• Kseniya Salakhutdinova
  • Irina Krivtsova
  • Ilya Lebedev
  • Mikhail Sukhoparov

Statement of Research. A need to reduce the increasing number of system vulnerabilities caused by unauthorized software installed on computer aids necessitates development of an approach to automate the data-storage media audit. The article describes an approach to identification of informative assembly instructions. Also, the influence of a chosen feature that is used to create a unified program signature on identification result is shown. Methods. Shannon method allowing a determination of feature informativeness for a random number of object classes and not depending on the sample volume of observed features is used to calculate informativeness. Identification of elf-files was based on applying statistical chi-squared test of homogeneity. Main Findings. Quantitative characteristics of informativeness for 118 assembly instructions have been obtained. The analysis of experimental results for executable files identification with 10 different features used to create program signatures compared by means of the chi-squared test of homogeneity at significance levels p = 0.05 and p = 0.01 has been carried out. Practical Relevance. The importance of using a particular feature in program signature creation has been discovered, as well as the capability of considering several executable file signatures together to provide a summative assessment on their belonging to a certain program.

Original languageEnglish
Title of host publicationInternet of Things, Smart Spaces, and Next Generation Networks and Systems - 18th International Conference, NEW2AN 2018, and 11th Conference, ruSMART 2018, Proceedings
EditorsSergey Balandin, Olga Galinina, Sergey Andreev, Yevgeni Koucheryavy
PublisherSpringer Nature
Pages318-327
Number of pages10
ISBN (Print)9783030011673
DOIs
StatePublished - 1 Jan 2018
Event18th International Conference on Next Generation Teletraffic and Wired/Wireless Advanced Networks and Systems, NEW2AN 2018 and 11th Conference on Internet of Things and Smart Spaces, ruSMART 2018 - St. Petersburg, Russian Federation
Duration: 27 Aug 201829 Aug 2018

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume11118 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference18th International Conference on Next Generation Teletraffic and Wired/Wireless Advanced Networks and Systems, NEW2AN 2018 and 11th Conference on Internet of Things and Smart Spaces, ruSMART 2018
Country/TerritoryRussian Federation
CitySt. Petersburg
Period27/08/1829/08/18

    Research areas

  • Chi-square test, Elf-files, Identification of executable files, Information security, Informativeness of a feature

    Scopus subject areas

  • Theoretical Computer Science
  • Computer Science(all)

ID: 53918998