首页> 外文期刊>ACM Transaction on Information and System Security >FOSSIL: A Resilient and Efficient System for Identifying FOSS Functions in Malware Binaries
【24h】

FOSSIL: A Resilient and Efficient System for Identifying FOSS Functions in Malware Binaries

机译:FOSSIL:一种可识别恶意软件二进制文件中的FOSS功能的弹性高效系统

获取原文
获取原文并翻译 | 示例

摘要

Identifying free open-source software (FOSS) packages on binaries when the source code is unavailable is important for many security applications, such as malware detection, software infringement, and digital forensics. This capability enhances both the accuracy and the efficiency of reverse engineering tasks by avoiding false correlations between irrelevant code bases. Although the FOSS package identification problem belongs to the field of software engineering, conventional approaches rely strongly on practical methods in data mining and database searching. However, various challenges in the use of these methods prevent existing function identification approaches from being effective in the absence of source code. To make matters worse, the introduction of obfuscation techniques, the use of different compilers and compilation settings, and software refactoring techniques has made the automated detection of FOSS packages increasingly difficult. With very few exceptions, the existing systems are not resilient to such techniques, and the exceptions are not sufficiently efficient.
机译:当源代码不可用时,识别二进制文件上的免费开源软件(FOSS)软件包对于许多安全应用程序非常重要,例如恶意软件检测,软件侵权和数字取证。通过避免不相关的代码库之间的错误关联,此功能提高了逆向工程任务的准确性和效率。尽管FOSS软件包识别问题属于软件工程领域,但是常规方法在数据挖掘和数据库搜索中仍然强烈依赖于实用方法。但是,使用这些方法的各种挑战使现有的功能识别方法无法在没有源代码的情况下有效。更糟的是,混淆技术的引入,不同编译器和编译设置的使用以及软件重构技术使FOSS软件包的自动检测变得越来越困难。除极少数例外外,现有系统对此类技术均无弹性,且例外效率不足。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号