{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,16]],"date-time":"2026-03-16T10:05:57Z","timestamp":1773655557780,"version":"3.50.1"},"reference-count":40,"publisher":"Allerton Press","issue":"7","license":[{"start":{"date-parts":[[2020,12,1]],"date-time":"2020-12-01T00:00:00Z","timestamp":1606780800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2020,12,1]],"date-time":"2020-12-01T00:00:00Z","timestamp":1606780800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Aut. Control Comp. Sci."],"published-print":{"date-parts":[[2020,12]]},"DOI":"10.3103\/s0146411620070044","type":"journal-article","created":{"date-parts":[[2021,2,8]],"date-time":"2021-02-08T12:46:46Z","timestamp":1612788406000},"page":"619-629","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":5,"title":["On the Automatic Analysis of the Practical Resistance of Obfuscating Transformations"],"prefix":"10.3103","volume":"54","author":[{"given":"P. D.","family":"Borisov","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yu. V.","family":"Kosolapov","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1627","published-online":{"date-parts":[[2021,2,8]]},"reference":[{"key":"7279_CR1","doi-asserted-by":"crossref","unstructured":"Siegmund, J., Program comprehension: Past, present, and future, IEEE 23rd International Conference on Software Analysis, Evolution, and Reengineering (SANER), 2016, vol. 5, pp. 13\u201320.","DOI":"10.1109\/SANER.2016.35"},{"key":"7279_CR2","doi-asserted-by":"crossref","unstructured":"Avidan, E. and Feitelson, D.G., From obfuscation to comprehension, Proceedings of the 2015 IEEE 23rd International Conference on Program Comprehension, 2015, pp. 178\u2013181.","DOI":"10.1109\/ICPC.2015.27"},{"key":"7279_CR3","first-page":"52","volume":"1","author":"A.G. Pozdeev","year":"2009","unstructured":"Pozdeev, A.G., Krivopalov, V.N., Romashkin, E.V., and Radchenko, E.D., Mathematical and software tools for program obfuscation, Prikl. Diskretn. Mat., 2009, vol. 1, pp. 52\u201353.","journal-title":"Prikl. Diskretn. Mat."},{"key":"7279_CR4","unstructured":"Chernov, A.V., Analyzing confusing program transformations, 2002. http:\/\/www.citforum.ru\/security\/articles\/analysis\/."},{"key":"7279_CR5","doi-asserted-by":"crossref","unstructured":"Kuzurin, N., Shokurov, A., Varnovsky, N., and Zakharov, V., On the concept of software obfuscation in computer security, International Conference on Information Security, Berlin\u2013Heidelberg: Springer, 2007, pp. 281\u2013298.","DOI":"10.1007\/978-3-540-75496-1_19"},{"key":"7279_CR6","doi-asserted-by":"publisher","first-page":"644","DOI":"10.1109\/TIT.1976.1055638","volume":"22","author":"W. Diffie","year":"1976","unstructured":"Diffie, W. and Hellman, M., New directions in cryptography, IEEE Trans. Inf. Theory, 1976, vol. 22, no. 6, pp.\u00a0644\u2013654.","journal-title":"IEEE Trans. Inf. Theory"},{"key":"7279_CR7","doi-asserted-by":"publisher","first-page":"735","DOI":"10.1109\/TSE.2002.1027797","volume":"28","author":"C.S. Collberg","year":"2002","unstructured":"Collberg, C.S. and Thomborson, C., Watermarking, tamper-proofing, and obfuscation tools for software protection, IEEE Trans. Software Eng., 2002, vol. 28, no. 8, pp. 735\u2013746.","journal-title":"IEEE Trans. Software Eng."