Forensic Malware Analysis: The Value of Fuzzy Hashing Algorithms in Identifying Similarities
Nikolaos Sarantinos, Chafika Benzaïd, Omar Arabiat, Ameer Al-Nemrat · 2016
This research aims to examine the effectiveness and efficiency of fuzzing hashing algorithm in the identification of similarities in Malware Analysis. More precisely, it will present the benefit of using fuzzy hashing algorithms, such as ssdeep, sdhash, mvHash and mrsh - v2, in identifying similarities in Malware domain. The obtained results will be compared with the traditional and most common Cryptographic Hashes, such as the MD5, SHA-1 and SHA-256. Furthermore, it will highlight the pros and cons of fuzzy and cryptographic hashing, as well as their adoption in real world applications.