计算机科学
聚类分析
字节
逆向工程
调试
数据挖掘
背景(考古学)
领域(数学)
协议(科学)
二进制数据
消息传递
二进制数
网络取证
分布式计算
计算机网络
理论计算机科学
人工智能
计算机安全
程序设计语言
数字取证
医学
古生物学
替代医学
数学
算术
病理
纯数学
生物
作者
Stephan Kleber,Frank Kargl,Milan State,Matthias Hollick
标识
DOI:10.1109/dsn-w54100.2022.00023
摘要
Reverse engineering of unknown network protocols based on recorded traffic traces enables security analyses and debugging of undocumented network services. In particular for binary protocols, existing approaches (1) lack comprehensive methods to classify or determine the data type of a discovered segment in a message, e.,g., a number, timestamp, or network address, that would allow for a semantic interpretation and (2) have strong assumptions that prevent analysis of lower-layer protocols often found in IoT or mobile systems. In this paper, we propose the first generic method for analyzing unknown messages from binary protocols to reveal the data types in message fields. To this end, we split messages into segments of bytes and use their vector interpretation to calculate similarities. These can be used to create clusters of segments with the same type and, moreover, to recognize specific data types based on the clusters' characteristics. Our extensive evaluation shows that our method provides precise classification in most cases and a data-type-recognition precision of up to 100% at reasonable recall, improving the state-of-the-art by a factor between 1.3 and 3.7 in realistic scenarios. We open-source our implementation to facilitate follow-up works.
科研通智能强力驱动
Strongly Powered by AbleSci AI