Journal on Communications ›› 2013, Vol. 34 ›› Issue (10): 162-173.doi: 10.3969/j.issn.1000-436x.2013.10.019

• Academic communication • Previous Articles     Next Articles

Protocol format extraction at semantic level

Zheng HONG,Zhen-ji ZHOU,Li-fa WU,Fan PAN   

  1. College of Command Information System,PLA University of Science and Technology,Nanjing 210007,China
  • Online:2013-10-25 Published:2017-08-10
  • Supported by:
    The National Natural Science Foundation of China;The Natural Science Foundation of Jiangsu Province;The Opening Foundation of Laboratory of Military Network Technology

Abstract:

Present methods for protocol format extraction analyze the execution traces of programs at syntax level,which leads to redundancy and conflict in the results of fie identification.In order to improve the accuracy of field identifica-tion,a semantic level method was proposed for protocol format extraction.The method firstly translated the binary in-structions into equivalent intermediate language,and tracked the parsing process of field semantics through fine-grained dynamic taint analysis.Further,it extracted otocol format using semantic level policies of field identifica-tion,based on the semantic indivisibility of fields.Experimental results show that the proposed method can achieve high identification accuracy with low complexity.

Key words: protocol reverse engineering, protocol format extraction, dynamic taint analysis, intermediate language

No Suggested Reading articles found!