首页> 外文会议>International conference on advanced data mining and applications >Protocol Specification Inference Based on Keywords Identification
【24h】

Protocol Specification Inference Based on Keywords Identification

机译:基于关键字识别的协议规范推断

获取原文

摘要

Protocol reverse engineering is becoming important in analyzing unknown protocols. Unfortunately, many techniques often have some limitations for few priori information or the time-consuming problem. To address these issues, we propose a framework based on protocol finite state machine (FSM) construction, which can infer the protocol specifications without any priori information of protocols. To improve our framework's efficiency, we identify the keywords before the finite state construction. Our framework constructs two FSMs, one is L - FSM (language FSM) and the other is S - FSM (state FSM). L - FSM is to illustrate the protocol languages. S - FSM shows protocol sessions' state transitions. We evaluate our framework with both binary and text protocol. The ARP and the SMTP are the target protocols as inputs. The precision rate and the recall rate are used for evaluation criterias in our experiments. The ARP's precision and recall rate are both reached 100%. The SMTP's precision rate is 100% and recall rate is almost 98%.
机译:协议逆向工程在分析未知协议方面变得重要。遗憾的是,许多技术通常对少数先验信息或耗时的问题具有一些限制。为了解决这些问题,我们提出了一个基于协议有限状态机(FSM)构造的框架,其可以推断出在没有任何先验协议信息的情况下推断协议规范。为了提高框架的效率,我们在有限状态建设之前识别关键字。我们的框架构造了两个FSM,一个是L - FSM(语言FSM),另一个是S - FSM(州FSM)。 L - FSM是为了说明协议语言。 S - FSM显示协议会话状态转换。我们使用二进制和文本协议评估我们的框架。 ARP和SMTP是目标协议作为输入。精密速率和召回率用于我们的实验中的评估标准。 ARP的精确度和召回率均达到100%。 SMTP的精确率为100%,召回率差不多为98%。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号