},{"key":"7279_CR8","doi-asserted-by":"crossref","unstructured":"Lee, B., Kim, Y., and Kim, J., binOb+: A framework for potent and stealthy binary obfuscation, Proceedings of the 5th ACM Symposium on Information, Computer and Communications Security, ASIACCS 2010, 2010, pp. 271\u2013281.","DOI":"10.1145\/1755688.1755722"},{"key":"7279_CR9","doi-asserted-by":"publisher","first-page":"211","DOI":"10.1007\/s11416-008-0084-2","volume":"4","author":"J.M. Borello","year":"2008","unstructured":"Borello, J.M. and Me, L., Code obfuscation techniques for metamorphic viruses, J. Comput. Virol., 2008, vol.\u00a04, no. 3, pp. 211\u2013220.","journal-title":"J. Comput. Virol."},{"key":"7279_CR10","doi-asserted-by":"crossref","unstructured":"Moser, A., Kruegel, C., and Kirda, E., Limits of static analysis for malware detection, Proceedings of Twenty-Third Annual Computer Security Applications Conference (ACSAC 2007), 2007, pp. 421\u2013430.","DOI":"10.1109\/ACSAC.2007.21"},{"key":"7279_CR11","doi-asserted-by":"crossref","unstructured":"Baiardi, F. and Sgandurra, D., An obfuscation-based approach against injection attacks, Proceedings of the Sixth International Conference on Availability, Reliability and Security (ARES), 2011, pp. 51\u201358.","DOI":"10.1109\/ARES.2011.17"},{"key":"7279_CR12","first-page":"93","volume":"28","author":"A.R. Nurmukhametov","year":"2016","unstructured":"Nurmukhametov, A.R., Use of diversifying and obfuscating transformations to change the signature of program code, Tr. Inst. Sist. Program. Ross. Akad. Nauk, 2016, vol. 28, no. 5, pp. 93\u2013104.","journal-title":"Tr. Inst. Sist. Program. Ross. Akad. Nauk"},{"key":"7279_CR13","doi-asserted-by":"publisher","first-page":"213","DOI":"10.18255\/1818-1015-2019-2-213-228","volume":"26","author":"Y.V. Kosolapov","year":"2019","unstructured":"Kosolapov, Y.V., About detection of code reuse attacks, Model. Anal. Inf. Sist., 2019, vol. 26, no. 2, pp. 213\u2013228.","journal-title":"Model. Anal. Inf. Sist."},{"key":"7279_CR14","unstructured":"Collberg, C., Thomborson, C., and Low, D., A Taxonomy of Obfuscating Transformations, Technical Report 148, The University of Auckland, 1997."},{"key":"7279_CR15","volume-title":"Similarity in programs","author":"A. Walenstein","year":"2007","unstructured":"Walenstein, A., El-Ramly, M., Cordy, J.R., Evans, W.S., Mahdavi, K., Pizka, M., Ramalingam, G., and von Gudenberg, J.W., Similarity in programs, Duplication, Redundancy, and Similarity in Software, 2007, pp. 1\u20138."},{"key":"7279_CR16","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/2110356.2110358","volume":"30","author":"V. Chipounov","year":"2012","unstructured":"Chipounov, V., Kuznetsov, V., and Candea, G., The S2E platform: Design, implementation, and applications, ACM Trans. Comput. Syst., 2012, vol. 30, no. 1, pp. 1\u201349.","journal-title":"ACM Trans. Comput. Syst."},{"key":"7279_CR17","unstructured":"Saudel, F. and Salwan, J., Triton: A dynamic symbolic execution framework, Symposium Sur La Security Des Technologies de L\u2019information et Des Communications, SSTIC, 2015, pp. 31\u201354."},{"key":"7279_CR18","doi-asserted-by":"crossref","unstructured":"Wang, Z., Ming, J., Jia, C., and Gao, D., Linear obfuscation to combat symbolic execution, Proceedings of Computer Security \u2013 ESORICS 2011, 2011, pp. 210\u2013226.","DOI":"10.1007\/978-3-642-23822-2_12"},{"key":"7279_CR19","doi-asserted-by":"publisher","first-page":"65","DOI":"10.1007\/978-0-387-68768-1_4","volume":"36","author":"D. Brumley","year":"2008","unstructured":"Brumley, D., Hartwig, C., Liang, Z., Newsome, J., Song, D., and Yin, H., Automatically identifying trigger-based behavior in malware, Botnet Detect., \n               Adv. Inf. Secur., 2008, vol. 36, pp. 65\u201388.","journal-title":"Adv. Inf. Secur."