2011 · 18 citations · 10 references
EngineeringVerificationSoftware SystemsSoftware EngineeringSource Code AnalysisSemantic WebSoftware AnalysisData ProvenanceInformation RetrievalData ScienceData MiningPattern RecognitionData IntegrationSoftware MiningSource CodeAutomated Provenance-similarity DetectionKnowledge DiscoveryComputer ScienceProvenance AnalysisStatic Program AnalysisSoftware DesignSoftware SecurityProgram AnalysisSoftware TestingProvenance ManagementMalware AnalystsMalware Analysis
Understanding, measuring, and leveraging the similarity of binaries (executable code) is a foundational challenge in software engineering. We present a notion of similarity based on provenance -- two binaries are similar if they are compiled from the same (or very similar) source code with the same (or similar) compilers. Empirical evidence suggests that provenance-similarity accounts for a significant portion of variation in existing binaries, particularly in malware. We propose and evaluate the applicability of classification to detect provenance-similarity. We evaluate a variety of classifiers, and different types of attributes and similarity labeling schemes, on two benchmarks derived from open-source software and malware respectively. We present encouraging results indicating that classification is a viable approach for automated provenance-similarity detection, and as an aid for malware analysts in particular.
10
Leo Breiman · Machine Learning · 2001 · 119.3K citations · Full text
Large-scale malware indexing using function-call graphs
Xin Hu, Tzi‐cker Chiueh, Kang G. Shin · 2009 · 314 citations
Detecting code clones in binary executables
Andreas Sæbjørnsen, Jeremiah Willcock, Thomas Panas et al. · 2009 · 171 citations
Graph-based comparison of Executable Objects
Thomas Dullien · 2005 · 133 citations