论文标题

末端软件保护作为风险分析过程

Man-at-the-End Software Protection as a Risk Analysis Process

论文作者

Canavese, Daniele, Regano, Leonardo, Basile, Cataldo, Coppens, Bart, De Sutter, Bjorn

论文摘要

在过去的几年中,对软件应用程序的数量和严重性都增加了末端(伴侣)攻击。但是,MATE软件保护措施以模糊概念和技术为主导,在该领域中,安全性无处不在。本文介绍了根据NIST SP800-39方法采用和标准化软件作为风险管理过程的理由。我们研究了在Mate软件保护的背景下,在此过程中正式化和自动化活动的相关方面。我们强调了研究界仍必须解决的开放问题。我们讨论了这种方法可以给所有利益相关者带来的好处。此外,我们提供了决策支持系统的概念证明(POC),该系统在风险分析方法中自动化了许多活动,以保护软件应用程序。尽管仍然是原型,但与行业专家的POC验证表明,拟议的风险管理过程的几个方面已经可以正式化并使用我们现有的工具箱自动化,并且它实际上可以帮助在工业相关的环境中做出决策

The last years have seen an increase of Man-at-the-End (MATE) attacks against software applications, both in number and severity. However, MATE software protections are dominated by fuzzy concepts and techniques, with security-through-obscurity omnipresent in the field. This paper presents a rationale for adopting and standardizing the protection of software as a risk management process according to the NIST SP800-39 approach. We examine the relevant aspects of formalizing and automating the activities in this process in the context of MATE software protection. We highlight the open issues that the research community still has to address. We discuss the benefits that such an approach can bring to all stakeholders. In addition, we present a Proof of Concept (PoC) of a decision support system that automates many activities in the risk analysis methodology towards the protection of software applications. Despite still being a prototype, the PoC validation with industry experts indicated that several aspects of the proposed risk management process can already be formalized and automated with our existing toolbox, and that it can actually assist decision making in industrially relevant settings

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源