Please use this identifier to cite or link to this item: https://dair.nps.edu/handle/123456789/4167
Full metadata record
DC FieldValueLanguage
dc.contributor.authorNeil Rowe-
dc.contributor.authorBruce Allen-
dc.date.accessioned2020-12-02T16:05:26Z-
dc.date.available2020-12-02T16:05:26Z-
dc.date.issued2019-12-02-
dc.identifier.citationPublished--Unlimited Distributionen_US
dc.identifier.urihttps://dair.nps.edu/handle/123456789/4167-
dc.descriptionInformation Technology / NPS Faculty Researchen_US
dc.description.abstractWe studied differences between versions of software by comparing their executable files. We used a large database (“corpus”) of around 2600 digital-forensic copies of secondary storage of computers and digital devices purchased around the world. We extracted families of executable files in the EXE and DLL formats having the same name; we also included in these families other files having the same contents as files in the family but different names. We measured file similarities between files in the same family by finding matches between 8-bit bytes in the two files, and then looking for sequences of unbroken consecutive matches. We developed several kinds of useful visualizations to show file similarities: Two ways to display the bytes that match between two files, and two ways to show the similarities between members of a file family over time. These methods should make it considerably easier to detect fraudulent or malicious software because it will stand out in the visualizations.en_US
dc.description.sponsorshipAcquisition Research Programen_US
dc.language.isoen_USen_US
dc.publisherAcquisition Research Programen_US
dc.relation.ispartofseriesSoftware;NPS-IT-20-014-
dc.subjectSoftwareen_US
dc.subjectExecutable Filesen_US
dc.subjectCorpusen_US
dc.subjectDatabaseen_US
dc.subjectDigital Devicesen_US
dc.subjectFraudulent Softwareen_US
dc.subjectMalicious Softwareen_US
dc.titleAnalysis of Differences between Versions of Software Executablesen_US
dc.typeTechnical Reporten_US
Appears in Collections:Sponsored Acquisition Research & Technical Reports

Files in This Item:
File Description SizeFormat 
NPS-IT-20-014.pdfTechnical Report1.84 MBAdobe PDFView/Open


Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.