ABInfer: A Novel Field Boundaries inference Approach for Protocol Reverse Engineering

计算机科学 逆向工程 推论 协议(科学) 领域(数学) 软件工程 人工智能 程序设计语言 数学 医学 病理 纯数学 替代医学
作者
Jiang Dongxiao,Chenggang Li,MA Li-xin,Xiaoyu Ji,Yanjiao Chen,Bo Li
标识
DOI:10.1109/bigdatasecurity-hpsc-ids49724.2020.00015
摘要

With the development of network, more and more unkown protocols appear. Network protocols define the rules between network entities and firewall uses network protocol for deep packet detection to prevent intrusions. For detecting these unkown protocols, firewall can't analyze these protocols, which makes many systems vulnerable. To solve this problem, protocol reverse engineering is getting more and more attention. Protocol reverse engineering is a process that reverses the syntax and grammar of a protocol from its traces of execution codes. It focuses on three protocol features: field boundaries, protocol grammar and state machine. Field boundaries inference is the basis of the protocol reverse engineering, the precision of this process has a big influence on reversing the grammar and state machine. In this paper, we propose a method called ABinfer, which leverage the Field Adjacent information to identify the field boundaries. We evaluate the method on three protocols and the results show that it has a good ability to identify field boundaries of protocols.

科研通智能强力驱动
Strongly Powered by AbleSci AI
科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
orixero应助科研通管家采纳,获得10
刚刚
赘婿应助科研通管家采纳,获得10
刚刚
上官若男应助科研通管家采纳,获得10
刚刚
小马甲应助科研通管家采纳,获得10
刚刚
搜集达人应助科研通管家采纳,获得10
刚刚
科研通AI2S应助科研通管家采纳,获得10
1秒前
香蕉觅云应助科研通管家采纳,获得10
1秒前
1秒前
情怀应助科研通管家采纳,获得10
1秒前
上官若男应助科研通管家采纳,获得10
1秒前
CodeCraft应助科研通管家采纳,获得10
1秒前
1秒前
上官若男应助科研通管家采纳,获得10
1秒前
邪恶柚子应助科研通管家采纳,获得10
1秒前
乐乐应助科研通管家采纳,获得10
1秒前
传奇3应助CC采纳,获得10
1秒前
bkagyin应助科研通管家采纳,获得10
1秒前
外向不尤应助科研通管家采纳,获得20
1秒前
1秒前
2秒前
2秒前
英俊的铭应助科研通管家采纳,获得10
2秒前
星辰大海应助段非非采纳,获得10
2秒前
NexusExplorer应助科研通管家采纳,获得10
2秒前
2秒前
JamesPei应助科研通管家采纳,获得10
2秒前
WW关闭了WW文献求助
2秒前
斯文败类应助Dreher采纳,获得30
2秒前
2秒前
小二郎应助科研通管家采纳,获得10
2秒前
ding应助科研通管家采纳,获得10
2秒前
Lucas应助科研通管家采纳,获得30
2秒前
英姑应助科研通管家采纳,获得10
3秒前
思源应助科研通管家采纳,获得10
3秒前
ding应助科研通管家采纳,获得20
3秒前
3秒前
CodeCraft应助科研通管家采纳,获得10
3秒前
kkkkkkk_发布了新的文献求助10
3秒前
哈哈悦完成签到,获得积分10
3秒前
安鹏应助科研通管家采纳,获得10
3秒前
高分求助中
(应助此贴封号)【重要!!请各用户(尤其是新用户)详细阅读】【科研通的精品贴汇总】 10000
Modern Epidemiology, Fourth Edition 5000
Kinesiophobia : a new view of chronic pain behavior 5000
Molecular Biology of Cancer: Mechanisms, Targets, and Therapeutics 3000
Digital Twins of Advanced Materials Processing 2000
Weaponeering, Fourth Edition – Two Volume SET 2000
Signals, Systems, and Signal Processing 610
热门求助领域 (近24小时)
化学 材料科学 医学 生物 工程类 有机化学 纳米技术 化学工程 生物化学 物理 计算机科学 内科学 复合材料 催化作用 物理化学 光电子学 电极 冶金 细胞生物学 基因
热门帖子
关注 科研通微信公众号,转发送积分 6016722
求助须知:如何正确求助?哪些是违规求助? 7599299
关于积分的说明 16153405
捐赠科研通 5164494
什么是DOI,文献DOI怎么找? 2764681
邀请新用户注册赠送积分活动 1745695
关于科研通互助平台的介绍 1634980