Internal Interface Diversification with Multiple Fake Interfaces

dc.contributor.authorRauti Sampsa
dc.contributor.authorLeppänen Ville
dc.contributor.organizationfi=ohjelmistotekniikka|en=Software Engineering|
dc.contributor.organization-code1.2.246.10.2458963.20.71310837563
dc.converis.publication-id28651179
dc.converis.urlhttps://research.utu.fi/converis/portal/Publication/28651179
dc.date.accessioned2022-10-28T12:47:18Z
dc.date.available2022-10-28T12:47:18Z
dc.description.abstract<p>Malware uses knowledge of well-known interfaces to achieve<br />its goals. However, if we uniquely diversify these interfaces<br />in each system, the malware no longer knows the ”language”<br />of a specific system and it becomes much more difficult for<br />malicious programs to operate. This paper extends the idea<br />of interface diversification by presenting a scheme where a<br />fake original interface and multiple other fake interfaces are<br />provided along with the valid interface in order to log the<br />suspicious activity in the system and possibly deceive malware<br />by initiating fallacious interaction with it. We also<br />present a proof-of-concept implementation of this scheme in<br />Linux environment and conduct experiments with it.<br /></p>
dc.format.pagerange245
dc.format.pagerange250
dc.identifier.isbn978-1-4503-5303-8
dc.identifier.olddbid178973
dc.identifier.oldhandle10024/162067
dc.identifier.urihttps://www.utupub.fi/handle/11111/30794
dc.identifier.urnURN:NBN:fi-fe2021042718081
dc.language.isoen
dc.okm.affiliatedauthorRauti, Sampsa
dc.okm.affiliatedauthorLeppänen, Ville
dc.okm.discipline113 Computer and information sciencesen_GB
dc.okm.discipline113 Tietojenkäsittely ja informaatiotieteetfi_FI
dc.okm.internationalcopublicationnot an international co-publication
dc.okm.internationalityInternational publication
dc.okm.typeA4 Conference Article
dc.publisher.countryUnited Statesen_GB
dc.publisher.countryYhdysvallat (USA)fi_FI
dc.publisher.country-codeUS
dc.publisher.placeNew York, NY
dc.relation.conferenceInternational Conference on Security of Information and Networks
dc.relation.doi10.1145/3136825.3136900
dc.relation.ispartofseriesACM International Conference Proceedings Series
dc.source.identifierhttps://www.utupub.fi/handle/10024/162067
dc.titleInternal Interface Diversification with Multiple Fake Interfaces
dc.title.bookSIN '17 Proceedings of the 10th International Conference on Security of Information and Networks
dc.year.issued2017

Tiedostot

Näytetään 1 - 1 / 1
Ladataan...
Name:
Multiple_fake_interfaces.pdf
Size:
183.61 KB
Format:
Adobe Portable Document Format
Description:
Final draft