{"title":"Inferring protocol state machine for binary communication protocol","authors":"Fanzhi Meng, Yuan Liu, Chunrui Zhang, Tong Li, Yang Yue","doi":"10.1109/WARTIA.2014.6976411","DOIUrl":null,"url":null,"abstract":"Communication protocol reverse engineering has played an important role in the field of network security. Inferring protocol state machine for unknown protocol is a part of protocol specifications mining. This paper proposed a novel approach in the mining of unknown binary protocol state machine. It allows to automatically generating the state models for binary protocol by listening to network traces. We present a new methodology to align the corresponding fields and extract the state relevant fields from binary protocol communication traces, and then based on the state relevant fields to construct the protocol state model. The experimental results of ARP and TCP show that our approach is effective.","PeriodicalId":288854,"journal":{"name":"2014 IEEE Workshop on Advanced Research and Technology in Industry Applications (WARTIA)","volume":"4563 2 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2014-12-08","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"7","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2014 IEEE Workshop on Advanced Research and Technology in Industry Applications (WARTIA)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/WARTIA.2014.6976411","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 7

Abstract

Communication protocol reverse engineering has played an important role in the field of network security. Inferring protocol state machine for unknown protocol is a part of protocol specifications mining. This paper proposed a novel approach in the mining of unknown binary protocol state machine. It allows to automatically generating the state models for binary protocol by listening to network traces. We present a new methodology to align the corresponding fields and extract the state relevant fields from binary protocol communication traces, and then based on the state relevant fields to construct the protocol state model. The experimental results of ARP and TCP show that our approach is effective.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
二进制通信协议的推断协议状态机
通信协议逆向工程在网络安全领域发挥着重要作用。未知协议的推断协议状态机是协议规范挖掘的一部分。提出了一种新的未知二进制协议状态机挖掘方法。它允许通过监听网络轨迹自动生成二进制协议的状态模型。提出了一种从二进制协议通信轨迹中提取相应字段和状态相关字段的方法,并基于状态相关字段构建协议状态模型。ARP和TCP的实验结果表明,该方法是有效的。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
相关文献
EDSM-Based Binary Protocol State Machine Reversing
IF 3.1 4区 计算机科学Cmc-computers Materials & ContinuaPub Date : 2021-01-01 DOI: 10.32604/cmc.2021.016562
Shen Wang, Fanghui Sun, Hongli Zhang, D. Zhan, Shuanggeng Li, Jun Wang
Inferring Protocol State Machine from Real-World Trace
IF 0 International Symposium on Recent Advances in Intrusion DetectionPub Date : 2010-09-15 DOI: 10.1007/978-3-642-15512-3_32
Yipeng Wang, Zhibin Zhang, Li Guo
Inferring Protocol State Machine from Network Traces: A Probabilistic Approach
IF 0 International Conference on Applied Cryptography and Network SecurityPub Date : 2011-06-07 DOI: 10.1007/978-3-642-21554-4_1
Yipeng Wang, Zhibin Zhang, D. Yao, Buyun Qu, Li Guo
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Hospital digital library based on cloud computing Design and actualization of management system in sports teaching A topology control algorithm for ribbon wireless sensor network From the user experience to optimization design in App development process Research on communication network architecture of energy internet based on SDN
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1