کد مقاله کد نشریه سال انتشار مقاله انگلیسی نسخه تمام متن
459111 696228 2009 12 صفحه PDF دانلود رایگان
عنوان انگلیسی مقاله ISI
A static API birthmark for Windows binary executables
موضوعات مرتبط
مهندسی و علوم پایه مهندسی کامپیوتر شبکه های کامپیوتری و ارتباطات
پیش نمایش صفحه اول مقاله
A static API birthmark for Windows binary executables
چکیده انگلیسی

A software birthmark is the inherent characteristics of a program extracted from the program itself. By comparing birthmarks, we can detect whether a program is a copy of another program or not. We propose a static API birthmark for Windows executables that utilizes sets of API calls identified by a disassembler statically. By comparing 49 Windows executables, we show that our birthmark can distinguish similar programs and detect copies. By comparing binaries generated by various compilers, we also demonstrate that our birthmark is resilient. We compare our birthmark with a previous Windows dynamic birthmark to show that it is more appropriate for GUI applications.

ناشر
Database: Elsevier - ScienceDirect (ساینس دایرکت)
Journal: Journal of Systems and Software - Volume 82, Issue 5, May 2009, Pages 862–873
نویسندگان
, , , ,