首页> 外国专利> AUTOMATIC PARSING OF BINARY-BASED APPLICATION PROTOCOLS USING NETWORK TRAFFIC

AUTOMATIC PARSING OF BINARY-BASED APPLICATION PROTOCOLS USING NETWORK TRAFFIC

机译:基于网络流量的基于二进制的应用协议自动解析

摘要

A method for analyzing a binary-based application protocol of a network. The method includes obtaining conversations from the network, extracting content of a candidate field from a message in each conversation, calculating a randomness measure of the content to represent a level of randomness of the content across all conversation, calculating a correlation measure of the content to represent a level of correlation, across all of conversations, between the content and an attribute of a corresponding conversation where the message containing the candidate field is located, and selecting, based on the randomness measure and the correlation measure, and using a pre-determined field selection criterion, the candidate offset from a set of candidate offsets as the offset defined by the protocol.
机译:一种用于分析网络的基于二进制的应用协议的方法。该方法包括从网络获得对话,从每个对话中的消息中提取候选字段的内容,计算内容的随机性度量以表示内容在所有对话中的随机性水平,计算内容的相关度量以代表所有对话中内容和对应对话的属性之间的相关级别,对话中包含候选字段的消息所在的位置,并基于随机性度量和相关性度量并使用预定值进行选择字段选择标准,即一组候选偏移量中的候选偏移量,作为协议定义的偏移量。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号