%0 Conference Proceedings %T Dynamic Software Birthmark for Java Based on Heap Memory Analysis %+ The University of Hong Kong (HKU) %A Chan, Patrick %A Hui, Lucas %A Yiu, S., M. %Z Part 1: Research Papers %< avec comité de lecture %( Lecture Notes in Computer Science %B 12th Communications and Multimedia Security (CMS) %C Ghent, Belgium %Y Bart Decker %Y Jorn Lapon %Y Vincent Naessens %Y Andreas Uhl %I Springer %3 Communications and Multimedia Security %V LNCS-7025 %P 94-107 %8 2011-10-19 %D 2011 %R 10.1007/978-3-642-24712-5_8 %K software birthmark %K software protection %K code theft detection %K Java %Z Computer Science [cs] %Z Computer Science [cs]/Networking and Internet Architecture [cs.NI]Conference papers %X Code theft has been a serious threat to the survival of the software industry. A dynamic software birthmark can help detect code theft by comparing the intrinsic characteristics of two programs extracted during their execution. We propose a dynamic birthmark system for Java based on the object reference graph. To the best of our knowledge, it is the first dynamic software birthmark making use of the heap memory. We evaluated our birthmark using 25 large-scale programs with most of them of tens of megabytes in size. Our results show that it is effective in detecting partial code theft. No false positive or false negative were found. More importantly, the birthmark remained intact even after the testing programs were obfuscated by the state-of-the-art Allatori obfuscator. These promising results reflect that our birthmark is ready for practical use. %G English %Z TC 6 %Z TC 11 %2 https://inria.hal.science/hal-01596200/document %2 https://inria.hal.science/hal-01596200/file/978-3-642-24712-5_8_Chapter.pdf %L hal-01596200 %U https://inria.hal.science/hal-01596200 %~ IFIP-LNCS %~ IFIP %~ IFIP-TC %~ IFIP-TC11 %~ IFIP-TC6 %~ IFIP-CMS %~ IFIP-LNCS-7025