A Preamble Mining Algorithm Oriented to Binary Protocol Using Random Probes

  • Tingyue Yu
  • Shen WangEmail author
  • Xiangzhan Yu
Conference paper
Part of the Smart Innovation, Systems and Technologies book series (SIST, volume 82)


At present, most of the researches on the protocol reverse are on the basis of segmented frames and lack of effective methods to analyze the raw data stream. Several existing frame segmentation algorithms based on AC have the problem of large space overhead and low time efficiency. In this paper, we study on frames segmentation algorithms based on preamble mining and propose a preamble mining algorithm based on random probes oriented to binary protocol. We extract the correct preamble by randomly inserting some probes into the data stream, from which to find continuous short mode strings, after which extracting the most frequently repeated strings as the candidate units, and then filtering them with the help of structural characteristics of the preamble. Experiment shows that the algorithm has higher time efficiency compared with the preamble mining algorithm based on AC algorithm.


Protocol reverse Frames segmentation Preamble mining Random probes 



This work is supported by the National Natural Science Foundation of China (Grant Number: 61471141, 61361166006), Key Technology Program of Shenzhen, China, (No. JSGG20160427185010977) and Basic Research Project of Shenzhen, China (grant Number: JCYJ20150513151706561).


  1. Narayan, J., Shukla, S.K.: A survey of automatic protocol reverse engineering tools. ACM Comput. Surv. 48(3), 1–26 (2015)CrossRefGoogle Scholar
  2. Marshall, A.: Beddoe: Network Protocol Analysis using Bioinformatics Algorithms (2004)Google Scholar
  3. Luo, J.-Z., Shun-Zheng, Yu.: Position-based automatic reverse engineering of network protocols. J. Netw. Comput. Appl. 36, 1070–1077 (2013)CrossRefGoogle Scholar
  4. Zhang, Z., Zhang, Z.: Toward unsupervised protocol feature word extraction. IEEE J. Sel. Areas Commun. 32(10), 1894–1906 (2014)MathSciNetCrossRefGoogle Scholar
  5. Aho, A.V., Corasick, M.J.: Efficient string matching: an aid to bibliographic search. Commun. ACM 18(6), 333–340 (1975)MathSciNetCrossRefzbMATHGoogle Scholar
  6. Ling, J.: Study on bit stream oriented unknown frame head. A Dissertation Submitted to Shanghai Jiao Tong University for the Master Degree of Engineering, January 2011Google Scholar
  7. Hezhou, W., Kaiping, X.: An unknown link Protocol bit stream segmentation Algorithm based on frequent statistics and association rules. J. Univ. Sci. Technol. China 43(7), 554–560 (2013)Google Scholar
  8. Aixia, W.: The technology research of feature selection for unknown protocol in the form of bit stream. A Master Thesis Submitted to University of Electronic Science and Technology of China, May 2015Google Scholar
  9. Dong, L., Tao, W.: Unknown protocol frame segmentation algorithm based on preamble. J. Comput. Appl. 37(2), 440–444 (2017)Google Scholar

Copyright information

© Springer International Publishing AG 2018

Authors and Affiliations

  1. 1.Department of Computer Science and TechnologyHarbin Institute of TechnologyHarbinChina

Personalised recommendations