计算机应用 ›› 2012, Vol. 32 ›› Issue (04): 1060-1063.DOI: 10.3724/SP.J.1087.2012.01060

• 人工智能 • 上一篇    下一篇

基于多属性决策的嵌入式操作系统识别技术研究2

张平,蒋烈辉,刘铁铭,谢耀滨   

  1. 信息工程大学 信息工程学院,郑州 450002
  • 收稿日期:2011-10-26 修回日期:2011-12-03 发布日期:2012-04-20 出版日期:2012-04-01
  • 通讯作者: 张平
  • 作者简介:张平(1986-),男,辽宁大石桥人,硕士研究生,主要研究方向:嵌入式软件逆向;
    蒋烈辉(1967-),男,浙江东阳人,教授,博士生导师,主要研究方向:逆向工程;
    刘铁铭(1977-),男,辽宁锦州人,副教授,主要研究方向:数据库、嵌入式系统;
    谢耀滨(1981-),男,福建漳州人,讲师,主要研究方向:嵌入式系统。

Research of embedded systems recognition based on MADM2

ZHANG Ping,JIANG Lie-hui,LIU Tie-ming,XIE Yao-bin   

  1. Institute of Information Engineering, Information Engineering University, Zhengzhou Henan 450002, China
  • Received:2011-10-26 Revised:2011-12-03 Online:2012-04-20 Published:2012-04-01
  • Contact: ZHANG Ping

摘要: 针对嵌入式固件逆向解析过程中操作系统类型识别困难的问题,提出了一种基于多属性决策的嵌入式操作系统识别技术。对固件映像中反映出的嵌入式操作系统的多种特征进行综合分析并构建了相关的识别模型,利用向量夹角余弦计算与标准系统之间的相似度。阐述了识别的基本思想和具体实现流程。实验结果表明,该方法在某些特征缺失的情况下仍能得到较准确的识别结果。

关键词: 嵌入式, 固件, 逆向解析, 操作系统, 多属性决策, 向量夹角余弦, 相似度

Abstract: Aiming at the problem that operating system type is difficult to recognize in embedded firmware reversing analysis, an recognition technology which is based on MADM(Multi-attribute Decision Making) was proposed. Comprehensively analyzed the multiply features in the firmware, built a recognition model, calculated the similarity using the vector included angle cosine method. The basic idea of recognition and the concrete realization of the process were described. Experimental results show that this method can get more accurate recognition results in some cases that some features are missed.

Key words: embedded, firmware, reverse analysis, operating system, Multi-attribute Decision Making(MADM), vector included angle cosine, similarity

中图分类号: