摘要
针对嵌入式固件逆向解析过程中操作系统类型识别困难的问题,提出了一种基于多属性决策的嵌入式操作系统识别技术。对固件映像中反映出的嵌入式操作系统的多种特征进行综合分析并构建了相关的识别模型,利用向量夹角余弦计算与标准系统之间的相似度,最后阐述了识别的基本思想和具体实现流程。实验结果表明,该方法在某些特征缺失的情况下仍能得到较准确的识别结果。
Concerning the problem that it is difficult to recognize operating system type in embedded firmware reversing analysis,a recognition technology based on Multi-Attribute Decision Making(MADM) was proposed.The paper comprehensively analyzed the multiple features in the firmware,built a recognition model,and calculated the similarity using the vector included angle cosine method.The basic idea of recognition and the concrete realization of the process were described.The experimental results show that this method can get more accurate recognition results in the cases with some features missing.
出处
《计算机应用》
CSCD
北大核心
2012年第4期1060-1063,共4页
journal of Computer Applications
关键词
嵌入式
固件
逆向解析
操作系统
多属性决策
向量夹角余弦
相似度
embedded
firmware
reverse analysis
operating system
Multi-Attribute Decision Making(MADM)
vector included angle cosine
similarity