Lifting Network Protocol Implementation to Precise Format Specification with Security Applications
Qingkai Shi, Junyang Shao, Yapeng Ye, Mingwei Zheng, Xiangyu Zhang
Abstract
Inferring protocol formats is critical for many security applications. However, existing format-inference techniques often miss many formats, because almost all of them are in a fashion of dynamic analysis and rely on a limited number of network packets to drive their analysis. If a feature is not present in the input packets, the feature will be missed in the resulting formats. We develop a novel static program analysis for format inference. It is well-known that static analysis does not rely on any input packets and can achieve high coverage by scanning every piece of code. However, for efficiency and precision, we have to address two challenges, namely path explosion and disordered path constraints. To this end, our approach uses abstract interpretation to produce a novel data structure called the abstract format graph. It delimits precise but costly operations to only small regions, thus ensuring precision and efficiency at the same time. Our inferred formats are of high coverage and precisely specify both field boundaries and semantic constraints among packet fields. Our evaluation shows that we can infer formats for a protocol in one minute with >95% precision and recall, much better than four baseline techniques. Our inferred formats can substantially enhance existing protocol fuzzers, improving the coverage by 20% to 260% and discovering 53 zero-days with 47 assigned CVEs. We also provide case studies of adopting our inferred formats in other security applications including traffic auditing and intrusion detection.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 4ec79073-a39b-46a3-8d20-788a58c9370bCited by top-tier papers6
- TAI3: Testing Agent Integrity in Interpreting User IntentShiwei Feng, Xiangzhe Xu, Xuan Chen, Kaiyuan Zhang et al.NeurIPS 2025 · 9 citations
- ParDiff: Practical Static Differential Analysis of Network Protocol ParsersMingwei Zheng, Qingkai Shi, Xuwei Liu, Xiangzhe Xu et al.OOPSLA 2024 · 9 citations
- RFCAudit: AI Agent for Auditing Protocol Implementations Against RFC SpecificationsMingwei Zheng, Chengpeng Wang, Xuwei Liu, Jinyao Guo et al.ASE 2025 · 5 citations
- Validating Network Protocol Parsers with Traceable RFC Document InterpretationMingwei Zheng, Danning Xie, Qingkai Shi, Chengpeng Wang et al.ISSTA 2025 · 4 citations
- DynPRE: Protocol Reverse Engineering via Dynamic InferenceZhengxiong Luo, Kai Liang, Yanyang Zhao, Feifan Wu et al.NDSS 2024
Builds on6
- Mining input grammars from dynamic control flowRahul Gopinath, Björn Mathis, Andreas ZellerFSE 2020 · 60 citations
- Message Type Identification of Binary Network Protocols using Continuous Segment SimilarityStephan Kleber, Rens W. van der Heijden, Frank KarglINFOCOM 2020 · 32 citations
- The Closer You Look, The More You Learn: A Grey-box Approach to Protocol State Machine LearningChris McMahon Stone, Sam L. Thomas, Mathy Vanhoef, James Henderson et al.CCS 2022 · 11 citations
- FRAMESHIFTER: Security Implications of HTTP/2-to-HTTP/1 Conversion AnomaliesBahruz Jabiyev, Steven Sprecher, Anthony Gavazzi, Tommaso Innocenti et al.USENIX Security 2022
- ProFactory: Improving IoT Security via Formalized Protocol CustomizationFei Wang, Jianliang Wu, Yuhong Nan, Yousra Aafer et al.USENIX Security 2022
Related papers
- Extracting Protocol Format as State Machine via Controlled Static Loop AnalysisQingkai Shi, Xiangzhe Xu, Xiangyu ZhangUSENIX Security 2023
- BinPRE: Enhancing Field Inference in Binary Analysis Based Protocol Reverse EngineeringJiayi Jiang, Xiyuan Zhang, Chengcheng Wan, Haoyi Chen et al.CCS 2024 · 8 citations
- Generating Precise Format Specification for Network Protocols Through Adversarial LLM InteractionsHengdi Ye, Bing Shui, Jielun Wu, Yufan Zhou et al.USENIX Security 2026
- Breaking the Traffic Barrier: Unveiling Multi-Format of Protocols via Autonomous Program ExplorationDingzhao Xue, Yibo Qu, Bowen Jiang, Xin Chen et al.ASE 2025
- BEACON: Directed Grey-Box Fuzzing with Provable Path PruningHeqing Huang, Yiyuan Guo, Qingkai Shi, Peisen Yao et al.S&P 2022 · 139 citations
