欢迎访问中国科学院大学学报,今天是
论文

一种基于自修改代码技术的软件保护方法

  • 王祥根 ,
  • 司端锋 ,
  • 冯登国 ,
  • 苏璞睿
展开
  • 1. 中国科学技术大学电子工程与信息科学系,合肥 230027;
    2. 中国科学院软件研究所信息安全国家重点实验室,?北京 100190;
    3. 信息安全共性技术国家工程研究中心,北京 100190

收稿日期: 2009-02-13

  修回日期: 2009-04-24

  网络出版日期: 2009-09-15

基金资助

国家自然科学基金项目(60703076)和国家"863"高技术研究发展计划项目(2006AA01Z412,2007AA01Z451)资助 

Software protection method based on self-modification mechanism

  • WANG Xiang-Gen ,
  • SI Duan-Feng ,
  • FENG Deng-Guo ,
  • SU Pu-Rui
Expand
  • 1. Department of Electronic Engineering and Information Science, University of Science and Technology of China, Hefei 230027, China;
    2. State Key Laboratory of Information Security, Institute of Software, Chinese Academy of Sciences, Beijing 100190, China;
    3. National Engineering Research Center for Information Security, Beijing 100190, China

Received date: 2009-02-13

  Revised date: 2009-04-24

  Online published: 2009-09-15

摘要

提出一种基于自修改代码(SMC)技术的软件保护方法,该方法通过将关键代码转换为数据存储在原程序中,以隐藏关键代码;受保护的可执行文件执行过程中,通过修改进程中存储有隐藏代码的虚拟内存页面属性为可执行,实现数据到可执行代码的转换. 实验证明,此软件保护方法简单,易实现,可以有效提高SMC的抗逆向分析能力.

本文引用格式

王祥根 , 司端锋 , 冯登国 , 苏璞睿 . 一种基于自修改代码技术的软件保护方法[J]. 中国科学院大学学报, 2009 , 26(5) : 688 -694 . DOI: 10.7523/j.issn.2095-6134.2009.5.015

Abstract

In this paper, we present a new method based on self-modification mechanism to protect softwares against illegal acts of hacking. The key idea is to converse key codes into data in the original program so as to make programs harder to analyze correctly. Then, we translate data to executable codes by enabling the virtual memory page which stores the hidden code to be executable at run-time. Our experiments demonstrate that the method is practical and efficient.

参考文献


[1] Yuichiro K, Akito M, Masahide N, et al. Exploiting self-modification mechanism for program protection //Proceedings of the 27th Annual International Computer Software and Applications Conference. Washington, DC, USA: IEEE Computer Society, 2003: 170-181.

[2] Yuichiro K, Akito M, Masahide N, et al. A software protection method based on instruction camouflage //Electronics and Communications in Japan (Part 3). Wiley Publishers, 2006, 89(1): 47-59.

[3] Yuichiro K, Akito M, Masahide N, et al. Program camouflage: a systematic instruction hiding method for protecting secrets //Proceedings of World Congress on Science, Engineering and Technology. Heidelberg, Germany: WASET, 2008, 33: 557-563.

[4] Linn C, Debray S. Obfuscation of executable code to improve resistance to static disassembly //Jajodia S, Atluri V, Jaeger T(eds). Proceedings of the 10th ACM Conference on Computer and Communications Security (CCS 2003). New York: ACM, 2003: 290-299.

[5] Madou M, Anckaert B, Moseley P, et al. Software protection through dynamic code mutation //Proceedings of the 6th International Workshop on Information Security Applications. Springer Berlin:Heidelberg, 2005, 3786: 194-206.

[6] Royal P, Halpin M, Dagon D, et al. PolyUnpack: Automating the hidden-code extraction of unpack-executing malware //Proceedings of the 22nd Annual Computer Security Applications Conference on Annual Computer Security Applications Conference (ACSAC ’06). Washington, DC, USA: IEEE Computer Society, 2006: 289-300.

[7] Kang M, Poosankam P, Yin H. Renovo: A hidden code extractor for packed executables //Proceedings of the 5th ACM Workshop on Recurring Malcode (WORM 2007). New York: ACM, 2007: 46-53.

[8] Wu Y D, Zhao Z G, Chui T W. An attack on SMC-based software protection //Proceedings of the International Conference on Computational Science 2006 (ICCS 2006). Springer Berlin:Heidelberg, 2006, 4307: 352-368.

文章导航

/