Topology-Aware Hashing for Effective Control Flow Graph Similarity Analysis

被引:4
|
作者
Li, Yuping [1 ]
Jang, Jiyong [2 ]
Ou, Xinming [3 ]
机构
[1] Pinterest, San Francisco, CA 94107 USA
[2] IBM Res, Yorktown Hts, NY USA
[3] Univ S Florida, Tampa, FL 33620 USA
基金
美国国家科学基金会;
关键词
CFG comparison; Binary similarity; Malware analysis;
D O I
10.1007/978-3-030-37228-6_14
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Control Flow Graph (CFG) similarity analysis is an essential technique for a variety of security analysis tasks, including malware detection and malware clustering. Even though various algorithms have been developed, existing CFG similarity analysis methods still suffer from limited efficiency, accuracy, and usability. In this paper, we propose a novel fuzzy hashing scheme called topology-aware hashing (TAH) for effective and efficient CFG similarity analysis. Given the CFGs constructed from program binaries, we extract blended n-gram graphical features of the CFGs, encode the graphical features into numeric vectors (called graph signatures), and then measure the graph similarity by comparing the graph signatures. We further employ a fuzzy hashing technique to convert the numeric graph signatures into smaller fixed-size fuzzy hash signatures for efficient similarity calculation. Our comprehensive evaluation demonstrates that TAH is more effective and efficient compared to existing CFG comparison techniques. To demonstrate the applicability of TAH to real-world security analysis tasks, we develop a binary similarity analysis tool based on TAH, and show that it outperforms existing similarity analysis tools while conducting malware clustering.
引用
收藏
页码:278 / 298
页数:21
相关论文
共 50 条
  • [41] SimRank*: effective and scalable pairwise similarity search based on graph topology
    Yu, Weiren
    Lin, Xuemin
    Zhang, Wenjie
    Pei, Jian
    McCann, Julie A.
    VLDB JOURNAL, 2019, 28 (03): : 401 - 426
  • [42] SimRank*: effective and scalable pairwise similarity search based on graph topology
    Weiren Yu
    Xuemin Lin
    Wenjie Zhang
    Jian Pei
    Julie A. McCann
    The VLDB Journal, 2019, 28 : 401 - 426
  • [43] Specification and Verification of a Topology-Aware Access Control Model for Cyber-Physical Space
    Yan Cao
    Zhiqiu Huang
    Shuanglong Kan
    Dajuan Fan
    Yang Yang
    Tsinghua Science and Technology, 2019, 24 (05) : 497 - 519
  • [44] Topology-Aware Graph Convolution Network for Few-Shot Incremental 3-D Object Learning
    Ma, Bingtao
    Cong, Yang
    Dong, Jiahua
    IEEE TRANSACTIONS ON SYSTEMS MAN CYBERNETICS-SYSTEMS, 2024, 54 (01): : 324 - 337
  • [45] Neighborhood Topology-Aware Knowledge Graph Learning and Microbial Preference Inferring for Drug-Microbe Association Prediction
    Gu, Jing
    Zhang, Tiangang
    Gao, Yihang
    Chen, Sentao
    Zhang, Yuxin
    Cui, Hui
    Xuan, Ping
    JOURNAL OF CHEMICAL INFORMATION AND MODELING, 2025, 65 (01) : 435 - 445
  • [46] A topology-aware access control model for collaborative cyber-physical spaces: Specification and verification
    Cao, Yan
    Huang, Zhiqiu
    Ke, Changbo
    Xie, Jian
    Wang, Jinyong
    COMPUTERS & SECURITY, 2019, 87
  • [47] TOMAS: A novel TOpology-aware Meta-Analysis approach applied to System biology
    Tin Nguyen
    Diaz, Diana
    Draghici, Sorin
    PROCEEDINGS OF THE 7TH ACM INTERNATIONAL CONFERENCE ON BIOINFORMATICS, COMPUTATIONAL BIOLOGY, AND HEALTH INFORMATICS, 2016, : 13 - 22
  • [48] Stochastic analysis of geometrically imperfect thin cylindrical shells using topology-aware uncertainty models
    Wang, Haoran
    Guilleminot, Johann
    Schafer, Benjamin W.
    Tootkaboni, Mazdak
    COMPUTER METHODS IN APPLIED MECHANICS AND ENGINEERING, 2022, 393
  • [49] Topology-Aware Distributed Smart Grid Control using a Clustering-Based Utility Maximization Approach
    Stuebs, Marius
    Ipach, Hanko
    Becker, Christian
    PROCEEDINGS OF THE 35TH ANNUAL ACM SYMPOSIUM ON APPLIED COMPUTING (SAC'20), 2020, : 1806 - 1815
  • [50] Energy-aware weighted graph based dynamic topology control algorithm
    Sun, Ruozi
    Yuan, Jian
    You, Ilsun
    Shan, Xiuming
    Ren, Yong
    SIMULATION MODELLING PRACTICE AND THEORY, 2011, 19 (08) : 1773 - 1781