• Àüü
  • ÀüÀÚ/Àü±â
  • Åë½Å
  • ÄÄÇ»ÅÍ
´Ý±â

»çÀÌÆ®¸Ê

Loading..

Please wait....

±¹³» ³í¹®Áö

Ȩ Ȩ > ¿¬±¸¹®Çå > ±¹³» ³í¹®Áö > Çѱ¹Á¤º¸°úÇÐȸ ³í¹®Áö > Á¤º¸°úÇÐȸ³í¹®Áö (Journal of KIISE)

Á¤º¸°úÇÐȸ³í¹®Áö (Journal of KIISE)

Current Result Document :

ÇѱÛÁ¦¸ñ(Korean Title) ½Å·Ú¼º ³ôÀº µ¿Àû API ½ÃÄö½º¸¦ ÀÌ¿ëÇÑ ¼ÒÇÁÆ®¿þ¾î À¯»ç¼º °Ë»ç
¿µ¹®Á¦¸ñ(English Title) Software Similarity Detection Using Highly Credible Dynamic API Sequences
ÀúÀÚ(Author) ¹Ú¼º¼ö   ÇÑȯ¼ö   Seongsoo Park   Hwansoo Han  
¿ø¹®¼ö·Ïó(Citation) VOL 43 NO. 10 PP. 1067 ~ 1072 (2016. 10)
Çѱ۳»¿ë
(Korean Abstract)
½ÇÇàÄڵ常À¸·Î ¼ÒÇÁÆ®¿þ¾î °£ÀÇ À¯»ç¼ºÀ» ºñ±³Çϰųª Ç¥ÀýÀ» °Ë»çÇϱâ À§ÇØ ¼ÒÇÁÆ®¿þ¾î¸¸ÀÇ
°íÀ¯ÇÑ Æ¯Â¡ÀÎ ¼ÒÇÁÆ®¿þ¾î ¹ö½º¸¶Å©¸¦ ÀÌ¿ëÇÑ´Ù. ÀϹÝÀûÀ¸·Î ¼ÒÇÁÆ®¿þ¾î ¹ö½º¸¶Å©´Â ÃßÃâ ¹æ¹ý¿¡ µû¶ó Á¤Àû ¹ö½º¸¶Å©¿Í µ¿Àû ¹ö½º¸¶Å©·Î ±¸ºÐµÇ°í, ÃßÃâµÈ ¹æ¹ý¿¡ µû¶ó Àå´ÜÁ¡ÀÌ ¶Ñ·ÇÇÏ°Ô ³ªÅ¸³­´Ù. º» ³í¹®¿¡¼­´Â µ¿Àû ºÐ¼®À» ÀÌ¿ëÇÏ¿© API ½ÃÄö½º ¹ö½º¸¶Å©¸¦ ÃßÃâÇÏ°í ½ÇÇàÄÚµå °£ÀÇ À¯»ç¼º °Ë»ç¿¡ ÀÌ¿ëÇÏ´Â ¹æ¹ýÀ» Á¦¾ÈÇÑ´Ù. Á¦¾ÈÇÏ´Â µ¿Àû ½ÃÄö½º ¹ö½º¸¶Å©´Â ÇÁ·Î±×·¥ÀÌ ½ÇÇàµÇ´Â °úÁ¤¿¡¼­ È£ÃâµÇ´Â ¸ðµç API ÇÔ¼ö ¹× ½Ã½ºÅÛ È£ÃâÀ» Æ÷ÇÔÇÏ´Â ±âÁ¸ÀÇ ¹æ¹ý°ú´Â ´Ù¸£°Ô ½ÇÇàÄÚµå ³»¿¡ Á¤ÀǵǾî ÀÖ´Â API ÇÔ¼ö¸¸À¸·Î ±¸¼ºµÈ API ½ÃÄö½º¸¦ ÀÌ¿ëÇÑ´Ù. ÃßÃâµÈ µ¿Àû ¹ö½º¸¶Å©´Â ÇÁ·Î±×·¥ÀÇ ½ÃÀÛ¿¡¼­ Á¾·á±îÁö È£ÃâµÇ´Â API ½ÃÄö½ºÀ̸ç À̸¦ È¿À²ÀûÀ¸·Î ºñ±³Çϱâ À§ÇØ ¼­¿­Á¤·Ä ¾Ë°í¸®ÁòÀ» È°¿ëÇÑ À¯»ç¼º ôµµ¸¦ »ç¿ëÇÑ´Ù. ¿©·¯ ¿ÀǼҽº ¼ÒÇÁÆ®¿þ¾î¸¦ ºñ±³ÇÏ¿© ¹ö½º¸¶Å©ÀÇ ½Å·Ú¼º°ú °­ÀμºÀ» °ËÁõÇÏ¿´´Ù. Á¦¾ÈÇÏ´Â µ¿Àû API ½ÃÄö½º ¹ö½º¸¶Å©´Â ½ÇÇàÄÚµåÀÇ À¯»ç¼º °Ë»ç¿¡ ¿ëÀÌÇÏ°Ô È°¿ëµÉ ¼ö ÀÖÀ» °ÍÀ¸·Î ±â´ëµÈ´Ù.
¿µ¹®³»¿ë
(English Abstract)
Software birthmarks, which are unique characteristics of the software, are used to
detect software plagiarism or software similarity. Generally, software birthmarks are divided into static birthmarks or dynamic birthmarks, which have evident pros and cons depending on the extraction method. In this paper, we propose a method for extracting the API sequence birthmarks using a dynamic analysis and similarity detection between the executable codes. Dynamic birthmarks based on API sequences extract API functions during the execution of programs. The extracted API sequences often include all the API functions called from the start to the end of the program. Meanwhile, our dynamic birthmark scheme extracts the API functions only called directly from the executable code. Then, it uses a sequence alignment algorithm to calculate the similarity metric effectively. We evaluate the birthmark with several open source software programs to verify its reliability and credibility. Our dynamic birthmark scheme based on the extracted API sequence can be utilized in a similarity test of executable codes.
Å°¿öµå(Keyword) ¹ÙÀ̳ʸ® À¯»çµµ   ¼ÒÇÁÆ®¿þ¾î ¹ö½º¸¶Å©   µ¿Àû API ½ÃÄö½º   ¼ÒÇÁÆ®¿þ¾î À¯»ç   binary level similarity   software birthmark   static/dynamic sequence   software similarity  
ÆÄÀÏ÷ºÎ PDF ´Ù¿î·Îµå