The method of elf-files identification based on the metric classification algorithms

When performing the internal audit of computer equipment an important problem is to identify the elf (executable and linkable format) files stored on the investigated hard drive. To solve this problem, we propose a method of identification of unknown elf-ffles based on the metric classification algo...

Full description

Bibliographic Details
Main Authors: Igor Zikratov, Igor Pantiukhin, Irina Krivtsova, Nikita Druzhinin
Format: Article
Language:English
Published: FRUCT 2016-04-01
Series:Proceedings of the XXth Conference of Open Innovations Association FRUCT
Subjects:
Online Access:https://fruct.org/publications/fruct18/files/Zik.pdf
_version_ 1811232277027356672
author Igor Zikratov
Igor Pantiukhin
Irina Krivtsova
Nikita Druzhinin
author_facet Igor Zikratov
Igor Pantiukhin
Irina Krivtsova
Nikita Druzhinin
author_sort Igor Zikratov
collection DOAJ
description When performing the internal audit of computer equipment an important problem is to identify the elf (executable and linkable format) files stored on the investigated hard drive. To solve this problem, we propose a method of identification of unknown elf-ffles based on the metric classification algorithms. The method consists of three stages. On the first stage the preparation of the training sample by the disassembly of each file and submitting it in the form of an ordered set of the 118 elements is implemented. Each of these elements is the frequency of occurrences of the 118 most commonly used commands in the assembler code. Each program in the sample is represented by several sets, corresponding to different versions or operating systems in which this software is installed. Then, the Minkowski metric of each sample file and identifiable file is calculated. For the method of potential functions the selection of the reference elements of each set is obtained. On the third stage using the metric classification algorithms we evaluate affiliation of the identifiable file for a particular program from the sample. To approbate proposed method the experiment with the use of this method was conducted; results showing the accuracy of identification of elf-files was equal to 89,60% were obtained. The results indicate that this method is applicable in problems of identification of elf-files while conducting the internal audit of computer equipment. The advantages of the method are the accuracy of program identification regardless of the elf-files versions in the Linux operating systems. The ease of implementation of our method and the identification execution speed can be used not only in tasks of internal audit, but also in other tasks of computer forensics.
first_indexed 2024-04-12T11:00:41Z
format Article
id doaj.art-ddf97ad6288446048d2768b106e16ae6
institution Directory Open Access Journal
issn 2305-7254
2343-0737
language English
last_indexed 2024-04-12T11:00:41Z
publishDate 2016-04-01
publisher FRUCT
record_format Article
series Proceedings of the XXth Conference of Open Innovations Association FRUCT
spelling doaj.art-ddf97ad6288446048d2768b106e16ae62022-12-22T03:35:59ZengFRUCTProceedings of the XXth Conference of Open Innovations Association FRUCT2305-72542343-07372016-04-016641839740310.1109/FRUCT-ISPIT.2016.7561556The method of elf-files identification based on the metric classification algorithmsIgor Zikratov0Igor Pantiukhin1Irina Krivtsova2Nikita Druzhinin3ITMO University, Saint Petersburg, RussiaITMO University, Saint Petersburg, RussiaITMO University, Saint Petersburg, RussiaITMO University, Saint Petersburg, RussiaWhen performing the internal audit of computer equipment an important problem is to identify the elf (executable and linkable format) files stored on the investigated hard drive. To solve this problem, we propose a method of identification of unknown elf-ffles based on the metric classification algorithms. The method consists of three stages. On the first stage the preparation of the training sample by the disassembly of each file and submitting it in the form of an ordered set of the 118 elements is implemented. Each of these elements is the frequency of occurrences of the 118 most commonly used commands in the assembler code. Each program in the sample is represented by several sets, corresponding to different versions or operating systems in which this software is installed. Then, the Minkowski metric of each sample file and identifiable file is calculated. For the method of potential functions the selection of the reference elements of each set is obtained. On the third stage using the metric classification algorithms we evaluate affiliation of the identifiable file for a particular program from the sample. To approbate proposed method the experiment with the use of this method was conducted; results showing the accuracy of identification of elf-files was equal to 89,60% were obtained. The results indicate that this method is applicable in problems of identification of elf-files while conducting the internal audit of computer equipment. The advantages of the method are the accuracy of program identification regardless of the elf-files versions in the Linux operating systems. The ease of implementation of our method and the identification execution speed can be used not only in tasks of internal audit, but also in other tasks of computer forensics.https://fruct.org/publications/fruct18/files/Zik.pdf information securityaudit of mediumidentification fileself-filesmetric algorithms
spellingShingle Igor Zikratov
Igor Pantiukhin
Irina Krivtsova
Nikita Druzhinin
The method of elf-files identification based on the metric classification algorithms
Proceedings of the XXth Conference of Open Innovations Association FRUCT
information security
audit of medium
identification files
elf-files
metric algorithms
title The method of elf-files identification based on the metric classification algorithms
title_full The method of elf-files identification based on the metric classification algorithms
title_fullStr The method of elf-files identification based on the metric classification algorithms
title_full_unstemmed The method of elf-files identification based on the metric classification algorithms
title_short The method of elf-files identification based on the metric classification algorithms
title_sort method of elf files identification based on the metric classification algorithms
topic information security
audit of medium
identification files
elf-files
metric algorithms
url https://fruct.org/publications/fruct18/files/Zik.pdf
work_keys_str_mv AT igorzikratov themethodofelffilesidentificationbasedonthemetricclassificationalgorithms
AT igorpantiukhin themethodofelffilesidentificationbasedonthemetricclassificationalgorithms
AT irinakrivtsova themethodofelffilesidentificationbasedonthemetricclassificationalgorithms
AT nikitadruzhinin themethodofelffilesidentificationbasedonthemetricclassificationalgorithms
AT igorzikratov methodofelffilesidentificationbasedonthemetricclassificationalgorithms
AT igorpantiukhin methodofelffilesidentificationbasedonthemetricclassificationalgorithms
AT irinakrivtsova methodofelffilesidentificationbasedonthemetricclassificationalgorithms
AT nikitadruzhinin methodofelffilesidentificationbasedonthemetricclassificationalgorithms