2010 · 24 citations · 19 references
EngineeringInformation SecurityCompiler TechnologyComputer ArchitectureSoftware EngineeringRegister RandomizationSoftware AnalysisFormal VerificationHardware SecurityVulnerability Assessment (Computing)FuzzingDynamic CompilationRuntime OverheadCompiler SupportComputer EngineeringComputer ScienceMulti-variant Program ExecutionStatic Program AnalysisSecurity Testing MethodSoftware SecurityProgram AnalysisSoftware TestingVulnerability DetectionVulnerability DiscoveryParallel ProgrammingSystem Software
Multi-variant program execution is an application of n-version programming, in which several slightly different instances of the same program are executed in lockstep on a multiprocessor. These variants are created in such a way that they behave identically under "normal" operation and diverge when "out of specification" events occur, which may be indicative of attacks. This paper assess the effectiveness of different code variation techniques to address different classes of vulnerabilities. In choosing a variant or combination of variants, security demands need to be balanced against runtime overhead. Our study indicates that a good combination of variations when running two variants is to choose one of instruction set randomization, system call number randomization, and register randomization, and use that together with library entry point randomization. Running more variants simultaneously makes it exponentially more difficult to take over the system.
19
StackGuard: automatic adaptive detection and prevention of buffer-overflow attacks
Crispin Cowan, Calton Pu, Dave Maier et al. · PDXScholar (Portland State University) · 1998 · 1.3K citations · Full text
Smashing The Stack For Fun And Profit
A. One · Medical Entomology and Zoology · 1996 · 767 citations
Building diverse computer systems
Stephanie Forrest, Anil Somayaji, David H. Ackley · 2002 · 490 citations
Heterogeneous Computing, Engineering, Information Security +23