A Preamble Mining Algorithm Oriented to Binary Protocol Using Random Probes
At present, most of the researches on the protocol reverse are on the basis of segmented frames and lack of effective methods to analyze the raw data stream. Several existing frame segmentation algorithms based on AC have the problem of large space overhead and low time efficiency. In this paper, we study on frames segmentation algorithms based on preamble mining and propose a preamble mining algorithm based on random probes oriented to binary protocol. We extract the correct preamble by randomly inserting some probes into the data stream, from which to find continuous short mode strings, after which extracting the most frequently repeated strings as the candidate units, and then filtering them with the help of structural characteristics of the preamble. Experiment shows that the algorithm has higher time efficiency compared with the preamble mining algorithm based on AC algorithm.
KeywordsProtocol reverse Frames segmentation Preamble mining Random probes
This work is supported by the National Natural Science Foundation of China (Grant Number: 61471141, 61361166006), Key Technology Program of Shenzhen, China, (No. JSGG20160427185010977) and Basic Research Project of Shenzhen, China (grant Number: JCYJ20150513151706561).
- Marshall, A.: Beddoe: Network Protocol Analysis using Bioinformatics Algorithms (2004)Google Scholar
- Ling, J.: Study on bit stream oriented unknown frame head. A Dissertation Submitted to Shanghai Jiao Tong University for the Master Degree of Engineering, January 2011Google Scholar
- Hezhou, W., Kaiping, X.: An unknown link Protocol bit stream segmentation Algorithm based on frequent statistics and association rules. J. Univ. Sci. Technol. China 43(7), 554–560 (2013)Google Scholar
- Aixia, W.: The technology research of feature selection for unknown protocol in the form of bit stream. A Master Thesis Submitted to University of Electronic Science and Technology of China, May 2015Google Scholar
- Dong, L., Tao, W.: Unknown protocol frame segmentation algorithm based on preamble. J. Comput. Appl. 37(2), 440–444 (2017)Google Scholar