TY - GEN
T1 - Detecting binary theft via static major-path birthmarks
AU - Park, Seongsoo
AU - Kim, Hyunjun
AU - Kim, Jaeju
AU - Han, Hwansoo
N1 - Publisher Copyright:
© 2014 ACM.
PY - 2014/10/5
Y1 - 2014/10/5
N2 - Software birthmarks are used for detecting software plagiarism. For binaries, not many reliable birthmarks are developed. API sequences are known to be successful birthmarks, but dynamically extracted sequences are often too large and unnecessarily repetitive. In this paper, we propose a static approach to generate API sequences along major paths, which are analyzed from control flow graphs of binaries. Since our API sequences are extracted along the most plausible paths of the binary codes, they can represent actual API sequences from executing binaries, but in a more concise form. In addition, as it is a static analysis, we can apply to partial binary objects, which cannot be executed on their own. Our similarity measures use the Smith-Waterman algorithm that is one of the popular sequence alignment algorithms for DNA sequence analysis. We evaluate our static path-based API sequence with multiple versions of five applications. In our experiment, our method reports a quite reliable similarity result for binary codes.
AB - Software birthmarks are used for detecting software plagiarism. For binaries, not many reliable birthmarks are developed. API sequences are known to be successful birthmarks, but dynamically extracted sequences are often too large and unnecessarily repetitive. In this paper, we propose a static approach to generate API sequences along major paths, which are analyzed from control flow graphs of binaries. Since our API sequences are extracted along the most plausible paths of the binary codes, they can represent actual API sequences from executing binaries, but in a more concise form. In addition, as it is a static analysis, we can apply to partial binary objects, which cannot be executed on their own. Our similarity measures use the Smith-Waterman algorithm that is one of the popular sequence alignment algorithms for DNA sequence analysis. We evaluate our static path-based API sequence with multiple versions of five applications. In our experiment, our method reports a quite reliable similarity result for binary codes.
KW - Binary level similarity
KW - Birthmark
KW - Static major-path
UR - https://www.scopus.com/pages/publications/84910002688
U2 - 10.1145/2663761.2664191
DO - 10.1145/2663761.2664191
M3 - Conference contribution
AN - SCOPUS:84910002688
T3 - Proceedings of the 2014 Research in Adaptive and Convergent Systems, RACS 2014
SP - 224
EP - 229
BT - Proceedings of the 2014 Research in Adaptive and Convergent Systems, RACS 2014
PB - Association for Computing Machinery
T2 - 2014 Conference on Research in Adaptive and Convergent Systems, RACS 2014
Y2 - 5 October 2014 through 8 October 2014
ER -