{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,21]],"date-time":"2026-07-21T00:59:46Z","timestamp":1784595586210,"version":"3.55.0"},"publisher-location":"Cham","reference-count":50,"publisher":"Springer International Publishing","isbn-type":[{"value":"9783319608754","type":"print"},{"value":"9783319608761","type":"electronic"}],"license":[{"start":{"date-parts":[[2017,1,1]],"date-time":"2017-01-01T00:00:00Z","timestamp":1483228800000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2017]]},"DOI":"10.1007\/978-3-319-60876-1_14","type":"book-chapter","created":{"date-parts":[[2017,6,3]],"date-time":"2017-06-03T08:00:34Z","timestamp":1496476834000},"page":"301-324","source":"Crossref","is-referenced-by-count":49,"title":["BinShape: Scalable and Robust Binary Library Function Identification Using Function Shape"],"prefix":"10.1007","author":[{"given":"Paria","family":"Shirani","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Lingyu","family":"Wang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Mourad","family":"Debbabi","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2017,6,4]]},"reference":[{"key":"14_CR1","unstructured":"C Language Library. \nhttp:\/\/www.cplusplus.com\/reference\/clibrary\/"},{"key":"14_CR2","unstructured":"Exeinfo PE. \nhttp:\/\/exeinfo.atwebpages.com"},{"key":"14_CR3","unstructured":"HexRays: IDA F.L.I.R.T. Technology. \nhttps:\/\/www.hex-rays.com\/products\/ida\/tech\/flirt\/in_depth.shtml"},{"key":"14_CR4","unstructured":"HexRays: IDA Pro. \nhttps:\/\/www.hex-rays.com\/products\/ida\/index.shtml"},{"key":"14_CR5","unstructured":"MongoDB. \nhttps:\/\/www.mongodb.com\/"},{"key":"14_CR6","unstructured":"NIST\/SEMATECH e-Handbook of Statistical Methods. \nhttp:\/\/www.itl.nist.gov\/div898\/handbook\/"},{"key":"14_CR7","unstructured":"WEKA. \nhttps:\/\/weka.wikispaces.com\/"},{"key":"14_CR8","doi-asserted-by":"crossref","first-page":"S94","DOI":"10.1016\/j.diin.2014.03.012","volume":"11","author":"S Alrabaee","year":"2014","unstructured":"Alrabaee, S., Saleem, N., Preda, S., Wang, L., Debbabi, M.: OBA2: an Onion approach to binary code authorship attribution. Digital Invest. 11, S94\u2013S103 (2014)","journal-title":"Digital Invest."},{"key":"14_CR9","doi-asserted-by":"crossref","first-page":"S61","DOI":"10.1016\/j.diin.2015.01.011","volume":"12","author":"S Alrabaee","year":"2015","unstructured":"Alrabaee, S., Shirani, P., Wang, L., Debbabi, M.: SIGMA: a semantic integrated graph matching approach for identifying reused functions in binary code. Digital Invest. 12, S61\u2013S71 (2015)","journal-title":"Digital Invest."},{"key":"14_CR10","doi-asserted-by":"crossref","first-page":"S11","DOI":"10.1016\/j.diin.2016.04.002","volume":"18","author":"S Alrabaee","year":"2016","unstructured":"Alrabaee, S., Wang, L., Debbabi, M.: BinGold: towards robust binary analysis by extracting the semantics of binary code as semantic flow graphs (SFGs). Digital Invest. 18, S11\u2013S22 (2016)","journal-title":"Digital Invest."