Small crises lead to small changes; large crises lead to large changes. COVID 19 is a large crisis but, at this moment in time, it is hard to tell what its long-lasting impacts on society and the economy will be. One thing is sure: we will all make a distinction between the time before Corona and the time after Corona, and the new normal is very likely to be different from the old normal, no matter how hard people try to go back to the latter. Historically, it might become as impactful as the fall of the Berlin Wall, or 9/11.
Summary To protect valuable assets embedded in software against reverse‐engineering attacks, software obfuscations aim at raising the apparent complexity of programs and at removing information that is useful for attackers. In this work, we propose to combine five transformations that obfuscate the type hierarchy of Java applications and eliminate much of the type information that can be inferred from the Java bytecode. We rely on some existing algorithms, present adaptations, and introduce new algorithms for some of the transformations, which are all made available in an open‐source prototype implementation ready for take‐up. We present an extensive experimental evaluation on benchmarks of real‐world complexity, using complementary metrics that cover the protection strength against both human and tool‐based reverse‐engineering attack methods. The results indicate that the obfuscation is effective as well as much more efficient than the previous state of the art. For the first time, this makes these obfuscations practically viable in real‐world deployment scenarios.
Existing compiler techniques can transform code to make its timing behavior independent of sensitive values to prevent information leakage through time side channels. Those techniques are hampered, however, by their static nature and dependence on details of the processor targeted during the compilation. This paper presents a dynamic compiler approach based on offline profiles and JIT compiler strategies. This approach reduces overhead significantly and enables a trade-off between provided protection and overhead. Furthermore, it supports adaptive policies in which the protection adapts to run-time changes in the requirements. A prototype implementation in the Jikes Research VM is evaluated on RSA encryption, HMAC key verification, and IDEA encryption.
Bjorn De Sutter合作论文数Electronics and Information Systems Department54
Michiel Ronsse合作论文数Ghent University;Department of Electronics and Information Systems29
Bertrand Anckaert合作论文数 Parallel Information Systems group (PARIS), of the Electronics and Information Systems Department (ELIS), of Ghent University (UGent).14
J.-M. Jacquet合作论文数Institute of Informatics, University of Namur, Namur, Belgium5
Jacques Chassin De Kergommeaux合作论文数INPG ?? l'ENSIMAG5