110 likes | 239 Views
Team meeting Oct 6, 2011. Bart Coppens. Program differences can be observed. Version 1. Version 2. Security hole fixed New features Watermarks. What changed?. Attacker will use tools to reduce search space. Version 1. Version 2. patch. irrelevant changes.
E N D
Team meetingOct 6, 2011 Bart Coppens
Program differencescan be observed Version 1 Version 2 • Security hole fixed • New features • Watermarks What changed?
Attacker will use tools to reduce search space Version 1 Version 2 patch irrelevant changes
How toreduce the search space?bsdiff/xdelta (1) Unfilteredresults (2) Filter relocatableaddresses (3) Opcodechanged (4) Executed code & filteredrelocatebleaddresses (5) Executed code & opcodechanged
How toreduce the search space?BinDiff Simple analysis,unfiltered (5) Full analysis, unfiltered (2) Simple analysis, problemsfiltered (3) Executed code of simpleanalysis (6) Full analysis, problemsfiltered (4) Exec code of simple analysis, problemsfiltered (7) Exec code of full analysis (8) Exec code of full analysis,problemsfiltered