},{"key":"14_CR11","doi-asserted-by":"crossref","unstructured":"Bourquin, M., King, A., Robbins, E.: BinSlayer: accurate comparison of binary executables. In: Proceedings of the 2nd ACM SIGPLAN Program Protection and Reverse Engineering Workshop, p. 4. ACM (2013)","DOI":"10.1145\/2430553.2430557"},{"key":"14_CR12","doi-asserted-by":"crossref","unstructured":"David, Y., Partush, N., Yahav, E.: Statistical similarity of binaries. In: Proceedings of the 37th ACM SIGPLAN Conference on Programming Language Design and Implementation (PLDI), pp. 266\u2013280. ACM (2016)","DOI":"10.1145\/2908080.2908126"},{"key":"14_CR13","doi-asserted-by":"crossref","unstructured":"David, Y., Yahav, E.: Tracelet-based code search in executables. In: ACM SIGPLAN Notices, vol. 49, pp. 349\u2013360. ACM (2014)","DOI":"10.1145\/2666356.2594343"},{"key":"14_CR14","first-page":"1","volume":"5","author":"T Dullien","year":"2005","unstructured":"Dullien, T., Rolles, R.: Graph-based comparison of executable objects (English version). SSTIC 5, 1\u20133 (2005)","journal-title":"SSTIC"},{"key":"14_CR15","volume-title":"The IDA Pro Book: The Unofficial Guide to the World\u2019s Most Popular Disassembler","author":"C Eagle","year":"2011","unstructured":"Eagle, C.: The IDA Pro Book: The Unofficial Guide to the World\u2019s Most Popular Disassembler. No Starch Press, San Francisco (2011)"},{"key":"14_CR16","doi-asserted-by":"crossref","unstructured":"Egele, M., Scholte, T., Kirda, E., Kruegel, C.: A survey on automated dynamic malware-analysis techniques and tools. ACM Comput. Surv. (CSUR) 44(2), 6 (2012)","DOI":"10.1145\/2089125.2089126"},{"key":"14_CR17","unstructured":"Egele, M., Woo, M., Chapman, P., Brumley, D.: Blanket execution: dynamic similarity testing for program binaries and components. In: Usenix Security, pp. 303\u2013317 (2014)"},{"issue":"3","key":"14_CR18","doi-asserted-by":"crossref","first-page":"540","DOI":"10.1175\/1520-0493(2001)129<0540:EDAASM>2.0.CO;2","volume":"129","author":"KL Elmore","year":"2001","unstructured":"Elmore, K.L., Richman, M.B.: Euclidean distance as a similarity metric for principal component analysis. Mon. Weather Rev. 129(3), 540\u2013549 (2001)","journal-title":"Mon. Weather Rev."},{"key":"14_CR19","doi-asserted-by":"crossref","unstructured":"Eschweiler, S., Yakdan, K., Gerhards-Padilla, E.: discovRE: efficient cross-architecture identification of bugs in binary code. In Proceedings of the 23th Symposium on Network and Distributed System Security (NDSS) (2016)","DOI":"10.14722\/ndss.2016.23185"},{"key":"14_CR20","doi-asserted-by":"crossref","first-page":"46","DOI":"10.1016\/j.diin.2015.06.001","volume":"15","author":"MR Farhadi","year":"2015","unstructured":"Farhadi, M.R., Fung, B.C., Fung, Y.B., Charland, P., Preda, S., Debbabi, M.: Scalable code clone search for malware analysis. Digital Invest. 15, 46\u201360 (2015)","journal-title":"Digital Invest."},{"key":"14_CR21","doi-asserted-by":"crossref","unstructured":"Feng, Q., Zhou, R., Xu, C., Cheng, Y., Testa, B., Yin, H.: Scalable graph-based bug search for firmware images. In: Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security (CCS), pp. 480\u2013491. ACM (2016)","DOI":"10.1145\/2976749.2978370"},{"issue":"1","key":"14_CR22","doi-asserted-by":"crossref","first-page":"63","DOI":"10.1023\/A:1007421302149","volume":"32","author":"E Frank","year":"1998","unstructured":"Frank, E., Wang, Y., Inglis, S., Holmes, G., Witten, I.H.: Using model trees for classification. Mach. Learn. 32(1), 63\u201376 (1998)","journal-title":"Mach. Learn."