2021
DOI: 10.1016/j.cose.2020.102119
|View full text |Cite
|
Sign up to set email alerts
|

Pre-processing memory dumps to improve similarity score of Windows modules

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1

Citation Types

0
0
0

Year Published

2021
2021
2024
2024

Publication Types

Select...
4
2
1

Relationship

0
7

Authors

Journals

citations
Cited by 9 publications
(3 citation statements)
references
References 12 publications
0
0
0
Order By: Relevance
“…In [17] , they introduce an intriguing notion of memory dump preprocessing with two various procedures, making the analysis process faster and easier by relocating file objects. Guided De-Relocation was the first strategy, which specified a new space for the information.…”
Section: Related Workmentioning
confidence: 99%
“…In [17] , they introduce an intriguing notion of memory dump preprocessing with two various procedures, making the analysis process faster and easier by relocating file objects. Guided De-Relocation was the first strategy, which specified a new space for the information.…”
Section: Related Workmentioning
confidence: 99%
“…This is motivated because in 64-bit mode the RIP-relative addressing form was introduced, which facilitates the construction of position-independent code and therefore the bytes a ected by relocation will be only the ones related to function addresses of shared libraries. We refer the reader to [1] for more details in this issue.…”
Section: Ementioning
confidence: 99%
“…The full version of this paper (with a full description of the experiments and limitations) was published in [1].…”
Section: Ementioning
confidence: 99%