...
首页> 外文期刊>Journal of network and computer applications >ReFSM: Reverse engineering from protocol packet traces to test generation by extended finite state machines
【24h】

ReFSM: Reverse engineering from protocol packet traces to test generation by extended finite state machines

机译:REFSM:来自协议包的逆向工程,通过扩展有限状态机来测试生成

获取原文
获取原文并翻译 | 示例
           

摘要

Protocol reverse engineering is helpful to automatically obtain the specifications of protocols that are useful for network management, network security systems and test case generation tools. To achieve better accuracy, these kinds of applications require good models that can capture not only the order of exchanging messages (control flow aspect) but also the data being transmitted (data flow aspect). However, current techniques only focus on inferring the control flow represented as a Finite State Machine (FSM) and without interpreting the data flow. The Extended Finite State Machine (EFSM), embedding memory in the states and data guard in the FSM transitions, is a method commonly used to represent the data flow. In this work, we propose ReFSM, a novel approach to infer the EFSMs of protocols from only network packet traces. The proposed method is evaluated by using datasets of real-world network traffic traces of four protocols: FTP, SMTP, BitTorrent and PPLive. Based on the results, the coverage, accuracy scores of correctness and behavior of inferred models are always higher than 90%. The precision and recall values of message type identification are, at least, well above 94% and 96%, respectively. The inferred EFSMs are close to the correct model derived from protocol specification.
机译:协议逆向工程有助于自动获取对网络管理,网络安全系统和测试用例生成工具有用的协议规范。为了实现更好的准确性,这些应用程序需要良好的模型,不仅可以捕获交换消息的顺序(控制流程方面),还可以捕获正在传输的数据(数据流方面)。然而,目前的技术仅关注推断为有限状态机(FSM)的控制流程,并且在不解释数据流程。扩展有限状态机(EFSM),在FSM转换中嵌入状态和数据保护中的内存,是一种常用于表示数据流的方法。在这项工作中,我们提出了一种新颖的方法来推断仅从网络数据包迹线推断协议的EFSMS的新方法。通过使用四个协议的实际网络流量迹线的数据集来评估所提出的方法:FTP,SMTP,BitTorrent和Pplive。根据结果​​,覆盖率,准确性的正确性和推断模型的行为总是高于90%。消息类型识别的精度和召回值分别远高于94%和96%。推断的EFSMS接近于源自协议规范的正确模型。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号