Cybersecurity (Apr 2020)

Layered obfuscation: a taxonomy of software obfuscation techniques for layered security

  • Hui Xu,
  • Yangfan Zhou,
  • Jiang Ming,
  • Michael Lyu

DOI
https://doi.org/10.1186/s42400-020-00049-3
Journal volume & issue
Vol. 3, no. 1
pp. 1 – 18

Abstract

Read online

Abstract Software obfuscation has been developed for over 30 years. A problem always confusing the communities is what security strength the technique can achieve. Nowadays, this problem becomes even harder as the software economy becomes more diversified. Inspired by the classic idea of layered security for risk management, we propose layered obfuscation as a promising way to realize reliable software obfuscation. Our concept is based on the fact that real-world software is usually complicated. Merely applying one or several obfuscation approaches in an ad-hoc way cannot achieve good obscurity. Layered obfuscation, on the other hand, aims to mitigate the risks of reverse software engineering by integrating different obfuscation techniques as a whole solution. In the paper, we conduct a systematic review of existing obfuscation techniques based on the idea of layered obfuscation and develop a novel taxonomy of obfuscation techniques. Following our taxonomy hierarchy, the obfuscation strategies under different branches are orthogonal to each other. In this way, it can assist developers in choosing obfuscation techniques and designing layered obfuscation solutions based on their specific requirements.

Keywords