TY - JOUR
T1 - Analysis of the network protocol syntax based on similarity matching
AU - Guo, Liang
AU - Luo, Sen Lin
AU - Pan, Li Min
N1 - Publisher Copyright:
© 2016, Beijing Institute of Technology. All right reserved.
PY - 2016/5/1
Y1 - 2016/5/1
N2 - To solve the problems in analysis of the network protocol syntax, which are rely on human intervention, low efficiency and narrow scope, a method was proposed for analysis of network protocol syntax based on similarity matching. The main process of the method include collecting the raw packets by network sniffer, and then preprocessing the packets, using a variety of methods for 9 features extraction, establishing a network protocol syntax analysis model based on similarity matching method, to analyze the syntax feature of network protocol. Taking the TCP protocol as a known protocol, experiments were actualized with different types of protocols as UDP, DNS and QQ. The results show that in the three types of protocol header, more than 33% of the correct similar syntax fields can be found in TCP protocol, and the average accuracy rate was over 96%, the process needs not manual intervention, it can improve the analysis efficiency, reduce the constraints, expand the scope of the analysis, and analyze the network protocol syntax more effectively.
AB - To solve the problems in analysis of the network protocol syntax, which are rely on human intervention, low efficiency and narrow scope, a method was proposed for analysis of network protocol syntax based on similarity matching. The main process of the method include collecting the raw packets by network sniffer, and then preprocessing the packets, using a variety of methods for 9 features extraction, establishing a network protocol syntax analysis model based on similarity matching method, to analyze the syntax feature of network protocol. Taking the TCP protocol as a known protocol, experiments were actualized with different types of protocols as UDP, DNS and QQ. The results show that in the three types of protocol header, more than 33% of the correct similar syntax fields can be found in TCP protocol, and the average accuracy rate was over 96%, the process needs not manual intervention, it can improve the analysis efficiency, reduce the constraints, expand the scope of the analysis, and analyze the network protocol syntax more effectively.
KW - Analysis of the network protocol syntax
KW - Protocol reverse
KW - Similarity matching
UR - https://www.scopus.com/pages/publications/84974705066
U2 - 10.15918/j.tbit1001-0645.2016.05.015
DO - 10.15918/j.tbit1001-0645.2016.05.015
M3 - Article
AN - SCOPUS:84974705066
SN - 1001-0645
VL - 36
SP - 520
EP - 523
JO - Beijing Ligong Daxue Xuebao/Transaction of Beijing Institute of Technology
JF - Beijing Ligong Daxue Xuebao/Transaction of Beijing Institute of Technology
IS - 5
ER -