首页> 外文会议>International Conference on Program Comprehension >How Professional Hackers Understand Protected Code while Performing Attack Tasks
【24h】

How Professional Hackers Understand Protected Code while Performing Attack Tasks

机译:专业黑客在执行攻击任务时如何理解受保护的代码

获取原文

摘要

Code protections aim at blocking (or at least delaying) reverse engineering and tampering attacks to critical assets within programs. Knowing the way hackers understand protected code and perform attacks is important to achieve a stronger protection of the software assets, based on realistic assumptions about the hackers' behaviour. However, building such knowledge is difficult because hackers can hardly be involved in controlled experiments and empirical studies. The FP7 European project Aspire has given the authors of this paper the unique opportunity to have access to the professional penetration testers employed by the three industrial partners. In particular, we have been able to perform a qualitative analysis of three reports of professional penetration test performed on protected industrial code. Our qualitative analysis of the reports consists of open coding, carried out by 7 annotators and resulting in 459 annotations, followed by concept extraction and model inference. We identified the main activities: understanding, building attack, choosing and customizing tools, and working around or defeating protections. We built a model of how such activities take place. We used such models to identify a set of research directions for the creation of stronger code protections.
机译:代码保护旨在阻止(或至少延迟)反向工程,并篡改对程序内关键资产的攻击。基于对黑客行为的现实假设,了解黑客理解受保护代码和执行攻击的方式对于实现对软件资产的更强保护非常重要。但是,建立这样的知识很困难,因为黑客很难参与受控实验和实证研究。 FP7欧洲项目Aspire为本文的作者提供了获得三个行业合作伙伴聘用的专业渗透测试人员的独特机会。特别是,我们能够对受保护的工业法规执行的三份专业渗透测试报告进行定性分析。我们对报告的定性分析包括由7个注释者进行的开放编码,并产生459个注释,然后进行概念提取和模型推断。我们确定了主要活动:了解,建立攻击,选择和自定义工具,以及变通或破坏保护措施。我们建立了如何进行此类活动的模型。我们使用这样的模型来确定一组研究方向,以创建更强大的代码保护。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号