通信学报 ›› 2013, Vol. 34 ›› Issue (10): 162-173.doi: 10.3969/j.issn.1000-436x.2013.10.019

• 学术通信 • 上一篇    下一篇

语义层次的协议格式提取方法

潘璠,洪征,周振吉,吴礼发   

  1. 解放军理工大学 指挥信息系统学院,江苏 南京210007
  • 出版日期:2013-10-25 发布日期:2017-08-10
  • 基金资助:
    国家自然科学基金资助项目;江苏省自然科学基金资助项目;军用网络技术实验室创新开放基金资助项目

Protocol format extraction at semantic level

Zheng HONG,Zhen-ji ZHOU,Li-fa WU,Fan PAN   

  1. College of Command Information System,PLA University of Science and Technology,Nanjing 210007,China
  • Online:2013-10-25 Published:2017-08-10
  • Supported by:
    The National Natural Science Foundation of China;The Natural Science Foundation of Jiangsu Province;The Opening Foundation of Laboratory of Military Network Technology

摘要:

现有协议格式提取方法在语法层次对程序执行轨迹进行分析,字段识别结果可能存在冗余和冲突。为了提高字段识别准确率,提出了一种语义层次的协议格式提取方法。方法首先将执行轨迹中的二进制指令转换为语义等价的中间语言形式,并通过细粒度的动态污点分析跟踪字段语义解析过程,在此基础上,依据字段的语义不可分割性,利用语义层次的字段识别策略实现了协议格式提取。测试结果表明,该方法具有较高的识别精度和较低的分析复杂度。

关键词: 协议逆向工程, 协议格式提取, 动态污点分析, 中间语言

Abstract:

Present methods for protocol format extraction analyze the execution traces of programs at syntax level,which leads to redundancy and conflict in the results of fie identification.In order to improve the accuracy of field identifica-tion,a semantic level method was proposed for protocol format extraction.The method firstly translated the binary in-structions into equivalent intermediate language,and tracked the parsing process of field semantics through fine-grained dynamic taint analysis.Further,it extracted otocol format using semantic level policies of field identifica-tion,based on the semantic indivisibility of fields.Experimental results show that the proposed method can achieve high identification accuracy with low complexity.

Key words: protocol reverse engineering, protocol format extraction, dynamic taint analysis, intermediate language

No Suggested Reading articles found!