skip to main content
10.1145/2897795.2897796acmotherconferencesArticle/Chapter ViewAbstractPublication PagescisrcConference Proceedingsconference-collections
short-paper

Practical implications and requirements of diversifying interpreted languages

Published: 05 April 2016 Publication History

Abstract

Instruction set randomization (ISR) provides a strong defense against all types of injection attacks, especially in interpreted environments. However, fully enabling a system to benefit from language interpreters that support programs diversified with ISR requires several alterations and considerations. In this paper we identify core challenges related to enabling system-wide interpreter diversification. We also propose possible solutions to each challenge and expand upon the existing diversification schemes for interpreted languages.

References

[1]
Linux From Scratch. http://www.linuxfromscratch.org/lfs/. Version 7.8 Accessed: 2016-01-21.
[2]
Vulnerability summary for cve-2014-6271. https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-6271. Initial CVE of Shellshock vulnerability Accessed: 2016-01-21.
[3]
Elias Athanasopoulos, Antonis Krithinakis, and Evangelos P Markatos. An Architecture for Enforcing JavaScript Randomization in Web 2.0 Applications. In Information Security, pages 203--209. Springer, 2011.
[4]
S.W. Boyd, G.S. Kc, M.E. Locasto, and A.D. Keromytis. On the General Applicability of Instruction-Set Randomization. IEEE Transactions on Dependable and Secure Computing, 7(3), 2008.
[5]
G. Portokalidis and A.D. Keromytis. Global ISR: Toward a Comprehensive Defense Against Unauthorized Code Execution. In Moving Target Defense, Creating Asymmetric Uncertainty for Cyber Threats, Advances in Information Security 54, pages 469--480. Springer, 2014.
[6]
Joni Uitto, Sampsa Rauti, Jari-Matti Mäkelä, and Ville Leppänen. Preventing Malicious Attacks by Diversifying Linux Shell Commands. In Proceedings of the 14th Symposium on Programming Languages and Software Tools (SPLST), pages 206--220, 2015.

Cited By

View all
  • (2024)ARAYÜZ ÇEŞİTLENDİRMESİNİN KÖTÜ AMAÇLI YAZILIMLARDA KULLANIM DURUMUİstanbul Ticaret Üniversitesi Teknoloji ve Uygulamalı Bilimler Dergisi10.56809/icujtas.1410198Online publication date: 9-May-2024
  • (2020)Internal interface diversification as a method against malwareJournal of Cyber Security Technology10.1080/23742917.2020.1813397(1-26)Online publication date: 31-Aug-2020
  • (2018)Internal Interface Diversification as a Security Measure in Sensor NetworksJournal of Sensor and Actuator Networks10.3390/jsan70100127:1(12)Online publication date: 6-Mar-2018
  • Show More Cited By

Recommendations

Comments

Information & Contributors

Information

Published In

cover image ACM Other conferences
CISRC '16: Proceedings of the 11th Annual Cyber and Information Security Research Conference
April 2016
150 pages
ISBN:9781450337526
DOI:10.1145/2897795
Permission to make digital or hard copies of all or part of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for components of this work owned by others than ACM must be honored. Abstracting with credit is permitted. To copy otherwise, or republish, to post on servers or to redistribute to lists, requires prior specific permission and/or a fee. Request permissions from [email protected]

In-Cooperation

  • Oak Ridge National Laboratory

Publisher

Association for Computing Machinery

New York, NY, United States

Publication History

Published: 05 April 2016

Permissions

Request permissions for this article.

Check for updates

Author Tags

  1. Diversification
  2. Interpreted languages
  3. Software security

Qualifiers

  • Short-paper
  • Research
  • Refereed limited

Conference

CISRC '16

Acceptance Rates

CISRC '16 Paper Acceptance Rate 11 of 28 submissions, 39%;
Overall Acceptance Rate 69 of 136 submissions, 51%

Contributors

Other Metrics

Bibliometrics & Citations

Bibliometrics

Article Metrics

  • Downloads (Last 12 months)0
  • Downloads (Last 6 weeks)0
Reflects downloads up to 08 Mar 2025

Other Metrics

Citations

Cited By

View all
  • (2024)ARAYÜZ ÇEŞİTLENDİRMESİNİN KÖTÜ AMAÇLI YAZILIMLARDA KULLANIM DURUMUİstanbul Ticaret Üniversitesi Teknoloji ve Uygulamalı Bilimler Dergisi10.56809/icujtas.1410198Online publication date: 9-May-2024
  • (2020)Internal interface diversification as a method against malwareJournal of Cyber Security Technology10.1080/23742917.2020.1813397(1-26)Online publication date: 31-Aug-2020
  • (2018)Internal Interface Diversification as a Security Measure in Sensor NetworksJournal of Sensor and Actuator Networks10.3390/jsan70100127:1(12)Online publication date: 6-Mar-2018
  • (2016)An interface diversified honeypot for malware analysisProccedings of the 10th European Conference on Software Architecture Workshops10.1145/2993412.2993417(1-6)Online publication date: 28-Nov-2016
  • (2016)Applying Internal Interface Diversification to IoT Operating Systems2016 International Conference on Software Security and Assurance (ICSSA)10.1109/ICSSA.2016.7(1-5)Online publication date: Aug-2016

View Options

Login options

View options

PDF

View or Download as a PDF file.

PDF

eReader

View online with eReader.

eReader

Figures

Tables

Media

Share

Share

Share this Publication link

Share on social media