{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,7]],"date-time":"2026-07-07T12:11:50Z","timestamp":1783426310876,"version":"3.54.6"},"publisher-location":"Cham","reference-count":35,"publisher":"Springer International Publishing","isbn-type":[{"value":"9783319584683","type":"print"},{"value":"9783319584690","type":"electronic"}],"license":[{"start":{"date-parts":[[2017,1,1]],"date-time":"2017-01-01T00:00:00Z","timestamp":1483228800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2017,1,1]],"date-time":"2017-01-01T00:00:00Z","timestamp":1483228800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2017]]},"DOI":"10.1007\/978-3-319-58469-0_23","type":"book-chapter","created":{"date-parts":[[2017,5,3]],"date-time":"2017-05-03T11:34:53Z","timestamp":1493811293000},"page":"341-355","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":30,"title":["BinSign: Fingerprinting Binary Functions to Support Automated Analysis of Code Executables"],"prefix":"10.1007","author":[{"given":"Lina","family":"Nouh","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ashkan","family":"Rahimian","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Djedjiga","family":"Mouheb","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Mourad","family":"Debbabi","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Aiman","family":"Hanna","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2017,5,4]]},"reference":[{"key":"23_CR1","doi-asserted-by":"crossref","unstructured":"Huang, H., Youssef, A., Debbabi, M.: BinSequence: Fast, Accurate and Scalable Binary Code Reuse Detection. Accepted for publication in the ACM Asia Conference on Computer and Communications Security (ASIACCS). ACM Press (2017)","DOI":"10.1145\/3052973.3052974"},{"key":"23_CR2","doi-asserted-by":"crossref","unstructured":"Alrabaee, S., Shirani, P., Debbabi, M., Lingyu, W.: On the feasibility of malware authorship attribution. In: International Symposium on Foundations and Practice of Security, pp. 256\u2013272. Springer, Cham (2016)","DOI":"10.1007\/978-3-319-51966-1_17"},{"key":"23_CR3","doi-asserted-by":"publisher","first-page":"S146","DOI":"10.1016\/j.diin.2015.05.015","volume":"14","author":"A Rahimian","year":"2015","unstructured":"Rahimian, A., Shirani, P., Alrabaee, S., Lingyu, W., Debbabi, M.: BinComp: a stratified approach to compiler provenance attribution. Digital Invest. 14, S146\u2013S155 (2015)","journal-title":"Digital Invest."},{"key":"23_CR4","doi-asserted-by":"publisher","first-page":"S61","DOI":"10.1016\/j.diin.2015.01.011","volume":"12","author":"S Alrabaee","year":"2015","unstructured":"Alrabaee, S., Shirani, P., Lingyu, W., Debbabi, M.: Sigma: a semantic integrated graph matching approach for identifying reused functions in binary code. Digital Invest. 12, S61\u2013S71 (2015)","journal-title":"Digital Invest."},{"key":"23_CR5","unstructured":"Advanced Message Queuing Protocol (AMQP). https:\/\/www.amqp.org\/"},{"key":"23_CR6","unstructured":"Internet Security Threat Report 2016. https:\/\/www.symantec.com\/content\/dam\/symantec\/docs\/reports\/istr-21-2016-en.pdf"},{"key":"23_CR7","unstructured":"Diaphora: A Program Diffing Plugin for IDA Pro. https:\/\/github.com\/joxeankoret\/diaphora"},{"key":"23_CR8","unstructured":"Hex-Rays IDA Pro. https:\/\/www.hex-rays.com\/products\/ida\/"},{"key":"23_CR9","unstructured":"Diffng Plugin for IDA. https:\/\/code.google.com\/p\/patchdiff2\/"},{"key":"23_CR10","unstructured":"Weka: Machine Learning Software. https:\/\/weka.wikispaces.com\/"},{"key":"23_CR11","doi-asserted-by":"publisher","first-page":"117","DOI":"10.1145\/1327452.1327494","volume":"51","author":"A Andoni","year":"2008","unstructured":"Andoni, A., Indyk, P.: Near-optimal hashing algorithms for approximate nearest neighbor in high dimensions. Commun. ACM. 51, 117\u2013122 (2008)","journal-title":"Commun. ACM."},{"key":"23_CR12","first-page":"112","volume":"7","author":"G Bonfante","year":"2012","unstructured":"Bonfante, G., Marion, J., Sabatier, F., Thierry, A.: Code synchronization by morphological analysis. Malicious Unwanted Softw. 7, 112\u2013119 (2012)","journal-title":"Malicious Unwanted Softw."