Achieving consistency of software updates against strong attackers

Abdullah L, Hahn S, Freiling F (2019)


Publication Type: Conference contribution

Publication year: 2019

Publisher: Association for Computing Machinery

Conference Proceedings Title: ACM International Conference Proceeding Series

Event location: Munich DE

ISBN: 9781450372961

DOI: 10.1145/3360664.3360670

Abstract

Update systems regularly distribute updates for installed software to end users. Problems arise when the update system is misused and malicious updates are sent to a small set of users only. Such situations can occur if the software supplier has been successfully attacked or is coerced by government agencies to distribute handcrafted updates containing promiscuous functionality like backdoors. In this paper, we define a set of general security requirements for update systems that encompass protection against malicious updates. We then introduce the design of an update system that satisfies the requirements and present an implementation as an extension to the advanced package tool (APT) for the Debian OS. We evaluate the strengths and weaknesses of the system and discuss its large-scale applicability with respect to security and performance overhead.

Authors with CRIS profile

How to cite

APA:

Abdullah, L., Hahn, S., & Freiling, F. (2019). Achieving consistency of software updates against strong attackers. In ACM International Conference Proceeding Series. Munich, DE: Association for Computing Machinery.

MLA:

Abdullah, Lamya, Sebastian Hahn, and Felix Freiling. "Achieving consistency of software updates against strong attackers." Proceedings of the 3rd Central European Cybersecurity Conference, CECC 2019, Munich Association for Computing Machinery, 2019.

BibTeX: Download