},{"key":"14_CR23","doi-asserted-by":"crossref","unstructured":"Gascon, H., Yamaguchi, F., Arp, D., Rieck, K.: Structural detection of android malware using embedded call graphs. In: Proceedings of the 2013 ACM Workshop on Artificial Intelligence and Security (AISec), pp. 45\u201354. ACM (2013)","DOI":"10.1145\/2517312.2517315"},{"key":"14_CR24","unstructured":"Griffin, C., Theory, G.: Penn State Math 485 Lecture Notes (2012). \nhttp:\/\/www.personal.psu.edu\/cxg286\/Math485.pdf"},{"key":"14_CR25","doi-asserted-by":"crossref","unstructured":"Hido, S., Kashima, H.: A linear-time graph kernel. In: Ninth IEEE International Conference on Data Mining, ICDM 2009, pp. 179\u2013188. IEEE (2009)","DOI":"10.1109\/ICDM.2009.30"},{"key":"14_CR26","doi-asserted-by":"crossref","unstructured":"Hu, X., Chiueh, T.-C., Shin, K.G.: Large-scale malware indexing using function-call graphs. In: Proceedings of the 16th ACM Conference on Computer and Communications Security (CCS), pp. 611\u2013620. ACM (2009)","DOI":"10.1145\/1653662.1653736"},{"key":"14_CR27","doi-asserted-by":"crossref","unstructured":"Huang, H., Youssef, A.M., Debbabi, M.: BinSequence: fast, accurate and scalable binary code reuse detection. In: Proceedings of the 2017 ACM on Asia Conference on Computer and Communications Security (ASIA CCS), pp. 155\u2013166. ACM (2017)","DOI":"10.1145\/3052973.3052974"},{"key":"14_CR28","doi-asserted-by":"crossref","unstructured":"Jacobson, E.R., Rosenblum, N., Miller, B.P.: Labeling library functions in stripped binaries. In: Proceedings of the 10th ACM SIGPLAN-SIGSOFT Workshop on Program Analysis for Software Tools (PASTE), pp. 1\u20138. ACM (2011)","DOI":"10.1145\/2024569.2024571"},{"key":"14_CR29","doi-asserted-by":"crossref","unstructured":"Junod, P., Rinaldini, J., Wehrli, J., Michielin, J.: Obfuscator-LLVM: software protection for the masses. In: Proceedings of the 1st International Workshop on Software PROtection (SPRO), pp. 3\u20139. IEEE Press (2015)","DOI":"10.1109\/SPRO.2015.10"},{"key":"14_CR30","unstructured":"Khoo, W.M.: Decompilation as search. Technical report, University of Cambridge, Computer Laboratory (2013)"},{"key":"14_CR31","doi-asserted-by":"crossref","unstructured":"Khoo, W.M., Mycroft, A., Anderson, R.: Rendezvous: a search engine for binary code. In: Proceedings of the 10th Working Conference on Mining Software Repositories (MSR), pp. 329\u2013338. IEEE Press (2013)","DOI":"10.1109\/MSR.2013.6624046"},{"key":"14_CR32","doi-asserted-by":"crossref","unstructured":"Kolbitsch, C., Holz, T., Kruegel, C., Kirda, E.: Inspector gadget: automated extraction of proprietary gadgets from malware binaries. In: 2010 IEEE Symposium on Security and Privacy (SP), pp. 29\u201344. IEEE (2010)","DOI":"10.1109\/SP.2010.10"},{"key":"14_CR33","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"207","DOI":"10.1007\/11663812_11","volume-title":"Recent Advances in Intrusion Detection","author":"C Kruegel","year":"2006","unstructured":"Kruegel, C., Kirda, E., Mutz, D., Robertson, W., Vigna, G.: Polymorphic worm detection using structural information of executables. In: Valdes, A., Zamboni, D. (eds.) RAID 2005. LNCS, vol. 3858, pp. 207\u2013226. Springer, Heidelberg (2006). doi:\n10.1007\/11663812_11"},{"key":"14_CR34","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/978-3-319-11379-1_1","volume-title":"Research