},{"key":"23_CR13","doi-asserted-by":"crossref","unstructured":"Bourquin, M., King, A., Robbins, E.: Binslayer: accurate comparison of binary executables. In: Proceedings of the 2nd ACM SIGPLAN Program Protection and Reverse Engineering Workshop, vol. 13, pp. 4:1\u20134:10 (2013)","DOI":"10.1145\/2430553.2430557"},{"key":"23_CR14","doi-asserted-by":"publisher","first-page":"307","DOI":"10.1109\/TDSC.2013.40","volume":"11","author":"S Cesare","year":"2014","unstructured":"Cesare, S., Xiang, Y., Zhou, W.: Control flow-based malware variant detection. IEEE Trans. Dependable Secure Comput. 11, 307\u2013317 (2014)","journal-title":"IEEE Trans. Dependable Secure Comput."},{"key":"23_CR15","doi-asserted-by":"crossref","unstructured":"Chaki, S., Cohen, C., Gurfinkel, A.: Supervised learning for provenance-similarity of binaries. In: Proceedings of the 17th ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, KDD 2011, pp. 15\u201323 (2011)","DOI":"10.1145\/2020408.2020419"},{"key":"23_CR16","doi-asserted-by":"crossref","unstructured":"Cordy, J.R., Roy, C.K.: Efficient Checking for Open Source Code Clones in Software Systems. In: 19th IEEE ICPC, pp. 217\u2013218 (2011)","DOI":"10.1109\/ICPC.2011.27"},{"key":"23_CR17","doi-asserted-by":"crossref","unstructured":"David, Y., Yahav, E.: Tracelet-based code search in executables. In: Proceedings of the 35th ACM SIGPLAN Conference on Programming Language Design and Implementation, PLDI 2014, pp. 349\u2013360 (2014)","DOI":"10.1145\/2594291.2594343"},{"key":"23_CR18","first-page":"1","volume":"5","author":"T Dullien","year":"2005","unstructured":"Dullien, T., Rolles, R.: Graph-based comparison of executable objects (English Version). SSTIC 5, 1\u20133 (2005)","journal-title":"SSTIC"},{"key":"23_CR19","doi-asserted-by":"crossref","unstructured":"Elva, R., Leavens, G.: Semantic clone detection using method IOE-behavior. In: 6th International Workshop on Software Clones (IWSC), pp. 80\u201381 (2012)","DOI":"10.1109\/IWSC.2012.6227874"},{"key":"23_CR20","doi-asserted-by":"crossref","unstructured":"Farhadi, M.R., Fung, B.C.M., Charland, P., Debbabi, M.: Binclone: detecting code clones in malware. In: International Conference on Software Security and Reliability, vol. 8, pp. 78\u201387 (2014)","DOI":"10.1109\/SERE.2014.21"},{"key":"23_CR21","doi-asserted-by":"crossref","unstructured":"Gascon, H., Yamaguchi, F., Arp, D., Rieck, K.: Structural detection of android malware using embedded call graphs. In: Proceedings of the ACM Workshop on Artificial Intelligence and Security, AISec 2013, pp. 45\u201354 (2013)","DOI":"10.1145\/2517312.2517315"},{"key":"23_CR22","unstructured":"Hex-Rays. Fast Library Identifiation and Recognition Technology: In-Depth. https:\/\/www.hex-rays.com\/products\/ida\/tech\/flirt\/in_depth.shtml"},{"key":"23_CR23","doi-asserted-by":"crossref","unstructured":"Jacobson, E.R., Rosenblum, N., Miller, B.P.: Labeling library functions in stripped binaries. In: Proceedings of the 10th ACM SIGPLAN-SIGSOFT Workshop on Program Analysis for Software Tools, PASTE 2011, pp. 1\u20138 (2011)","DOI":"10.1145\/2024569.2024571"},{"key":"23_CR24","doi-asserted-by":"crossref","unstructured":"Jin, W., Chaki, S., Cohen, C., Gurfinkel, A., Havrilla, J., Hines, C., Narasimhan, P.: Binary function clustering using semantic hashes. In: 11th International Conference on Machine Learning and Applications (ICMLA), vol. 1, pp. 386\u2013391 (2012)","DOI":"10.1109\/ICMLA.2012.70"},{"key":"23_CR25","doi-asserted-by":"crossref","unstructured":"Junod, P., Rinaldini, J., Wehrli, J., Michielin, J.: Obfuscator-LLVM: software protection for the masses. In: Wyseur, B. (ed.) Proceedings of the IEEE\/ACM 1st International Workshop on Software Protection, SPRO 2015, vol. 3\u20139 (2015)","DOI":"10.1109\/SPRO.2015.10"},{"key":"23_CR26","doi-asserted-by":"crossref","unstructured":"Keivanloo, I., Rilling, J., Charland, P.: Internet-scale real-time code clone search via multi-level indexing. In: 18th Working Conference on Reverse Engineering (WCRE), pp. 23\u201327 (2011)","DOI":"10.1109\/WCRE.2011.13"},{"key":"23_CR27","doi-asserted-by":"crossref","unstructured":"Khoo, W.M., Mycroft, A., Anderson, R.: Rendezvous: a search engine for binary code. In: Proceedings of the 10th Working Conference on Mining Software Repositories, MSR 2013, pp. 329\u2013338 (2013)","DOI":"10.1109\/MSR.2013.6624046"},{"key":"23_CR28","doi-asserted-by":"publisher","first-page":"233","DOI":"10.1007\/s11416-011-0151-y","volume":"7","author":"J Kinable","year":"2011","unstructured":"Kinable, J., Kostakis, O.: Malware classification based on call graph clustering. J. Comput. Virol. 