, the firmware, operating system, support libraries, and virtual machines that underpin just about any modern computer system are still written in low-level languages that value flexibility and performance over convenience and safety. Programming errors in low-level code are often exploitable and can, in the worst case, give adversaries unfettered access to the compromised host system. This book provides an introduction to and overview of automatic software diversity techniques that, in one way or another, use randomization to greatly increase the difficulty of exploiting the vast amounts of low-level code in existence. Diversity-based defenses are motivated by the observation that a single attack will fail against multiple targets with unique attack surfaces. We introduce the many, often complementary, ways that one can diversify attack surfaces and provide an accessible guide to more than two decades worth of research on the topic. We also discuss techniques used in conjunction with diversity to prevent accidental disclosure of randomized program aspects and present an in-depth case study of one of our own diversification solutions.
Tags from this library: No tags from this library for this title. Log in to add tags.
Star ratings
    Average rating: 0.0 (0 votes)
Holdings
Item type Current library Collection Call number Status Date due Barcode Item holds
LIBRO-E NO PRÉSTAMO LIBRO-E NO PRÉSTAMO Madrid Digital Acceso Electrónico (UEM) Ciencias e Ingeniería QA76.758 2016 EB (Browse shelf(Opens below)) Acceso electrónico eBook.01112174
Total holds: 0

Preface -- Acknowledgments -- Introduction -- Attacking and Defending -- What to Diversify -- When to Diversify -- Case Study: Compile-time Diversification -- Information Leakage Resilience -- Advanced Topics -- Bibliography -- Authors' Biographies.

Whereas user-facing applications are often written in modern languages, the firmware, operating system, support libraries, and virtual machines that underpin just about any modern computer system are still written in low-level languages that value flexibility and performance over convenience and safety. Programming errors in low-level code are often exploitable and can, in the worst case, give adversaries unfettered access to the compromised host system. This book provides an introduction to and overview of automatic software diversity techniques that, in one way or another, use randomization to greatly increase the difficulty of exploiting the vast amounts of low-level code in existence. Diversity-based defenses are motivated by the observation that a single attack will fail against multiple targets with unique attack surfaces. We introduce the many, often complementary, ways that one can diversify attack surfaces and provide an accessible guide to more than two decades worth of research on the topic. We also discuss techniques used in conjunction with diversity to prevent accidental disclosure of randomized program aspects and present an in-depth case study of one of our own diversification solutions.

There are no comments on this title.

to post a comment.
Share