Identifying Malicious Source Code Using LZJD

dc.contributor.advisorNicholas, Charles
dc.contributor.authorRoca, Alexander James
dc.contributor.departmentComputer Science and Electrical Engineering
dc.contributor.programComputer Science
dc.date.accessioned2022-09-29T15:37:51Z
dc.date.available2022-09-29T15:37:51Z
dc.date.issued2021-01-01
dc.description.abstractThis work presents a proof-of-concept of the use of Lempel-Ziv Jaccard Distance, or LZJD, as a means of detecting malicious source code by comparing the suspect source code to a library of known malicious source code. In this paper we detail our method of making these comparisons, evaluate how well it works, and suggest some potential methods of improvement for future work. We conclude that LZJD does appear to be effective at identifying similar files, but that it appears to struggle when attempting to aggregate the scores to compare entire source code projects.
dc.formatapplication:pdf
dc.genretheses
dc.identifierdoi:10.13016/m2dvzs-ihk8
dc.identifier.other12474
dc.identifier.urihttp://hdl.handle.net/11603/25974
dc.languageen
dc.relation.isAvailableAtThe University of Maryland, Baltimore County (UMBC)
dc.relation.ispartofUMBC Computer Science and Electrical Engineering Department Collection
dc.relation.ispartofUMBC Theses and Dissertations Collection
dc.relation.ispartofUMBC Graduate School Collection
dc.relation.ispartofUMBC Student Collection
dc.rightsThis item may be protected under Title 17 of the U.S. Copyright Law. It is made available by UMBC for non-commercial research and education. For permission to publish or reproduce, please see http://aok.lib.umbc.edu/specoll/repro.php or contact Special Collections at speccoll(at)umbc.edu
dc.sourceOriginal File Name: Roca_umbc_0434M_12474.pdf
dc.subjectLZJD
dc.subjectMalware Analysis
dc.subjectSimilarity
dc.subjectSource Code
dc.titleIdentifying Malicious Source Code Using LZJD
dc.typeText
dcterms.accessRightsDistribution Rights granted to UMBC by the author.
dcterms.accessRightsAccess limited to the UMBC community. Item may possibly be obtained via Interlibrary Loan thorugh a local library, pending author/copyright holder's permission.

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
Roca_umbc_0434M_12474.pdf
Size:
2.39 MB
Format:
Adobe Portable Document Format

License bundle

Now showing 1 - 1 of 1
No Thumbnail Available
Name:
Roca-Alexander_Open.pdf
Size:
229.38 KB
Format:
Adobe Portable Document Format
Description: