Find binary-like files with ssdeep
|
Conclusions
The ssdeep tool fills a gap. In the way that agrep makes it possible to perform fuzzy searches in text files, ssdeep lets you find connections and similarities between any – even binary – files and to reliably evaluate them. The implemented method also lets you effectively examine large collections of files; however, its particular strengths are with text-based files.
ressdeep is a Java-based alternative to ssdeep [8] that even offers a graphical interface (Figure 2). You can start the program using
java -jar ressdeep.exe
There are other options available as well, usually based on pHash, which often have better results specifically in regard to searching for similar images.
Infos
- ssdeep homepage: http://ssdeep.sourceforge.net
- Jesse Kornblum: http://jessekornblum.com/
- Md5deep: http://md5deep.sourceforge.net/
- ssdeep principle: http://dx.doi.org/10.1016/j.diin.2006.06.015
- Spamsum: https://www.samba.org/ftp/unpacked/junkcode/spamsum/README
- pHash: http://phash.org
- FSlint: http://www.pixelbeat.org/fslint/
- ressdeep: http://reboot.pro/files/file/220-ressdeep/
« Previous 1 2 Next »
Buy this article as PDF
Pages: 3
(incl. VAT)