首页> 美国卫生研究院文献>Sensors (Basel Switzerland) >A Type-Aware Approach to Message Clustering for Protocol Reverse Engineering
【2h】

A Type-Aware Approach to Message Clustering for Protocol Reverse Engineering

机译:协议逆向工程的一种基于类型的消息聚类方法

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

Protocol Reverse Engineering (PRE) is crucial for information security of Internet-of-Things (IoT), and message clustering determines the effectiveness of PRE. However, the quality of services still lags behind the strict requirement of IoT applications as the results of message clustering are often coarse-grained with the intrinsic type information hidden in messages largely ignored. Aiming at this problem, this study proposes a type-aware approach to message clustering guided by type information. The approach regards a message as a combination of n-grams, and it employs the Latent Dirichlet Allocation (LDA) model to characterize messages with types and n-grams via inferring the type distribution of each message. The type distribution is finally used to measure the similarity of messages. According to this similarity, the approach clusters messages and further extracts message formats. Experimental results of the approach against Netzob in terms of a number of protocols indicate that the correctness and conciseness can be significantly improved, e.g., figures 43.86% and 3.87%, respectively for the CoAP protocol.
机译:协议逆向工程(PRE)对于物联网(IoT)的信息安全至关重要,而消息群集决定了PRE的有效性。但是,服务质量仍然落后于IoT应用程序的严格要求,因为消息群集的结果通常是粗粒度的,而隐藏在消息中的固有类型信息却被大大忽略了。针对该问题,本研究提出了一种基于类型信息的消息感知类型聚类方法。该方法将消息视为n-gram的组合,并采用潜在狄利克雷分配(LDA)模型通过推断每个消息的类型分布来表征具有类型和n-gram的消息。最后使用类型分布来衡量消息的相似性。根据这种相似性,该方法对消息进行聚类并进一步提取消息格式。针对Netzob的方法在许多协议方面的实验结果表明,CoAP协议的正确性和简洁性可以得到显着提高,例如,分别为43.86%和3.87%。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号