Evidence on the effectiveness of ManMachine-At-The-End (MATE) software protections, such as code obfuscation, has mainly come from limited empirical research. Recently, however, a meta-model and an automatable method waswere proposed to obtain statistical models of the required effort to attack (protected) software. The proposed method was sketched for a number of attack strategies but not instantiated, evaluated, or validated for those that require human interaction with the attacked software. In this paper, we present an fullend-to-end instantiation, formalisation, implementation, and validation of thethat existing meta-model and method to obtain statistical effort models for game resource localisation attacks, which represent a major step towards creating game cheats, a prime example of MATE attacks. We discuss in detail all relevant aspects of our instantiation and the results obtained for two game use cases. Our results confirm the feasibility of the proposedexisting meta-model and method, and itstheir utility for decision support for users of software protection tools. These results open up a new avenue for obtaining models of the impact of software protections on reverse engineering attacks, which will scale much better than empirical research involving human participants.
Statistical effort modelling of game resource localisation attacks
Sanna A.Co-primo
;Regano L.
;Maiorca D.;
2026-01-01
Abstract
Evidence on the effectiveness of ManMachine-At-The-End (MATE) software protections, such as code obfuscation, has mainly come from limited empirical research. Recently, however, a meta-model and an automatable method waswere proposed to obtain statistical models of the required effort to attack (protected) software. The proposed method was sketched for a number of attack strategies but not instantiated, evaluated, or validated for those that require human interaction with the attacked software. In this paper, we present an fullend-to-end instantiation, formalisation, implementation, and validation of thethat existing meta-model and method to obtain statistical effort models for game resource localisation attacks, which represent a major step towards creating game cheats, a prime example of MATE attacks. We discuss in detail all relevant aspects of our instantiation and the results obtained for two game use cases. Our results confirm the feasibility of the proposedexisting meta-model and method, and itstheir utility for decision support for users of software protection tools. These results open up a new avenue for obtaining models of the impact of software protections on reverse engineering attacks, which will scale much better than empirical research involving human participants.I metadati presenti in IRIS UNICA sono rilasciati con licenza Creative Commons CC0 1.0 Universal, mentre i file delle pubblicazioni sono protetti da diritto d'autore, salvo diversa indicazione.



