Marcus Botacin · @MarcusBotacin
31 followers · 31 posts · Server infosec.exchange

[Paper of the day][#18] How do you triage ? How do you tell two files are similar? An interesting static analysis approach is to use tools, such as and . However, to be effective, their application can't be straightforward, but should follow a protocol. In this paper, we discuss how to efficiently apply these functions for malware family classification. We show that hashing only the instruction disassembly has a greater impact than hashing the entire file. Check this result and much more.

Academic paper: sciencedirect.com/science/arti
Archived version: secret.inf.ufpr.br/papers/marc

#malware #similarity #hashing #ssdeep #sdhash

Last updated 2 years ago