Skip to main navigation Skip to search Skip to main content

Identifying ubiquitious third-party libraries in compiled executables using annotated and translated disassembled code with supervised machine learning

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

5 Scopus citations

Abstract

The size and complexity of the software ecosystem is a major challenge for vendors, asset owners and cybersecurity professionals who need to understand the security posture of these systems. Annotated and Translated Disassembled Code is a graph based datastore designed to organize firmware and software analysis data across builds, packages and systems, providing a highly scalable platform enabling automated binary software analysis tasks including corpora construction and storage for machine learning. This paper describes an approach for the identification of ubiquitous third-party libraries in firmware and software using Annotated and Translated Disassembled Code and supervised machine learning. Annotated and Translated Disassembled Code provide matched libraries, function names and addresses of previously unidentified code in software as it is being automatically analyzed. This data can be ingested by other software analysis tools to improve accuracy and save time. Defenders can add the identified libraries to their vulnerability searches and add effective detection and mitigation into their operating environment.

Original languageEnglish
Title of host publicationProceedings - 2020 IEEE Symposium on Security and Privacy Workshops, SPW 2020
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages157-162
Number of pages6
ISBN (Electronic)9781728193465
ISBN (Print)9781728193465
DOIs
StatePublished - May 2020
Event2020 IEEE Symposium on Security and Privacy Workshops, SPW 2020 - Virtual, San Francisco, United States
Duration: May 21 2020 → …

Publication series

NameProceedings - 2020 IEEE Symposium on Security and Privacy Workshops, SPW 2020

Conference

Conference2020 IEEE Symposium on Security and Privacy Workshops, SPW 2020
Country/TerritoryUnited States
CityVirtual, San Francisco
Period05/21/20 → …

Keywords

  • Bayes method
  • Classification algorithms
  • Clustering methods
  • Databases
  • Graph theory
  • Internet
  • K-nearest neighbor search
  • Machine learning
  • Matrices
  • Neural network
  • Reverse engineering
  • Supervised learning
  • Supply chain management
  • Support vector machines

Fingerprint

Dive into the research topics of 'Identifying ubiquitious third-party libraries in compiled executables using annotated and translated disassembled code with supervised machine learning'. Together they form a unique fingerprint.

Cite this