Feature Extraction Optimization for Bitstream Communication Protocol Format Reverse Analysis

被引:8
|
作者
Hei, Xinhong [1 ]
Bai, Binbin [1 ]
Wang, Yichuan [1 ]
Zhang, Li [1 ]
Zhu, Lei [1 ]
Ji, Wenjiang [1 ]
机构
[1] Xian Univ Technol, Coll Comp Sci & Engn, Xian, Peoples R China
关键词
Apriori; AC; Network Security; Reverse Analysis; Message Format;
D O I
10.1109/TrustCom/BigDataSE.2019.00094
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The unknown [?] format bitstream network communication protocol not merely brings the challenge to the safe and efficient network management, but also provides the possibility for the security audit and data disclosure of the network communication content. Feature extraction of unknown protocol is an indispensable part of the network protocol reverse. In dealing with this problem, the number of elements in the feature candidate set increases exponentially with the increase of time and the length of frequent items in the existing algorithms such as Apriori and AC(Aho-Corasick). This makes the algorithm have high time and space complexity. In this paper, CFI(Combined Frequent Items) algorithm first employs AC algorithm to generate frequent byte items, then applies Apriori algorithm to perform frequent item matching, and uses location identification to ensure the completeness of feature candidate sets. The experimental results show that compared with the Apriori and AC algorithms, the CFI algorithm can reduce the time complexity by 78% and the space complexity by 60% in time, and can accurately and fleetly analyze the reverse message format from unknown protocols.
引用
收藏
页码:662 / 669
页数:8
相关论文
共 50 条
  • [1] A Format Reverse Method for Binary Protocol from Communication Data
    Meng, Fanzhi
    Liu, Yuan
    Zhang, Chunrui
    Liu, Dong
    PROCEEDINGS OF THE 2015 3RD INTERNATIONAL CONFERENCE ON MACHINERY, MATERIALS AND INFORMATION TECHNOLOGY APPLICATIONS, 2015, 35 : 718 - 724
  • [2] Anomaly detection based on feature extraction of unknown protocol payload format
    Song, Zefan
    Wu, Bin
    PROCEEDINGS OF 2020 IEEE 5TH INFORMATION TECHNOLOGY AND MECHATRONICS ENGINEERING CONFERENCE (ITOEC 2020), 2020, : 709 - 714
  • [3] BitFREE: On Significant Speedup and Security Applications of FPGA Bitstream Format Reverse Engineering
    Zhang, Tao
    Tehranipoor, Mark
    Farahmandi, Farimah
    2023 IEEE EUROPEAN TEST SYMPOSIUM, ETS, 2023,
  • [4] Automatic protocol reverse-engineering: Message format extraction and field semantics inference
    Caballero, Juan
    Song, Dawn
    COMPUTER NETWORKS, 2013, 57 (02) : 451 - 474
  • [5] Bit-oriented format extraction approach for automatic binary protocol reverse engineering
    Tao, Siyu
    Yu, Hongyi
    Li, Qing
    IET COMMUNICATIONS, 2016, 10 (06) : 709 - 716
  • [6] REVBiT: REVerse Engineering of BiTstream for LUT Extraction & Logic Identification
    Narwariya, Anmol Singh
    Talele, Chetan
    Das, Pabitra
    Acharyya, Amit
    2024 IEEE INTERNATIONAL SYMPOSIUM ON CIRCUITS AND SYSTEMS, ISCAS 2024, 2024,
  • [7] Bitstream-based feature extraction for wireless speech recognition
    Kim, HK
    Cox, RV
    2000 IEEE INTERNATIONAL CONFERENCE ON ACOUSTICS, SPEECH, AND SIGNAL PROCESSING, PROCEEDINGS, VOLS I-VI, 2000, : 1607 - 1610
  • [8] RNN Based Bitstream Feature Extraction Method for Codec Classification
    Wee, Seungwoo
    Jeong, Jechang
    INTERNATIONAL WORKSHOP ON ADVANCED IMAGE TECHNOLOGY (IWAIT) 2019, 2019, 11049
  • [9] An MTSA Algorithm for Unknown Protocol Format Reverse
    Sun, Fanghui
    Wang, Shen
    Zhang, Hongli
    ADVANCES IN INTELLIGENT INFORMATION HIDING AND MULTIMEDIA SIGNAL PROCESSING, VOL 1, 2017, 63 : 209 - 216
  • [10] Automated Reverse Engineering Tools for FPGA Bitstream Extraction and Logic Estimation
    Cho, Mannhee
    Lee, Dongchan
    Lee, Sanghyun
    Kim, Youngmin
    Lee, Hyung-Min
    2022 19TH INTERNATIONAL SOC DESIGN CONFERENCE (ISOCC), 2022, : 328 - 329