liu.seSearch for publications in DiVA
RefereraExporteraLink to record
Permanent link

Direct link
Referera
Referensformat
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • oxford
  • Annet format
Fler format
Språk
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Annet språk
Fler språk
Utmatningsformat
  • html
  • text
  • asciidoc
  • rtf
Automatic Detection, unpacking of untagged compressed data
Linköpings universitet, Institutionen för datavetenskap, Cybersäkerhet.
Linköpings universitet, Institutionen för datavetenskap, Cybersäkerhet.
2026 (engelsk)Independent thesis Advanced level (degree of Master (Two Years)), 20 poäng / 30 hpOppgaveAlternativ tittel
Automatisk detektion, uppacking av otaggad komprimerad data (svensk)
Abstract [en]

Modern digital systems rely heavily on firmware updates that are frequently distributed as compressed binary blobs. In forensic investigations and security audits, these blobs often appear withoutfile headers or metadata, rendering standard signature-based extraction tools ineffective. This thesispresents BinSift, a modular Python-based framework designed for the automatic detection, classification, and “blind” decompression of untagged compressed data.To calibrate the system, a large-scale statistical analysis was conducted on the FirmSec dataset, profiling approximately 34,136 firmware images totaling over 200 GB of binary data. Results indicatethat an average Shannon entropy threshold of 7.1 bits per byte provides an optimal balance for capturing modern compression formats like LZMA and SquashFS while minimizing false positives fromhigh-density uncompressed code.The BinSift framework was evaluated against industrial firmware samples, achieving a 59.0% successrate in “True Blind” mode without any prior knowledge of file headers. This approach maintained an81.5% fidelity retention compared to metadata-assisted baselines. When excluding mathematicallyunrecoverable encrypted payloads, the effective success rate rose to 84.4%. These findings demonstrate that entropy-based stream identification and bit-level refinement are viable solutions for bypassing obfuscation in embedded systems forensics.

sted, utgiver, år, opplag, sider
2026. , s. 66
Emneord [en]
Firmware Forensics, Blind Decompression, Shannon Entropy, Embedded Systems Security, Binary Blob Analysis, Signatureless Extraction, Heuristic Stream Detection, Reverse Engineering
HSV kategori
Identifikatorer
URN: urn:nbn:se:liu:diva-224113ISRN: LITH-EX-A--26/018--SEOAI: oai:DiVA.org:liu-224113DiVA, id: diva2:2060854
Presentation
2026-05-13, Charles Babbage, Linköping, 14:15 (engelsk)
Veileder
Examiner
Tilgjengelig fra: 2026-05-27 Laget: 2026-05-19 Sist oppdatert: 2026-05-27bibliografisk kontrollert

Open Access i DiVA

fulltext(4222 kB)208 nedlastinger
Filinformasjon
Fil FULLTEXT01.pdfFilstørrelse 4222 kBChecksum SHA-512
6d8a8edeccae0c3442899d454a16f2b5caeea9ff8c209b10ba8ae55a5b614f7e94c1c2882aa2d19bf912a5b33f2d9b3f69a49f460cef30d6756c2d08d6e3f920
Type fulltextMimetype application/pdf

Søk i DiVA

Av forfatter/redaktør
Attin, ArvidChristensson, Martin
Av organisasjonen

Søk utenfor DiVA

GoogleGoogle Scholar
Antall nedlastinger er summen av alle nedlastinger av alle fulltekster. Det kan for eksempel være tidligere versjoner som er ikke lenger tilgjengelige

urn-nbn

Altmetric

urn-nbn
Totalt: 128 treff
RefereraExporteraLink to record
Permanent link

Direct link
Referera
Referensformat
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • oxford
  • Annet format
Fler format
Språk
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Annet språk
Fler språk
Utmatningsformat
  • html
  • text
  • asciidoc
  • rtf