[<prev] [next>] [day] [month] [year] [list]
Message-ID: <m3hdvylz49.fsf@jetcar.qnz.org>
Date: Mon, 05 Apr 2004 20:38:14 -0400
From: Todd Sabin <tsabin@...or.bindview.com>
To: bugtraq@...urityfocus.com
Subject: Paper: Comparing binaries with graph isomorphisms
I'm pleased to announce the availability of a new paper:
Comparing binaries with graph isomorphisms.
http://razor.bindview.com/publish/papers/comparing-binaries.html
The paper presents a method and algorithms for finding differences
between two versions of a binary executable file, based on graph
isomorphisms. One possible application is to discover the differences
in a security patch, and a couple examples in that vein are shown. A
brief comparison is also made to Halvar Flake's function signatures
approach (as I understand it).
The tool implementing the technique is not being made available at
this time, but will likely be released later this year.
--
Todd Sabin <tsabin@...online.net>
BindView RAZOR Team <tsabin@...or.bindview.com>
Powered by blists - more mailing lists