Entropy-Driven Visualization in GView: Unveiling the Unknown in Binary File Formats

Andrada-Livia Antoneac, Gheorghiţă Mutu, Dragoş-Teodor Gavriluţ · 2024

The number of known malicious samples has increased exponentially in the last decade, making it more complicated for a security researcher to identify and cluster them quickly. While for most scenarios, most data viewers relate to the file type (either binary or textual) to extract meaningful data, the protective measurements of different malicious payloads may make this task difficult. Our research introduces an approach that develops an enhanced visualization mode within the open-source framework GView to address this challenge. It harnesses established entropy-based analytical principles to facilitate the identification of anomalies and intrinsic properties in binary data, irrespective of specific file formats. This methodology streamlines threat evaluation and contributes to the broader field of cybersecurity by offering a building block for a scalable solution for analyzing the everexpanding volumes of digital information.

Read the paper · More papers on PaperTik