Publications

Semantic-based Code Obfuscation by Abstract Interpretation  (2009)

Authors:
DALLA PREDA, Mila; Giacobazzi, Roberto
Title:
Semantic-based Code Obfuscation by Abstract Interpretation
Year:
2009
Type of item:
Articolo in Rivista
Tipologia ANVUR:
Articolo su rivista
Language:
Inglese
Format:
A Stampa
Referee:
Name of journal:
JOURNAL OF COMPUTER SECURITY
ISSN of journal:
0926-227X
N° Volume:
17
Number or Folder:
6
Page numbers:
855-908
Keyword:
Code obfuscation; abstract interpretation; program semantics; static program analysis
Short description of contents:
In recent years code obfuscation has attracted research interest as a promising technique for protecting secret properties of programs. The basic idea of code obfuscation is to transform programs in order to hide their sensitive information while preserving their functionality. One of the major drawbacks of code obfuscation is the lack of a rigorous theoretical framework that makes it difficult to formally analyze and certify the effectiveness of obfuscating techniques. We face this problem by providing a formal framework for code obfuscation based on abstract interpretation and program semantics. In particular, we show that what is hidden and what is preserved by an obfuscating transformation can be expressed as abstract interpretations of program semantics. Being able to specify what is masked and what is preserved by an obfuscation allows us to understand its potency, namely the amount of obscurity that the transformation adds to programs. In the proposed framework, obfuscation and attackers are modeled as approximations of program semantics and the lattice of abstract interpretations provides a formal tool for comparing obfuscations with respect to their potency. In particular, we prove that our framework provides an adequate setting to measure not only the potency of an obfuscation but also its resilience, i.e., the difficulty of undoing the obfuscation. We consider code obfuscation by opaque predicate insertion and we show how the degree of abstraction needed to disclose different opaque predicates allows us to compare their potency and resilience.
Web page:
http://iospress.metapress.com/content/d441n2341j810827/?p=2241c1b6e5984556aa9f0121d33e42fd&pi=1
Product ID:
56307
Handle IRIS:
11562/342463
Deposited On:
April 2, 2012
Last Modified:
November 15, 2022
Bibliographic citation:
DALLA PREDA, Mila; Giacobazzi, Roberto, Semantic-based Code Obfuscation by Abstract Interpretation «JOURNAL OF COMPUTER SECURITY» , vol. 17 , n. 62009pp. 855-908

Consulta la scheda completa presente nel repository istituzionale della Ricerca di Ateneo IRIS

<<back

Activities

Research facilities

Share