DocumentCode :
3740231
Title :
Protocol Reverse Engineering Using LDA and Association Analysis
Author :
Haifeng Li;Bo Shuai;Jian Wang;Chaojing Tang
Author_Institution :
Sch. of Electron. Sci. &
fYear :
2015
Firstpage :
312
Lastpage :
316
Abstract :
Automatic protocol reverse engineering for application protocol is becoming more and more important for many applications such as application protocol analyzer, penetration testing, intrusion prevention and detection. However, many techniques for extracting the protocol message format specifications of unknown applications often have some limitations for little priori information or the time-consuming problem. In this paper, we present a method for automatically reverse engineering the protocol message formats of an application from its network trace, by using LDA and association analysis. The approach exploits the semantics of protocol messages without the executable code of application protocols, but focuses on the insight that the n-grams of protocol traces exhibit highly semantic information that can be leveraged for accurate protocol message format inference. Firstly, we propose the way to key words extract by utilizing the LDA model, secondly, the association analysis method is applied to constructing the feature words based on the above process. Lastly our experiments Show that the method can accurately infer message format specifications of SMTP text protocol.
Keywords :
"Protocols","Feature extraction","Reverse engineering","Association rules","Yttrium","Semantics"
Publisher :
ieee
Conference_Titel :
Computational Intelligence and Security (CIS), 2015 11th International Conference on
Type :
conf
DOI :
10.1109/CIS.2015.83
Filename :
7397097
Link To Document :
بازگشت