ANALYZING THE EFFECTIVENESS OF SOFTWARE DIVERSITY FOR SYSTEM SECURITY

Han Jin,Zang Binyu
DOI: https://doi.org/10.3969/j.issn.1000-386X.2010.09.086
2010-01-01
Abstract:Principal working theory of mainstream intrusion detection system is that to compare the outcomes of two softwares with similar functions when tackling the same input and to determine one of them has or has not been intruded by malicious software based on the differences of their outcomes.When these replicas are constructed using off-the-shelf software products,it is assumed that they are sufficiently diverse and will not be compromised simultaneously under the attack from same malicious software.In this paper,we analyzed 6000 or more vulnerabilities published in 2007 to evaluate the validity of this assumption.Analytical results demonstrate that about 98% or more application software with same functions can be used to form the intrusion detection system of such kind effectively,and almost half of these applications can be run on multiple operating system platform simultaneously for improving system security effectually.
What problem does this paper attempt to address?