Graph-based comparison of Executable Objects

Thomas Dullien · 2005

Résumé A method to construct an optimal isomorphism between the sets of instructions, sets of basic blocks and sets of functions in two differing but similar executables is presented. This isomorphism can be used for porting recovered information between different disassemblies, recover changes made by security updates and detect code theft. The most interesting applications in the realm of security are in malware analysis where the analysis of a family of trojans or viruses can be reduced to analyzing the differences between the variants, and in recovering the details of fixed vulnerabilities when the vendor of the security patch refuses to disclose details. A framework implementing the described methods is presented, along with empirical data about it’s performance when analyzing multiple variants of the same malware and recovering vulnerability details from security updates. 1

Read the paper · More papers on PaperTik