Find binary-like files with ssdeep

Slashdot it! Delicious Share on Facebook Tweet! Digg!

Conclusions

The ssdeep tool fills a gap. In the way that agrep makes it possible to perform fuzzy searches in text files, ssdeep lets you find connections and similarities between any – even binary – files and to reliably evaluate them. The implemented method also lets you effectively examine large collections of files; however, its particular strengths are with text-based files.

ressdeep is a Java-based alternative to ssdeep [8] that even offers a graphical interface (Figure 2). You can start the program using

java -jar ressdeep.exe
Figure 2: The Java version of ssdeep has a GUI.

There are other options available as well, usually based on pHash, which often have better results specifically in regard to searching for similar images.

Buy this article as PDF

Express-Checkout as PDF

Pages: 3

Price $0.99
(incl. VAT)

Buy Ubuntu User

SINGLE ISSUES
 
SUBSCRIPTIONS
 
TABLET & SMARTPHONE APPS
Get it on Google Play

US / Canada

Get it on Google Play

UK / Australia

Related content