首页 | 本学科首页   官方微博 | 高级检索  
     

二进制文件同源性检测的结构化相似度计算
引用本文:刘春红,郭涛,崔宝江,王建新.二进制文件同源性检测的结构化相似度计算[J].北京邮电大学学报,2012,35(3):56-60.
作者姓名:刘春红  郭涛  崔宝江  王建新
作者单位:河南师范大学计算机与信息技术学院,河南新乡,453007;中国信息安全测评中心,北京,100085;北京邮电大学计算机学院,北京,100876;北京林业大学信息学院,北京,100083
摘    要:提出了一种利用二进制文件的结构化信息进行软件同源性相似度计算的方法.针对克隆软件的特点,设计了基本块签名,在文件-函数-基本块的层次化结构基础上,构建了基于基本块属性和结构化信息的基本块相似度度量,利用函数的结构化信息构建函数权重计算文件相似度,来衡量原文件和目标文件的同源性.针对常见克隆手段进行测试,对所提出的加权相似度算法与不加权算法、主流二进制比对工具的检测结果进行对比.结果表明,加权方法能更准确地衡量出2个文件的相似程度.

关 键 词:二进制文件  同源性检测  结构化签名  权重
收稿时间:2011-08-14

Similarity Computation for Executable Objects Homology Detection Based on Structural Signature
LIU Chun-hong , GUO Tao , CUI Bao-jiang , WANG Jian-xin.Similarity Computation for Executable Objects Homology Detection Based on Structural Signature[J].Journal of Beijing University of Posts and Telecommunications,2012,35(3):56-60.
Authors:LIU Chun-hong  GUO Tao  CUI Bao-jiang  WANG Jian-xin
Affiliation:1College of Computer and Information Technology, Henan Normal University, Henan Xinxiang 453007, China;2School of Computer Science and Technology, Beijing University of Posts and Telecommunications, Beijing 100876, China;3China Information Technology Security Evaluation Center, Beijing 100085, China; 4School of Information of Science and Technology, Beijing Forestry University, Beijing 100083, China
Abstract:A method of similarity computation for executable objects homology detection based on structural signature was proposed.At first step,considering the characteristic of clone code,a signature of basic code block was designed.On the basis of the hierarchical structure of file-function-basic code block,similarity measurement of basic code block was built based on its basic properties and structural information.At second step,to evaluate the homology between original and object files,the similarity was calculated through constructing function weight by means of function structural information.Aiming at the most common clone patterns,some experiments were conducted between the proposed method,the method without considering weight and some mainstream similarity detection tools.Comparative results demonstrate that the proposed method can measure the similarity of two executable objects more accurately than other methods.
Keywords:executable objects  homologous detection  structural signature  weight
本文献已被 CNKI 万方数据 等数据库收录!
点击此处可从《北京邮电大学学报》浏览原始摘要信息
点击此处可从《北京邮电大学学报》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号