Helix++: A platform for efficiently securing software

التفاصيل البيبلوغرافية
العنوان: Helix++: A platform for efficiently securing software
المؤلفون: Davidson, Jack W., Hiser, Jason D., Nguyen-Tuong, Anh
سنة النشر: 2023
المجموعة: Computer Science
مصطلحات موضوعية: Computer Science - Cryptography and Security, Computer Science - Software Engineering, D.2.m
الوصف: The open-source Helix++ project improves the security posture of computing platforms by applying cutting-edge cybersecurity techniques to diversify and harden software automatically. A distinguishing feature of Helix++ is that it does not require source code or build artifacts; it operates directly on software in binary form--even stripped executables and libraries. This feature is key as rebuilding applications from source is a time-consuming and often frustrating process. Diversification breaks the software monoculture and makes attacks harder to execute as information needed for a successful attack will have changed unpredictably. Diversification also forces attackers to customize an attack for each target instead of attackers crafting an exploit that works reliably on all similarly configured targets. Hardening directly targets key attack classes. The combination of diversity and hardening provides defense-in-depth, as well as a moving target defense, to secure the Nation's cyber infrastructure.
Comment: 4 pages, 1 figure, white paper
نوع الوثيقة: Working Paper
URL الوصول: http://arxiv.org/abs/2304.04846
رقم الأكسشن: edsarx.2304.04846
قاعدة البيانات: arXiv