본문 바로가기
  • Home

Obfuscation-Resilient Behavioral Similarity Analysis of Simulation Software Using Event Logs

  • Journal of Software Forensics
  • Abbr : JSF
  • 2026, 22(3), pp.121~132
  • Publisher : Korea Software Assessment and Valuation Society
  • Research Area : Engineering > Computer Science
  • Received : August 19, 2026
  • Accepted : September 20, 2026
  • Published : September 30, 2026

Yea Dong Yoo 1,  Byeonghyeon Cho 1,  Sooyoung Jang 2,  Seungho Yang 1,  Changbeom Choi 1

1한밭대
2국립한밭대학교

Accredited

ABSTRACT

In disputes involving simulation software, source code may be unavailable and derivative indications must be examined from execution logs. Label renaming and same-time record splitting, however, can invalidate label-dependent similarity metrics. This paper combines label-free state signatures and Hungarian assignment with stutter merging inspired by weak bisimulation, and specifies a conditional restoration procedure and its applicability conditions. We evaluated one reference implementation and six comparison variants generated with pyjevsim. The raw-label similarity of the renamed variant was 0.133, nearly identical to 0.132 for the independent implementation; after alignment, the scores became 1.000 and 0.847, respectively. Oracle checks confirmed that the renamed, split, and combined variants matched the defined log transformations. These results show that the method can restore concealed behavioral similarity under the evaluated obfuscation conditions and support technical analysis of possible derivation.

Journal Copyright Policy

No CCL information provided

Citation status

* References for papers published after 2025 are currently being built.