Back to Search
Start Over
ABInfer: A Novel Field Boundaries inference Approach for Protocol Reverse Engineering
- Source :
- BigDataSecurity/HPSC/IDS
- Publication Year :
- 2020
- Publisher :
- IEEE, 2020.
-
Abstract
- With the development of network, more and more unkown protocols appear. Network protocols define the rules between network entities and firewall uses network protocol for deep packet detection to prevent intrusions. For detecting these unkown protocols, firewall can’t analyze these protocols, which makes many systems vulnerable. To solve this problem, protocol reverse engineering is getting more and more attention. Protocol reverse engineering is a process that reverses the syntax and grammar of a protocol from its traces of execution codes. It focuses on three protocol features: field boundaries, protocol grammar and state machine. Field boundaries inference is the basis of the protocol reverse engineering, the precision of this process has a big influence on reversing the grammar and state machine. In this paper, we propose a method called ABinfer, which leverage the Field Adjacent information to identify the field boundaries. We evaluate the method on three protocols and the results show that it has a good ability to identify field boundaries of protocols.
- Subjects :
- Reverse engineering
Finite-state machine
Grammar
Computer science
media_common.quotation_subject
Distributed computing
ComputerSystemsOrganization_COMPUTER-COMMUNICATIONNETWORKS
Inference
020206 networking & telecommunications
02 engineering and technology
computer.software_genre
Firewall (construction)
Packet detection
0202 electrical engineering, electronic engineering, information engineering
020201 artificial intelligence & image processing
Reversing
Communications protocol
computer
media_common
Subjects
Details
- Database :
- OpenAIRE
- Journal :
- 2020 IEEE 6th Intl Conference on Big Data Security on Cloud (BigDataSecurity), IEEE Intl Conference on High Performance and Smart Computing, (HPSC) and IEEE Intl Conference on Intelligent Data and Security (IDS)
- Accession number :
- edsair.doi...........7fc6a3126006ec98f16588b813dfa06c
- Full Text :
- https://doi.org/10.1109/bigdatasecurity-hpsc-ids49724.2020.00015