},{"key":"7279_CR20","doi-asserted-by":"publisher","first-page":"385","DOI":"10.1145\/360248.360252","volume":"19","author":"J.C. King","year":"1976","unstructured":"King, J.C., Symbolic execution and program testing, Commun. ACM, 1976, vol. 19, no. 7, pp. 385\u2013394.","journal-title":"Commun. ACM"},{"key":"7279_CR21","unstructured":"Cadar, C., Dunbar, D., and Engler, D.R., KLEE: Unassisted and automatic generation of high-coverage tests for complex systems programs, 8th USENIX Symposium on Operating Systems Design and Implementation, 2008, pp. 209\u2013224."},{"key":"7279_CR22","doi-asserted-by":"crossref","unstructured":"Shoshitaishvili, Y., et al., SoK: (State of) the art of war: Offensive techniques in binary analysis, IEEE Symposium on Security and Privacy, 2016, pp. 138\u2013157.","DOI":"10.1109\/SP.2016.17"},{"key":"7279_CR23","unstructured":"Sharif, M.I., Lanzi, A., Giffin, J.T., and Lee, W., Impeding malware analysis using conditional code obfuscation, Proceedings of NDSS, 2008, pp. 1\u201313."},{"key":"7279_CR24","unstructured":"Udupa, S.K., Debray, S.K., and Madou, M., Deobfuscation: Reverse engineering obfuscated code, Proceedings of the 12th Working Conference on Reverse Engineering (WCRE'05), 2005, pp. 44\u201353."},{"key":"7279_CR25","doi-asserted-by":"crossref","unstructured":"Nagarajan, V., Gupta, R., Zhang, X., Madou, M., and De Sutter, B., Matching control flow of program versions, IEEE International Conference on Software Maintenance, 2007, pp. 84\u201393.","DOI":"10.1109\/ICSM.2007.4362621"},{"key":"7279_CR26","doi-asserted-by":"crossref","unstructured":"Bonfante, G., Kaczmarek, M., and Marion, J.Y., Control flow graphs as malware signatures, International Workshop on the Theory of Computer Viruses, 2007, pp. 1\u20136.","DOI":"10.1109\/MALWARE.2008.4690851"},{"key":"7279_CR27","doi-asserted-by":"crossref","unstructured":"Park, Y., Reeves, D., Mulukutla, V., and Sundaravel, B., Fast malware classification by automated behavioral graph matching, Proceedings of the Sixth Annual Workshop on Cyber Security and Information Intelligence Research, 2010, pp. 1\u20134.","DOI":"10.1145\/1852666.1852716"},{"key":"7279_CR28","doi-asserted-by":"publisher","first-page":"233","DOI":"10.1007\/s11416-011-0151-y","volume":"7","author":"J. Kinable","year":"2011","unstructured":"Kinable, J. and Kostakis, O., Malware classification based on call graph clustering, J. Comput. Virol., 2011, vol.\u00a07, no. 4, pp. 233\u2013245.","journal-title":"J. Comput. Virol."},{"key":"7279_CR29","doi-asserted-by":"crossref","unstructured":"Lim, H.I., Comparing control flow graphs of binary programs through match propagation, IEEE 38th Annual Computer Software and Applications Conference, 2014, pp. 598\u2013599.","DOI":"10.1109\/COMPSAC.2014.84"},{"key":"7279_CR30","unstructured":"Dullien, T. and Rolles, R., Graph-Based Comparison of Executable Objects, 2005, pp. 1\u20138."},{"key":"7279_CR31","doi-asserted-by":"crossref","unstructured":"Chan, P.P.F. and Collberg, C., A method to evaluate CFG comparison algorithms, 14th International Conference on Quality Software, 2014, pp. 95\u2013104.","DOI":"10.1109\/QSIC.2014.28"},{"key":"7279_CR32","doi-asserted-by":"publisher","first-page":"123","DOI":"10.1002\/jgt.20296","volume":"58","author":"M. Axenovich","year":"2008","unstructured":"Axenovich, M., Kezdy, A., and Martin, R., On the editing distance of graphs, J. Graph Theory, 2008, vol. 58, no. 2, pp. 123\u2013138.","journal-title":"J. Graph Theory"},{"key":"7279_CR33","unstructured":"Borisov, P.D. and Kosolapov, Y.V., On the choice of characteristics for assessing the stability of obfuscating transformations, Sovremennye informatsionnye tekhnologii: Tendentsii i perspektivy razvitiya. Trudy XXV nauchnoi konferentsii SITO-2019 (Modern Information Technologies: Trends and Development Prospects. Proc. 25th Sci. Conf. SITO-2019), 2019, pp. 42\u201344."