FIELD: hardware identification.
SUBSTANCE: method for express identification of hardware architecture of an executing device based on the analysis of binary data. In the method, an unmodified memory image of the device under study is obtained, including the machine code of the control program, areas of high-entropy and low-entropy data are excluded from the memory image of the device under study, in the obtained memory area, commands of conditional and unconditional transfers are searched for relative offset in accordance with the alleged hardware architecture by continuous decoding binary data, while the above search is carried out on the basis of the decoded machine codes of conditional and unconditional transfers of the hypothetical hardware architecture obtained from the database of hardware architectures, control transfer graphs are formed and analysed based on the above found commands, after which a decision is made on the correct identification of the hardware architecture on based on the obtained characteristics of control transfer graphs.
EFFECT: technical result consists of increasing the efficiency of identifying the hardware architecture of the executing device.
7 cl, 6 dwg, 1 tbl
Title | Year | Author | Number |
---|---|---|---|
METHOD AND SYSTEM FOR DETECTING MALICIOUS FILES IN A NON-ISOLATED MEDIUM | 2020 |
|
RU2722692C1 |
METHOD AND SYSTEM FOR DETERMINING BELONGING OF SOFTWARE BY ITS MACHINE CODE | 2019 |
|
RU2728497C1 |
PARALLEL COMPUTING ARCHITECTURE | 2016 |
|
RU2644535C2 |
LDPC DECODING DEVICE AND METHOD | 2005 |
|
RU2392737C2 |
METHOD AND SYSTEM FOR CLUSTERING EXECUTABLE FILES | 2021 |
|
RU2778979C1 |
VIRTUALISATION FOR DIVERSIFIED PROTECTION FROM UNAUTHORISED INTERFERENCE | 2007 |
|
RU2458394C2 |
METHOD OF FUNCTIONING COMPUTER DEVICE OPERATING SYSTEM OF SOFTWARE AND HARDWARE COMPLEX | 2016 |
|
RU2626350C1 |
DETERMINING THE ORDER OF INITIALIZATION OF STATIC OBJECTS | 2014 |
|
RU2656580C2 |
INSTRUCTION AND LOGICAL SCHEME FOR SORTING AND LOADING OF SAVE INSTRUCTIONS | 2014 |
|
RU2663362C1 |
IMPROVED PUNCTURING AND CODE STRUCTURE WITH LOW DENSITY OF PARITY CHECKS (LDPC) | 2017 |
|
RU2718171C1 |
Authors
Dates
2024-04-26—Published
2022-07-05—Filed