The method of elf-files identification based on the metric classification algorithms
When performing the internal audit of computer equipment an important problem is to identify the elf (executable and linkable format) files stored on the investigated hard drive. To solve this problem, we propose a method of identification of unknown elf-ffles based on the metric classification algo...
Main Authors: | , , , |
---|---|
Format: | Article |
Language: | English |
Published: |
FRUCT
2016-04-01
|
Series: | Proceedings of the XXth Conference of Open Innovations Association FRUCT |
Subjects: | |
Online Access: | https://fruct.org/publications/fruct18/files/Zik.pdf
|
_version_ | 1811232277027356672 |
---|---|
author | Igor Zikratov Igor Pantiukhin Irina Krivtsova Nikita Druzhinin |
author_facet | Igor Zikratov Igor Pantiukhin Irina Krivtsova Nikita Druzhinin |
author_sort | Igor Zikratov |
collection | DOAJ |
description | When performing the internal audit of computer equipment an important problem is to identify the elf (executable and linkable format) files stored on the investigated hard drive. To solve this problem, we propose a method of identification of unknown elf-ffles based on the metric classification algorithms. The method consists of three stages. On the first stage the preparation of the training sample by the disassembly of each file and submitting it in the form of an ordered set of the 118 elements is implemented. Each of these elements is the frequency of occurrences of the 118 most commonly used commands in the assembler code. Each program in the sample is represented by several sets, corresponding to different versions or operating systems in which this software is installed. Then, the Minkowski metric of each sample file and identifiable file is calculated. For the method of potential functions the selection of the reference elements of each set is obtained. On the third stage using the metric classification algorithms we evaluate affiliation of the identifiable file for a particular program from the sample. To approbate proposed method the experiment with the use of this method was conducted; results showing the accuracy of identification of elf-files was equal to 89,60% were obtained. The results indicate that this method is applicable in problems of identification of elf-files while conducting the internal audit of computer equipment. The advantages of the method are the accuracy of program identification regardless of the elf-files versions in the Linux operating systems. The ease of implementation of our method and the identification execution speed can be used not only in tasks of internal audit, but also in other tasks of computer forensics. |
first_indexed | 2024-04-12T11:00:41Z |
format | Article |
id | doaj.art-ddf97ad6288446048d2768b106e16ae6 |
institution | Directory Open Access Journal |
issn | 2305-7254 2343-0737 |
language | English |
last_indexed | 2024-04-12T11:00:41Z |
publishDate | 2016-04-01 |
publisher | FRUCT |
record_format | Article |
series | Proceedings of the XXth Conference of Open Innovations Association FRUCT |
spelling | doaj.art-ddf97ad6288446048d2768b106e16ae62022-12-22T03:35:59ZengFRUCTProceedings of the XXth Conference of Open Innovations Association FRUCT2305-72542343-07372016-04-016641839740310.1109/FRUCT-ISPIT.2016.7561556The method of elf-files identification based on the metric classification algorithmsIgor Zikratov0Igor Pantiukhin1Irina Krivtsova2Nikita Druzhinin3ITMO University, Saint Petersburg, RussiaITMO University, Saint Petersburg, RussiaITMO University, Saint Petersburg, RussiaITMO University, Saint Petersburg, RussiaWhen performing the internal audit of computer equipment an important problem is to identify the elf (executable and linkable format) files stored on the investigated hard drive. To solve this problem, we propose a method of identification of unknown elf-ffles based on the metric classification algorithms. The method consists of three stages. On the first stage the preparation of the training sample by the disassembly of each file and submitting it in the form of an ordered set of the 118 elements is implemented. Each of these elements is the frequency of occurrences of the 118 most commonly used commands in the assembler code. Each program in the sample is represented by several sets, corresponding to different versions or operating systems in which this software is installed. Then, the Minkowski metric of each sample file and identifiable file is calculated. For the method of potential functions the selection of the reference elements of each set is obtained. On the third stage using the metric classification algorithms we evaluate affiliation of the identifiable file for a particular program from the sample. To approbate proposed method the experiment with the use of this method was conducted; results showing the accuracy of identification of elf-files was equal to 89,60% were obtained. The results indicate that this method is applicable in problems of identification of elf-files while conducting the internal audit of computer equipment. The advantages of the method are the accuracy of program identification regardless of the elf-files versions in the Linux operating systems. The ease of implementation of our method and the identification execution speed can be used not only in tasks of internal audit, but also in other tasks of computer forensics.https://fruct.org/publications/fruct18/files/Zik.pdf information securityaudit of mediumidentification fileself-filesmetric algorithms |
spellingShingle | Igor Zikratov Igor Pantiukhin Irina Krivtsova Nikita Druzhinin The method of elf-files identification based on the metric classification algorithms Proceedings of the XXth Conference of Open Innovations Association FRUCT information security audit of medium identification files elf-files metric algorithms |
title | The method of elf-files identification based on the metric classification algorithms |
title_full | The method of elf-files identification based on the metric classification algorithms |
title_fullStr | The method of elf-files identification based on the metric classification algorithms |
title_full_unstemmed | The method of elf-files identification based on the metric classification algorithms |
title_short | The method of elf-files identification based on the metric classification algorithms |
title_sort | method of elf files identification based on the metric classification algorithms |
topic | information security audit of medium identification files elf-files metric algorithms |
url | https://fruct.org/publications/fruct18/files/Zik.pdf
|
work_keys_str_mv | AT igorzikratov themethodofelffilesidentificationbasedonthemetricclassificationalgorithms AT igorpantiukhin themethodofelffilesidentificationbasedonthemetricclassificationalgorithms AT irinakrivtsova themethodofelffilesidentificationbasedonthemetricclassificationalgorithms AT nikitadruzhinin themethodofelffilesidentificationbasedonthemetricclassificationalgorithms AT igorzikratov methodofelffilesidentificationbasedonthemetricclassificationalgorithms AT igorpantiukhin methodofelffilesidentificationbasedonthemetricclassificationalgorithms AT irinakrivtsova methodofelffilesidentificationbasedonthemetricclassificationalgorithms AT nikitadruzhinin methodofelffilesidentificationbasedonthemetricclassificationalgorithms |