},{"key":"7279_CR34","volume-title":"Program Evolution. Processes of Software Change","author":"M.M. Lehman","year":"1985","unstructured":"Lehman, M.M. and Belady, L.A., Program Evolution. Processes of Software Change, Academic Press, 1985."},{"key":"7279_CR35","doi-asserted-by":"crossref","unstructured":"Schnappinger, M., Osman, M.H., Pretschner, A., Pizka, M., and Fietzke, A., Software quality assessment in practice: A hypothesis-driven framework, Proceedings of the 12th ACM\/IEEE International Symposium on Empirical Software Engineering and Measurement, 2018, pp. 1\u20136.","DOI":"10.1145\/3239235.3268922"},{"key":"7279_CR36","unstructured":"Borisov, P.D. and Kosolapov, Y.V., A model of the experimental analysis of the robustness of obfuscation algorithms, Sovremennye informatsionnye tekhnologii: Tendentsii i perspektivy razvitiya. Trudy XXV nauchnoi konferentsii SITO-2019 (Modern Information Technologies: Trends and Development Prospects. Proc. 25th Sci. Conf. SITO-2019), 2019, pp. 37\u201339."},{"key":"7279_CR37","unstructured":"IDA Pro. https:\/\/www.hex-rays.com\/products\/ida\/."},{"key":"7279_CR38","unstructured":"The LLVM Compiler Infrastructure. https:\/\/llvm.org\/."},{"key":"7279_CR39","unstructured":"McSema. https:\/\/github.com\/trailofbits\/mcsema."},{"key":"7279_CR40","doi-asserted-by":"crossref","unstructured":"Junod, P., Rinaldini, J., Wehrli, J., and Michieliny, J., Obfuscator-LLVM \u2013 software protection for the masses, 2015 IEEE\/ACM 1st International Workshop on Software Protection (SPRO), 2015, pp. 3\u20139.","DOI":"10.1109\/SPRO.2015.10"}],"container-title":["Automatic Control and Computer Sciences"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.3103\/S0146411620070044.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.3103\/S0146411620070044","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.3103\/S0146411620070044.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,3,15]],"date-time":"2026-03-15T22:00:48Z","timestamp":1773612048000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.3103\/S0146411620070044"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,12]]},"references-count":40,"journal-issue":{"issue":"7","published-print":{"date-parts":[[2020,12]]}},"alternative-id":["7279"],"URL":"https:\/\/doi.org\/10.3103\/s0146411620070044","relation":{},"ISSN":["0146-4116","1558-108X"],"issn-type":[{"value":"0146-4116","type":"print"},{"value":"1558-108X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2020,12]]},"assertion":[{"value":"18 July 2019","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"9 September 2019","order":2,"name":"revised","label":"Revised","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"11 September 2019","order":3,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"8 February 2021","order":4,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"The authors declare that they have no conflicts of interest.","order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"CONFLICT OF INTEREST"}},{"value":"Petr D. Borisov, orcid.org\/0000-0002-8919-8310, graduate student.Yury V. Kosolapov, orcid.org\/0000-0002-1491-524X, PhD.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"ADDITIONAL INFORMATION"}}]}}