OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
[Full-Disclosure] Paper: Comparing binaries with graph isomorphisms

From: Todd Sabin (tsabinrazor.bindview.com)
Date: Mon Apr 05 2004 - 19:39:29 CDT


I'm pleased to announce the availability of a new paper:

Comparing binaries with graph isomorphisms.
http://razor.bindview.com/publish/papers/comparing-binaries.html

The paper presents a method and algorithms for finding differences
between two versions of a binary executable file, based on graph
isomorphisms. One possible application is to discover the differences
in a security patch, and a couple examples in that vein are shown. A
brief comparison is also made to Halvar Flake's function signatures
approach (as I understand it).

The tool implementing the technique is not being made available at
this time, but will likely be released later this year.

--
Todd Sabin <tsabinoptonline.net>
BindView RAZOR Team <tsabinrazor.bindview.com>

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html