Title :
Web server protection by customized instruction set encoding
Author :
Fechner, Bernhard ; Keller, Jörg ; Wohlfeld, Andreas
Author_Institution :
Fern Univ., Hagen, Germany
Abstract :
We present a novel technique to secure the execution of a processor against the execution of malicious code (trojans, viruses). The main idea is to permute parts of the opcode values so that it gets a different semantic meaning. A virus which does not know the permutation is not able to execute and will cause a failure such as segmentation violation, whereby the execution of malicious code is prevented. The permutation is realized by a lookup table. We develop several variants that require only small changes to microprocessors. We sketch how to bootstrap a system such that all intended applications (including operating system) are reversely permuted, and can execute as intended. While this will be cumbersome for typical personal computers, it will work for Web servers, because the number of applications and frequency of installation is lower. Furthermore, Web servers are particularly endangered: they cannot be protected as good as personal computers, because by the very nature of their duty they are more openly connected with the Internet than any other computer in an organization´s network.
Keywords :
Internet; computer bootstrapping; computer viruses; instruction sets; Internet; Web server protection; customized instruction set encoding; lookup table; malicious code; opcode values; segmentation violation; trojans; viruses; Application software; Encoding; Frequency; Microcomputers; Microprocessors; Operating systems; Protection; Table lookup; Viruses (medical); Web server;
Conference_Titel :
Parallel and Distributed Processing Symposium, 2006. IPDPS 2006. 20th International
Print_ISBN :
1-4244-0054-6
DOI :
10.1109/IPDPS.2006.1639665