{"title":"BaNet3F: a Bayesian network approach to automatic binary frame format identification","authors":"P. Greau-Hamard, M. Djoko-Kouam, Y. Louét","doi":"10.12988/ces.2022.91940","DOIUrl":null,"url":null,"abstract":"In the fast developing world of telecommunications, it may be useful to analyse any protocol one comes across, even if it is unknown. To that end, one needs to get the state machine and the frame format of the protocol. These can be extracted from network and/or execution traces via Protocol Reverse Engineering (PRE). In this paper, we present BaNet3F, a model aimed at finding the hidden structure of binary protocol frames. To quantify the complexity of the traces analysed (from BaNet3F perspective), we suggest a new meaningful metric: the Average Dependencies Ratio (ADR). We then compare the proposed model to two state-of-the-art ones, Latent Dirichlet Allocation (LDA) and Cai et al. model, and show that BaNet3F outperforms them by far.","PeriodicalId":10543,"journal":{"name":"Contemporary engineering sciences","volume":null,"pages":null},"PeriodicalIF":0.0000,"publicationDate":"2022-01-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Contemporary engineering sciences","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.12988/ces.2022.91940","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0
Abstract
In the fast developing world of telecommunications, it may be useful to analyse any protocol one comes across, even if it is unknown. To that end, one needs to get the state machine and the frame format of the protocol. These can be extracted from network and/or execution traces via Protocol Reverse Engineering (PRE). In this paper, we present BaNet3F, a model aimed at finding the hidden structure of binary protocol frames. To quantify the complexity of the traces analysed (from BaNet3F perspective), we suggest a new meaningful metric: the Average Dependencies Ratio (ADR). We then compare the proposed model to two state-of-the-art ones, Latent Dirichlet Allocation (LDA) and Cai et al. model, and show that BaNet3F outperforms them by far.