A method of searching for similar code sequences in executable binary files using a featureless approach

Автор: Yumaganov Alexander Sergeevich, Myasnikov Vladislav Valerievich

Журнал: Компьютерная оптика @computer-optics

Рубрика: Численные методы и анализ данных

Статья в выпуске: 5 т.41, 2017 года.

Бесплатный доступ

The work is devoted to solving a problem of searching for similar code sequences in executable binary files. The proposed method involves partitioning the processor instructions into functional groups, forming a given function’s primary description by commands position in its body, followed by generating the function’s intermediate description through its comparison with the functions from a "base" library. With the dimensionality of the resulting vector reduced in this way, the resulting final description is then used to perform the search. Results of the experimental study demonstrate the operability of the proposed method. The efficiency of the proposed method is compared against existing methods of searching for similar code sequences. We also provide recommendations on the choice of parameters of the developed method.

Еще

Searching, code sequence, featureless recognition

Короткий адрес: https://sciup.org/140228768

IDR: 140228768   |   DOI: 10.18287/2412-6179-2017-41-5-756-764

Статья научная