DOI

  • Kseniya Salakhutdinova
  • Ilya Lebedev
  • Irina Krivtsova
  • Nurzhan Bazhayev
  • Mikhail Sukhoparov
  • Pavel Smimov
  • Dmitry Markelov
  • Alexander Davvdov
  • Sergey Pecherkin
  • Dmitry Kolcherin
  • Yuriy Shaparenko
  • Yuriy Iskanderov

The paper presents methods of executable file signature creation based on frequency distributions of their informative features to be applied for program identification. Identification here should be understood as a process of file recognition by establishing its coincidence with a particular program. A new approach to creation of the archive of program signatures, both in terms of byte-frequency distribution of a program's binary code, and in terms of frequency distribution of assembler commands in their disassembler codes, is presented. The new method of executable file identification is offered and the results of experiments on their identification using a statistical criterion of ∗-Fisher and analysis of the slope are provided. The proposed method can be used to audit data-storage medium.

Язык оригиналаанглийский
Название основной публикации11th IEEE International Conference on Application of Information and Communication Technologies, AICT 2017 - Proceedings
ИздательInstitute of Electrical and Electronics Engineers Inc.
ISBN (электронное издание)9781538605011
DOI
СостояниеОпубликовано - 10 апр 2019
Событие11th IEEE International Conference on Application of Information and Communication Technologies, AICT 2017 - Moscow, Российская Федерация
Продолжительность: 20 сен 201722 сен 2017

Серия публикаций

Название11th IEEE International Conference on Application of Information and Communication Technologies, AICT 2017 - Proceedings

конференция

конференция11th IEEE International Conference on Application of Information and Communication Technologies, AICT 2017
Страна/TерриторияРоссийская Федерация
ГородMoscow
Период20/09/1722/09/17

    Предметные области Scopus

  • Компьютерные сети и коммуникации
  • Прикладные компьютерные науки

ID: 53918835