7, 233\u2013245 (2011)","journal-title":"J. Comput. Virol."},{"key":"23_CR29","doi-asserted-by":"crossref","unstructured":"Lakhotia, A., Preda, M.D., Giacobazzi, R.: Fast location of similar code fragments using semantic \u2018Juice\u2019. In: Proceedings of the 2nd ACM SIGPLAN Program Protection and Reverse Engineering Workshop, PPREW 2013, pp. 5:1\u20135:6 (2013)","DOI":"10.1145\/2430553.2430558"},{"key":"23_CR30","unstructured":"Milletary, J.: Citadel Trojan Malware Analysis. Technical report, Dell SecureWorks Counter Threat Unit Intelligence Services (2012)"},{"key":"23_CR31","doi-asserted-by":"crossref","unstructured":"Ng, B.H., Prakash, A.: Expose: discovering potential binary code re-use. In: COMPSAC, IEEE 37th Annual, pp. 492\u2013501 (2013)","DOI":"10.1109\/COMPSAC.2013.83"},{"key":"23_CR32","unstructured":"Pivotal Software. RabbitMQ Web Site. https:\/\/www.rabbitmq.com\/"},{"key":"23_CR33","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"408","DOI":"10.1007\/978-3-319-05302-8_25","volume-title":"Foundations and Practice of Security","author":"A Rahimian","year":"2014","unstructured":"Rahimian, A., Ziarati, R., Preda, S., Debbabi, M.: On the reverse engineering of the citadel botnet. In: Danger, J.-L., Debbabi, M., Marion, J.-Y., Garcia-Alfaro, J., Zincir Heywood, N. (eds.) FPS -2013. LNCS, vol. 8352, pp. 408\u2013425. Springer, Cham (2014). doi:10.1007\/978-3-319-05302-8_25"},{"key":"23_CR34","volume-title":"Mining of Massive Datasets","author":"A Rajaraman","year":"2014","unstructured":"Rajaraman, A., Ullman, J.D.: Mining of Massive Datasets. Cambridge University Press, New York (2014)"},{"key":"23_CR35","doi-asserted-by":"publisher","first-page":"323","DOI":"10.1007\/s11416-008-0082-4","volume":"4","author":"Y Ye","year":"2008","unstructured":"Ye, Y., Wang, D., Li, T., Jiang, Q.: An intelligent pe-malware detection system based on association mining. J. Comput. Virol. 4, 323\u2013334 (2008)","journal-title":"J. Comput. Virol."}],"container-title":["IFIP Advances in Information and Communication Technology","ICT Systems Security and Privacy Protection"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-58469-0_23","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,5,22]],"date-time":"2021-05-22T00:07:28Z","timestamp":1621642048000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-319-58469-0_23"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2017]]},"ISBN":["9783319584683","9783319584690"],"references-count":35,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-58469-0_23","relation":{},"ISSN":["1868-4238","1868-422X"],"issn-type":[{"value":"1868-4238","type":"print"},{"value":"1868-422X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2017]]},"assertion":[{"value":"4 May 2017","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"SEC","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"IFIP International Conference on ICT Systems Security and Privacy Protection","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Rome","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Italy","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2017","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"29 May 2017","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"31 May 2017","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"32","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"sec2017","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"http:\/\/ifipsec.org\/2017\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"This content has been made available to all.","name":"free","label":"Free to read"}]}}