• DocumentCode
    2467401
  • Title

    Extracting Information from Unknown Protocols On CampusNet

  • Author

    Yu, Zhuanghui ; Huang, Yongzhong ; Guo, Shaozhong ; Zhou, Bei ; Ren, Hua

  • Author_Institution
    Inf. Eng. Univ. of PLA, Zhengzhou
  • fYear
    2007
  • fDate
    23-25 Nov. 2007
  • Firstpage
    535
  • Lastpage
    539
  • Abstract
    As information security has been increasingly concerned on our campus network, in many occasions, it´s highly useful to extract information from various network traces, including recognizing malware variants, detecting intrusion, and normalizing traffic. Traditionally, the extracting work often depends on the protocol specification. However, there are often no sufficient documents or time for parsing the protocol specified. We present Catcher, a system for semi-automatically extracting information from unknown protocols. The key novelty in our work is that we locate the information and pick it out directly. Catcher does not require knowledge of any protocol, it automatically parses packets given. In the afterward step, if the same type packets come up, it Mill recognize them and extract information out of them. In order to test the effectiveness of our tool, we use Catcher to extract information over Http and DNS (with no predefinitions of these protocols), as well as chat applications such as MSN, the result reveals that Catcher can extract information from unknown protocols effectively.
  • Keywords
    Internet; network analysers; protocols; security of data; telecommunication security; telecommunication traffic; CampusNet protocol specification; Catcher semiautomatic information extraction system; campus network; information security; intrusion detection; malware recognition; Algorithm design and analysis; Data mining; Information analysis; Information security; Intrusion detection; Programmable logic arrays; Protocols; Reverse engineering; Telecommunication traffic; Testing; Dynamic Field; Information Extraction; Message Format;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Information Technologies and Applications in Education, 2007. ISITAE '07. First IEEE International Symposium on
  • Conference_Location
    Kunming
  • Print_ISBN
    978-1-4244-1386-7
  • Electronic_ISBN
    978-1-4244-1386-7
  • Type

    conf

  • DOI
    10.1109/ISITAE.2007.4409343
  • Filename
    4409343