Invention Grant
- Patent Title: Technologies for software basic block similarity analysis
-
Application No.: US14494751Application Date: 2014-09-24
-
Publication No.: US10043009B2Publication Date: 2018-08-07
- Inventor: Jason R. Upchurch
- Applicant: Intel Corporation
- Applicant Address: US CA Santa Clara
- Assignee: Intel Corporation
- Current Assignee: Intel Corporation
- Current Assignee Address: US CA Santa Clara
- Agency: Barnes & Thornburg LLP
- Main IPC: G06F21/56
- IPC: G06F21/56 ; G06F21/57 ; G06F17/30 ; G06F21/12

Abstract:
Technologies for analyzing software similarity include a computing device having access to a collection of sample software. The computing device identifies a number of code segments, such as basic blocks, within the software. The computing device normalizes each code segment by extracting the first data element of each computer instruction within the code segment. The first data element may be the first byte. The computing device calculates a probabilistic feature hash signature for each normalized code segment. The computing device may filter out known-good code segments by comparing signatures with a probabilistic hash filter generated from a collection of known-good software. The computing device calculates a similarity value between each pair of unfiltered, normalized code segments. The computing device generates a graph including the normalized code segments and the similarity values. The computing device may cluster the graph using a force-based clustering algorithm.
Public/Granted literature
- US20170300691A1 TECHNOLOGIES FOR SOFTWARE BASIC BLOCK SIMILARITY ANALYSIS Public/Granted day:2017-10-19
Information query