作者
Yipeng Wang, Xiaochun Yun, M Zubair Shafiq, Liyan Wang, Alex X Liu, Zhibin Zhang, Danfeng Yao, Yongzheng Zhang, Li Guo
发表日期
2012/10/30
研讨会论文
2012 20th IEEE International Conference on Network Protocols (ICNP)
页码范围
1-10
出版商
IEEE
简介
Extracting the protocol message format specifications of unknown applications from network traces is important for a variety of applications such as application protocol parsing, vulnerability discovery, and system integration. In this paper, we propose ProDecoder, a network trace based protocol message format inference system that exploits the semantics of protocol messages without the executable code of application protocols. ProDecoder is based on the key insight that the n-grams of protocol traces exhibit highly skewed frequency distribution that can be leveraged for accurate protocol message format inference. In ProDecoder, we first discover the latent relationship among n-grams by first grouping protocol messages with the same semantics and then inferring message formats by keyword based clustering and cluster sequence alignment. We implemented and evaluated ProDecoder to infer message format …
引用总数
2013201420152016201720182019202020212022202320243111821102516201717125
学术搜索中的文章
Y Wang, X Yun, MZ Shafiq, L Wang, AX Liu, Z Zhang… - 2012 20th IEEE International Conference on Network …, 2012