Detailed Information

Cited 0 time in webofscience Cited 0 time in scopus
Metadata Downloads

Function matching-based binary-level software similarity calculation

Authors
Lee, Yeo ReumKang, BooJoongIm, Eul Gyu
Issue Date
Oct-2013
Publisher
Association for Computing Machinary, Inc.
Keywords
binary analysis; call graph; function matching; malware; N-gram; software similarity; static analysis
Citation
Proceedings of the 2013 Research in Adaptive and Convergent Systems, RACS 2013, pp.322 - 327
Indexed
SCOPUS
Journal Title
Proceedings of the 2013 Research in Adaptive and Convergent Systems, RACS 2013
Start Page
322
End Page
327
URI
https://scholarworks.bwise.kr/hanyang/handle/2021.sw.hanyang/161783
DOI
10.1145/2513228.2513300
ISSN
0000-0000
Abstract
This paper proposes a method to calculate similarities of software without any source code information. The proposed method can be used for various applications such as detecting the source code theft and copyright infringement, as well as locating updated parts of software including malware. To determine the similarities of software, we used an approach that matches similar functions included in software. Our function-based matching process is composed of two steps. In step 1, the structural information of call graph in binary file is used to match functions, and the matched functions are not processed in step 2 to reduce the number of detailed matching. In step 2, by using instruction mnemonics, N-gram similarity-based matching is performed. Using the structural matching proposed in this paper, about 30% improvement in the matching performance is achieved with the four-tuple matching which also reduces the false positive rate compared to previous studies. Our other experimental results showed that, in comparison to source code-based approaches, our proposed method has only about 3% difference in similarity calculation with real software samples. Therefore, we argue that our proposed method makes a contribution in the field of binary-based software similarity calculation.
Files in This Item
Go to Link
Appears in
Collections
서울 공과대학 > 서울 컴퓨터소프트웨어학부 > 1. Journal Articles

qrcode

Items in ScholarWorks are protected by copyright, with all rights reserved, unless otherwise indicated.

Related Researcher

Researcher Im, Eul Gyu photo

Im, Eul Gyu
COLLEGE OF ENGINEERING (SCHOOL OF COMPUTER SCIENCE)
Read more

Altmetrics

Total Views & Downloads

BROWSE