BSIM explained once and for all!
Introduction During our work on SightHouse, we evaluated several binary similarity engines to find one that met our needs. After thorough evaluation, we chose Ghidra's Behavioral Similarity (BSIM) feature. One key difference of BSIM compared to other approaches is that, despite being open-source, its algorithm is sparsely documented. Existing documentation1 indicates BSIM uses locality-sensitive hashing and cosine similarity, but the description is brief and incomplete. So here it is, once and f...
Read full article →