Original Post
Some weeks ago I was discussing with a few friends about whether or not it was possible to secure a completely open source game (an FPS specifically) against cheating. I'll focus this discussion on FPSes because they are historically the most cheat-infested and because they offer up a number of interesting challenges in ways that people can cheat. When I asy "completely" open source, I mean that no closed source components are allowed. We cn't rely on a magic closed source black box like PunkBuster to fix things for us. Now source code merely facilitates seeing the behavior of a program, but it makes what might be an eventual achievement on the part of a reverse engineer doable almost immediately. First, let's quickly take a look at the ways people have historically cheated. Wallhacks are one that are fairly striaghtforward; for games built on the HL1 engine for example, the OpenGL dll can be trivially hooked -- a few tweaks to rendering modes, and suddenly players are visible through walls. Another simple kind is to ues custom models, particularly simple with games that are built to be moddable. Simply use a player model which is larger than normal (a "spike" model for example) and hiding in weird corner spots becomes ineffective. Another thing that's been done on occasion is to use hacked video or mouse drivers to gain an advantage; these methods are less relable but largely undetectable. The most powerful and most complex hacks are highly intrusive, going directly into the process memory, interloping in-between game dlls, or otherwise dipping deeply into the system to control and rewire it. The usual approach to preventing these measures has been to use client side code, either as part of the game itself or as a seperate process, that attempts to detect these hacks. Scanning for video DLLs in non-standard directories, signatures of known evil processes in memory, seeing if a sketchy "debugger" has attached to your game, or looking for weird system-wide hooks. Many of these methods are largely reactive, since they rely on known evil signatures, not unlike a virus scanner. A quick look at games nowadays makes it clear that these methods are of limited effectiveness, as it's a constant fight between the game developers trying to detect evil programs and the hackers trying to evade detection. Open source makes this a basically useless approach, since your scanning methods are easy to see and thus blocked without that much difficulty. (For example, memory scans can be deftly cut down with clever virtual allocations and tweaking of page access permissions.) We can't even checksum anything, because our checksumming code is open source and we can't guarantee that it's doing what it's supposed to and not simply returning what it already knows are the correct results. Without getting deeper into that discussion, suffice to say that it is impossible to completely prevent cheating without resorting to psychotic measures like RSA encrypting every frame on the server, sending it to the client, allowing only trusted drivers, etc. Even then it might not be possible (theoretically speaking) to guarantee that the player is not cheating without using a TPM. The approach up to this point has been to make cheating a general pain, and that's worked to some extent but not really. If you know where to look, a cheat for any of the popular FPSes can be picked up easily. So if the situation is hopeless, why am I posting? Well, when I originally discussed this with my friends, one of whom is a specialist in this sort of security, we couldn't figure out any kind of client-side undefeatable system, and the truth is that there probably isn't, and you can probably prove that there isn't. You guessed it, we move to the server side of things. The key point is this -- we only need to identify a cheater and ban his ass; it's not necesary to make it impossible to cheat. The server is open source too, so technically there's no reason somebody can't modify the server to allow cheating. But since the server sets the rules to begin with, that's not a problem. What we need to do is to detect all forms of cheating on the server. I believe this is possible and reasonable to do, although it's likely to be somewhat CPU intensive on the server. Enter HackCam. The idea is that the server has at least as much information as any client has. Obviously some of this information wil be difficult to get (we can't afford to render every client's screen on the server and run image analysis on every frame, for example). However, the server should be able to do at least enough analysis to throw out obvious cheaters, and the discussions I've read of HackCam indicate that it is fairly good at identifying cheaters even amongst pro-class players. If we have a level where a considerable amount of visibility precalculation has been done, then the server could conceivably run very fast queries as to whether or not it is possible that one player knows the presence of another. Certain behaviors can then be identified as suspicious, and we can mark players who accumulate a lot of suspicious activity with some kind of likelihood of cheating. (Bayesian techniques might assist accuracy as well.) Speedhacks are easy to catch. Wallhacks are more difficult, but the HackCam interview suggests that it's entirely in the realm of possibility. Examination of a player's behavior could also identify use of aimbots and the like. I don't have the AI background to know how much of this is possible, but the things I've heard and see about HackCam are very heartening. It turns out that we get a number of interesting benefits from this kind of analysis, rather than simply attacking the programs involved in cheating. For one thing, players are now allowed to modify any part of the game code, including the rendering system. I can write up a new shader for players or walls or whatever and use it, and as long as the shader doesn't cause me to be able to see things I shouldn't, it's perfectly alright. Also, a few oddball brands of cheats can now be picked up. The one that comes to mind is "ghosting", the process of using out-of-game voice-chat and a spectating and/or dead teammate to give you extra information about what is going on. We're no longer reacting to cheats that appear; instead of blacklisting the illegitimate, we are whitelisting the legitimate. There are disadvantages as well, of course. For one thing, implementing this kind of an intelligent analysis system is probably not easy. There's a fair bit of temporal information required, and the player needs to get the benefit of the doubt in all cases. We have to deal with crazy cases where the player may not have been cheating. For example, the case of the rifle barrel stick out past the end of the box is going to be difficult to detect, but the case where the rifle barrel was sticking through is going to be a hell of a lot more irritating. Also, this method is likely to only catch the outright cheaters; people who are using more subtle configurations (an aimbot with a visibility of 2 degrees, for example) are going to be difficult or impossible to seperate from the legitimate players. So, as far as replies from you guys go I'm looking for a couple different things. If you want to challenge me and say that client side prevention is possible, go right ahead -- I'll enjoy tearing you apart [grin] I was quite irritated with the prospect that cheating might actually be literally, provably impossible to prevent, and server side heuristic analysis provides what seems to be a way out, though again I don't know how challenging it will be to implement or how well it will do in practice. If anyone's attempted something like this bfore, I'd love to hear about it. In the end, I just want something interesting to read and ponder on as a response to this thread/rant [smile]