Results 1 -
1 of
1
Matching Global Data References in Related
"... Research and development efforts have recently compared malware variants. A number of these projects have focused on identifying functions through the use of signature-based classifiers. We introduce three new classifiers that characterize a function’s use of global data. Experiments on malware show ..."
Abstract
- Add to MetaCart
Research and development efforts have recently compared malware variants. A number of these projects have focused on identifying functions through the use of signature-based classifiers. We introduce three new classifiers that characterize a function’s use of global data. Experiments on malware show that we can meaningfully correlate functions on the basis of their global data references even when their functions share little code. We also present an algorithm that combines existing classifiers and our new ones into an ensemble for correlating functions in two binary programs. The resulting combined ensemble classifier dominates the previously reported classifiers.

