Automatic Selection of Protections to Mitigate Risks Against Software Applications

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Canavese, Daniele, Regano, Leonardo, De Sutter, Bjorn, Basile, Cataldo
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866910235428388864
author Canavese, Daniele
Regano, Leonardo
De Sutter, Bjorn
Basile, Cataldo
author_facet Canavese, Daniele
Regano, Leonardo
De Sutter, Bjorn
Basile, Cataldo
contents This paper introduces a novel approach for the automated selection of software protections to mitigate MATE risks against critical assets within software applications. We formalize the key elements involved in protection decision-making - including code artifacts, assets, security requirements, attacks, and software protections - and frame the protection process through a game-theoretic model. In this model, a defender strategically applies protections to various code artifacts of a target application, anticipating repeated attack attempts by adversaries against the confidentiality and integrity of the application's assets. The selection of the optimal defense maximizes resistance to attacks while ensuring the application remains usable by constraining the overhead introduced by protections. The game is solved through a heuristic based on a mini-max depth-first exploration strategy, augmented with dynamic programming optimizations for improved efficiency. Central to our formulation is the introduction of the Software Protection Index, an original contribution that extends existing notions of potency and resilience by evaluating protection effectiveness against attack paths using software metrics and expert assessments. We validate our approach through a proof-of-concept implementation and expert evaluations, demonstrating that automated software protection is a practical and effective solution for risk mitigation in software.
format Preprint
id arxiv_https___arxiv_org_abs_2506_18470
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Automatic Selection of Protections to Mitigate Risks Against Software Applications
Canavese, Daniele
Regano, Leonardo
De Sutter, Bjorn
Basile, Cataldo
Cryptography and Security
Software Engineering
This paper introduces a novel approach for the automated selection of software protections to mitigate MATE risks against critical assets within software applications. We formalize the key elements involved in protection decision-making - including code artifacts, assets, security requirements, attacks, and software protections - and frame the protection process through a game-theoretic model. In this model, a defender strategically applies protections to various code artifacts of a target application, anticipating repeated attack attempts by adversaries against the confidentiality and integrity of the application's assets. The selection of the optimal defense maximizes resistance to attacks while ensuring the application remains usable by constraining the overhead introduced by protections. The game is solved through a heuristic based on a mini-max depth-first exploration strategy, augmented with dynamic programming optimizations for improved efficiency. Central to our formulation is the introduction of the Software Protection Index, an original contribution that extends existing notions of potency and resilience by evaluating protection effectiveness against attack paths using software metrics and expert assessments. We validate our approach through a proof-of-concept implementation and expert evaluations, demonstrating that automated software protection is a practical and effective solution for risk mitigation in software.
title Automatic Selection of Protections to Mitigate Risks Against Software Applications
topic Cryptography and Security
Software Engineering
url https://arxiv.org/abs/2506.18470