Title :
Automatic protocol field inference for deeper protocol understanding
Author :
Bermudez, Ignacio ; Tongaonkar, Alok ; Iliofotou, Marios ; Mellia, Marco ; Munafo, Maurizio M.
Author_Institution :
Symantec Corp., CA, USA
Abstract :
Security tools have evolved dramatically in the recent years to combat the increasingly complex nature of attacks, but to be effective these tools need to be configured by experts that understand network protocols thoroughly. In this paper we present FieldHunter, which automatically extracts fields and infers their types; providing this much needed information to the security experts for keeping pace with the increasing rate of new network applications and their underlying protocols. FieldHunter relies on collecting application messages from multiple sessions and then applying statistical correlations is able to infer the types of the fields. These statistical correlations can be between different messages or other associations with meta-data such as message length, client or server IPs. Our system is designed to extract and infer fields from both binary and textual protocols. We evaluated FieldHunter on real network traffic collected in ISP networks from three different continents. FieldHunter was able to extract security relevant fields and infer their nature for well documented network protocols (such as DNS and MSNP) as well as protocols for which the specifications are not publicly available (such as SopCast) and from malware such as (Ramnit).
Keywords :
Internet; invasive software; meta data; statistical analysis; telecommunication traffic; transport protocols; DNS; FieldHunter; ISP network; Internet protocol; Internet service provider; MSNP; Microsoft notification protocol; Ramnit; SopCast; automatic protocol field inference; binary protocol; client IP; domain name system; field extraction; malware; message length; metadata; network protocol; network traffic; protocol understanding; security tool; server IP; statistical correlation; textual protocol; Correlation; Entropy; IP networks; Protocols; Radiation detectors; Security; Servers;
Conference_Titel :
IFIP Networking Conference (IFIP Networking), 2015
Conference_Location :
Toulouse
DOI :
10.1109/IFIPNetworking.2015.7145307