首页> 外文OA文献 >Automatic protocol field inference for deeper protocol understanding
【2h】

Automatic protocol field inference for deeper protocol understanding

机译:自动协议字段推断,可更深入地了解协议

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

Security tools have evolved dramatically in the recent years to combat the increasingly complex nature of attacks, but to be effective these tools need to be configured by experts that understand network protocols thoroughly. In this paper we present FieldHunter, which automatically extracts fields and infers their types; providing this much needed information to the security experts for keeping pace with the increasing rate of new network applications and their underlying protocols. FieldHunter relies on collecting application messages from multiple sessions and then applying statistical correlations is able to infer the types of the fields. These statistical correlations can be between different messages or other associations with meta-data such as message length, client or server IPs. Our system is designed to extract and infer fields from both binary and textual protocols. We evaluated FieldHunter on real network traffic collected in ISP networks from three different continents. FieldHunter was able to extract security relevant fields and infer their nature for well documented network protocols (such as DNS and MSNP) as well as protocols for which the specifications are not publicly available (such as SopCast) and from malware such as (Ramnit).
机译:近年来,安全工具已经发生了巨大变化,以应对日益复杂的攻击性质,但是要使这些工具有效,必须由透彻理解网络协议的专家进行配置。在本文中,我们介绍了FieldHunter,它可以自动提取字段并推断其类型。向安全专家提供这些急需的信息,以跟上新网络应用及其底层协议不断增长的速度。 FieldHunter依赖于从多个会话中收集应用程序消息,然后应用统计相关性就可以推断出字段的类型。这些统计相关性可以在不同的消息之间或与元数据的其他关联之间,例如消息长度,客户端或服务器IP。我们的系统旨在从二进制和文本协议中提取和推断字段。我们根据来自三大洲的ISP网络中收集的实际网络流量对FieldHunter进行了评估。 FieldHunter能够提取与安全相关的字段,并推断出它们的性质,这些字段已被详细记录的网络协议(例如DNS和MSNP)以及未公开提供其规范的协议(例如SopCast)和恶意软件(例如(Ramnit))。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号