Back to Search Start Over

ABInfer: A Novel Field Boundaries inference Approach for Protocol Reverse Engineering

Authors :
Yanjiao Chen
Ma Lixin
Chenggang Li
Xiaoyu Ji
Bo Li
Dongxiao Jiang
Source :
BigDataSecurity/HPSC/IDS
Publication Year :
2020
Publisher :
IEEE, 2020.

Abstract

With the development of network, more and more unkown protocols appear. Network protocols define the rules between network entities and firewall uses network protocol for deep packet detection to prevent intrusions. For detecting these unkown protocols, firewall can’t analyze these protocols, which makes many systems vulnerable. To solve this problem, protocol reverse engineering is getting more and more attention. Protocol reverse engineering is a process that reverses the syntax and grammar of a protocol from its traces of execution codes. It focuses on three protocol features: field boundaries, protocol grammar and state machine. Field boundaries inference is the basis of the protocol reverse engineering, the precision of this process has a big influence on reversing the grammar and state machine. In this paper, we propose a method called ABinfer, which leverage the Field Adjacent information to identify the field boundaries. We evaluate the method on three protocols and the results show that it has a good ability to identify field boundaries of protocols.

Details

Database :
OpenAIRE
Journal :
2020 IEEE 6th Intl Conference on Big Data Security on Cloud (BigDataSecurity), IEEE Intl Conference on High Performance and Smart Computing, (HPSC) and IEEE Intl Conference on Intelligent Data and Security (IDS)
Accession number :
edsair.doi...........7fc6a3126006ec98f16588b813dfa06c
Full Text :
https://doi.org/10.1109/bigdatasecurity-hpsc-ids49724.2020.00015