in Attacks, Intrusions and Defenses","author":"M K\u00fchrer","year":"2014","unstructured":"K\u00fchrer, M., Rossow, C., Holz, T.: Paint it black: evaluating the effectiveness of malware blacklists. In: Stavrou, A., Bos, H., Portokalidis, G. (eds.) RAID 2014. LNCS, vol. 8688, pp. 1\u201321. Springer, Cham (2014). doi:\n10.1007\/978-3-319-11379-1_1"},{"issue":"3","key":"14_CR35","doi-asserted-by":"crossref","first-page":"201","DOI":"10.1007\/s11416-010-0148-y","volume":"7","author":"D Lin","year":"2011","unstructured":"Lin, D., Stamp, M.: Hunting for undetectable metamorphic viruses. J. Comput. Virol. 7(3), 201\u2013214 (2011)","journal-title":"J. Comput. Virol."},{"issue":"3","key":"14_CR36","doi-asserted-by":"crossref","first-page":"253","DOI":"10.1007\/s10044-012-0284-8","volume":"16","author":"L Livi","year":"2013","unstructured":"Livi, L., Rizzi, A.: The graph matching problem. Pattern Anal. Appl. 16(3), 253\u2013283 (2013)","journal-title":"Pattern Anal. Appl."},{"key":"14_CR37","doi-asserted-by":"crossref","unstructured":"Martignoni, L., Christodorescu, M., Jha, S.: Omniunpack: fast, generic, and safe unpacking of malware. In: Twenty-Third Annual Computer Security Applications Conference, ACSAC 2007, pp. 431\u2013441. IEEE (2007)","DOI":"10.1109\/ACSAC.2007.15"},{"key":"14_CR38","doi-asserted-by":"crossref","unstructured":"Nouh, L., Rahimian, A., Mouheb, D., Debbabi, M., Hanna, A.: BinSign: fingerprinting binary functions to support automated analysis of code executables. In: IFIP International Information Security and Privacy Conference (IFIP SEC). Springer (2017)","DOI":"10.1007\/978-3-319-58469-0_23"},{"issue":"8","key":"14_CR39","doi-asserted-by":"crossref","first-page":"1226","DOI":"10.1109\/TPAMI.2005.159","volume":"27","author":"H Peng","year":"2005","unstructured":"Peng, H., Long, F., Ding, C.: Feature selection based on mutual information criteria of max-dependency, max-relevance, and min-redundancy. IEEE Trans. Pattern Anal. Mach. Intell. (TPAMI) 27(8), 1226\u20131238 (2005)","journal-title":"IEEE Trans. Pattern Anal. Mach. Intell. (TPAMI)"},{"key":"14_CR40","doi-asserted-by":"crossref","unstructured":"Pewny, J., Garmany, B., Gawlik, R., Rossow, C., Holz, T.: Cross-architecture bug search in binary executables. In: 2015 IEEE Symposium on Security and Privacy (SP), pp. 709\u2013724. IEEE (2015)","DOI":"10.1109\/SP.2015.49"},{"issue":"2","key":"14_CR41","doi-asserted-by":"crossref","first-page":"187","DOI":"10.1109\/TSE.2015.2470241","volume":"42","author":"J Qiu","year":"2016","unstructured":"Qiu, J., Su, X., Ma, P.: Using reduced execution flow graph to identify library functions in binary code. IEEE Trans. Softw. Eng. (TSE) 42(2), 187\u2013202 (2016)","journal-title":"IEEE Trans. Softw. Eng. (TSE)"},{"key":"14_CR42","doi-asserted-by":"crossref","unstructured":"Rad, B.B., Masrom, M., Ibrahim, S.: Opcodes histogram for classifying metamorphic portable executables malware. In: 2012 International Conference on e-Learning and e-Technologies in Education (ICEEE), pp. 209\u2013213. IEEE (2012)","DOI":"10.1109\/ICeLeTE.2012.6333411"},{"key":"14_CR43","unstructured":"Ramaswami, M., Bhaskaran, R.: A study on feature selection techniques in educational data mining. arXiv preprint \narXiv:0912.3924\n\n (2009)"},{"key":"14_CR44","doi-asserted-by":"crossref","first-page":"463","DOI":"10.1007\/978-3-540-35488-8_23","volume-title":"Feature Extraction","author":"D Roobaert","year":"2006","unstructured":"Roobaert, D., Karakoulas, G., Chawla, N.V.: Information gain, correlation and support vector machines. In: Guyon, I., Nikravesh, M., Gunn, S., Zadeh, L.A. (eds.) Feature Extraction. STUDFUZZ, vol. 207, pp. 463\u2013470. Springer, Heidelberg (2006)"},{"key":"14_CR45","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"172","DOI":"10.1007\/978-3-642-23822-2_10","volume-title":"Computer Security \u2013 ESORICS 2011","author":"N Rosenblum","year":"2011","unstructured":"Rosenblum, N., Zhu, X., Miller, B.P.: Who wrote this code? identifying the authors of program binaries. In: Atluri, V., Diaz, C. (eds.) ESORICS 2011. LNCS, vol. 6879, pp. 172\u2013189. Springer, Heidelberg (2011). doi:\n10.1007\/978-3-642-23822-2_10"},{"issue":"1","key":"14_CR46","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1007\/s11416-012-0171-2","volume":"9","author":"AH Toderici","year":"2013","unstructured":"Toderici, A.H., Stamp, M.: Chi-squared distance and metamorphic virus detection. J. Comput. Virol. Hacking Tech. 9(1), 1\u201314 (2013)","journal-title":"J. Comput. Virol. Hacking Tech."},{"key":"14_CR47","doi-asserted-by":"crossref","unstructured":"van der Veen, V., G\u00f6ktas, E., Contag, M., Pawoloski, A., Chen, X., Rawat, S., Bos, H., Holz, T., Athanasopoulos, E., Giuffrida, C.: A tough call: mitigating advanced code-reuse attacks at the binary level. In: 2016 IEEE Symposium on Security and Privacy (SP), pp. 934\u2013953. IEEE (2016)","DOI":"10.1109\/SP.2016.60"},{"key":"14_CR48","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"165","DOI":"10.1007\/978-3-319-45719-2_8","volume-title":"Research in Attacks, Intrusions, and Defenses","author":"A Yokoyama","year":"2016","unstructured":"Yokoyama, A., et al.: SandPrint: fingerprinting malware sandboxes to provide intelligence for sandbox evasion. In: Monrose, F., Dacier, M., Blanc, G., Garcia-Alfaro, J. (eds.) RAID 2016. LNCS, vol. 9854, pp. 165\u2013187. Springer, Cham (2016). doi:\n10.1007\/978-3-319-45719-2_8"},{"key":"14_CR49","doi-asserted-by":"crossref","unstructured":"Zeng, J., Fu, Y., Miller, K.A., Lin, Z., Zhang, X., Xu, D.: Obfuscation resilient binary code reuse through trace-oriented programming. In: Proceedings of the 2013 ACM SIGSAC Conference on Computer & Communications Security (CCS), pp. 487\u2013498. ACM (2013)","DOI":"10.1145\/2508859.2516664"},{"key":"14_CR50","unstructured":"Ziegel, E.R.: Probability and Statistics for Engineering and the Sciences. Technometrics (2012)"}],"container-title":["Lecture Notes in Computer Science","Detection of Intrusions and Malware, and Vulnerability Assessment"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-60876-1_14","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2017,6,12]],"date-time":"2017-06-12T12:16:34Z","timestamp":1497269794000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-319-60876-1_14"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2017]]},"ISBN":["9783319608754","9783319608761"],"references-count":50,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-60876-1_14","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2017]]}}}