量化协议格式的可逆性

Zhengguo Xu, Ling You, Hui Zheng
{"title":"量化协议格式的可逆性","authors":"Zhengguo Xu, Ling You, Hui Zheng","doi":"10.1109/MASS.2018.00079","DOIUrl":null,"url":null,"abstract":"Protocol format reverse engineering aims to extract the protocol fields automatically without access to the protocol specification. Existing works focus on the methodology of deriving the protocol format efficiently, but neglect the relationship between the statistical characteristics of protocol data and the intrinsic properties of the protocol format. In this paper, we study two problems to see how the protocol specification affects the statistical properties, and how the latter affect the difficulty of format reverse analysis. Through empirical analysis of known protocols, we first verify the stationarity of protocol features, which is the stand for developing trace-based reverse methods. We study the position arrangement and value distribution of protocol fields, and investigate their influence on the statistical properties of the protocol format. Then we propose an HMP-based model of protocol data. Using this model, we define two quantitative indicators by protocol fields' structure and content to reflect the reversibility of protocol format: the field non-interlacing ratio and the field information variation. We apply the analysis of format reversibility to a number of typical realistic protocols. The results suggest that the fields of most protocols can be partially revealed, but there are also certain fields difficult for reverse analysis. The quantitative results can provide hints for improving protocol reverse engineering approaches.","PeriodicalId":146214,"journal":{"name":"2018 IEEE 15th International Conference on Mobile Ad Hoc and Sensor Systems (MASS)","volume":"9 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2018-10-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"Quantifying the Reversibility of Protocol Format\",\"authors\":\"Zhengguo Xu, Ling You, Hui Zheng\",\"doi\":\"10.1109/MASS.2018.00079\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Protocol format reverse engineering aims to extract the protocol fields automatically without access to the protocol specification. Existing works focus on the methodology of deriving the protocol format efficiently, but neglect the relationship between the statistical characteristics of protocol data and the intrinsic properties of the protocol format. In this paper, we study two problems to see how the protocol specification affects the statistical properties, and how the latter affect the difficulty of format reverse analysis. Through empirical analysis of known protocols, we first verify the stationarity of protocol features, which is the stand for developing trace-based reverse methods. We study the position arrangement and value distribution of protocol fields, and investigate their influence on the statistical properties of the protocol format. Then we propose an HMP-based model of protocol data. Using this model, we define two quantitative indicators by protocol fields' structure and content to reflect the reversibility of protocol format: the field non-interlacing ratio and the field information variation. We apply the analysis of format reversibility to a number of typical realistic protocols. The results suggest that the fields of most protocols can be partially revealed, but there are also certain fields difficult for reverse analysis. The quantitative results can provide hints for improving protocol reverse engineering approaches.\",\"PeriodicalId\":146214,\"journal\":{\"name\":\"2018 IEEE 15th International Conference on Mobile Ad Hoc and Sensor Systems (MASS)\",\"volume\":\"9 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2018-10-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2018 IEEE 15th International Conference on Mobile Ad Hoc and Sensor Systems (MASS)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/MASS.2018.00079\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2018 IEEE 15th International Conference on Mobile Ad Hoc and Sensor Systems (MASS)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/MASS.2018.00079","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

摘要

协议格式逆向工程的目的是在不访问协议规范的情况下自动提取协议字段。现有的研究侧重于有效推导协议格式的方法,而忽略了协议数据的统计特征与协议格式内在属性之间的关系。本文研究了协议规范对统计特性的影响,以及统计特性对格式逆向分析难度的影响。通过对已知协议的实证分析,我们首先验证了协议特征的平稳性,这是开发基于跟踪的反向方法的基础。研究了协议字段的位置排列和值分布,并探讨了它们对协议格式统计性质的影响。然后提出了一种基于hmp的协议数据模型。利用该模型,我们根据协议字段的结构和内容定义了两个量化指标来反映协议格式的可逆性:字段非隔行率和字段信息变化。我们将格式可逆性分析应用于一些典型的现实协议。结果表明,大多数协议的字段可以部分揭示,但也有一些字段难以反向分析。定量结果可以为改进协议逆向工程方法提供提示。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
Quantifying the Reversibility of Protocol Format
Protocol format reverse engineering aims to extract the protocol fields automatically without access to the protocol specification. Existing works focus on the methodology of deriving the protocol format efficiently, but neglect the relationship between the statistical characteristics of protocol data and the intrinsic properties of the protocol format. In this paper, we study two problems to see how the protocol specification affects the statistical properties, and how the latter affect the difficulty of format reverse analysis. Through empirical analysis of known protocols, we first verify the stationarity of protocol features, which is the stand for developing trace-based reverse methods. We study the position arrangement and value distribution of protocol fields, and investigate their influence on the statistical properties of the protocol format. Then we propose an HMP-based model of protocol data. Using this model, we define two quantitative indicators by protocol fields' structure and content to reflect the reversibility of protocol format: the field non-interlacing ratio and the field information variation. We apply the analysis of format reversibility to a number of typical realistic protocols. The results suggest that the fields of most protocols can be partially revealed, but there are also certain fields difficult for reverse analysis. The quantitative results can provide hints for improving protocol reverse engineering approaches.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信