Protocol Reverse Engineering via Deep Transfer Learning
Yanyang Zhao, Zhengxiong Luo, Wenlong Zhang, Feifan Wu, Yuanliang Chen, Fuchen Ma, Qi Xu, Heyuan Shi, Yu Jiang
Abstract
Protocol reverse engineering infers the specification of proprietary or poorly documented protocols and serves as the foundation for security analysis such as fuzz testing. While many existing techniques achieve this by mining statistical features from network traces, they face increasing challenges due to incomplete field pattern information available in the traces. Although protocol development has accumulated rich prior knowledge about protocol design, this knowledge remains largely untapped in protocol reverse engineering. This paper introduces TransRE, a protocol reverse engineering tool that leverages prior syntax knowledge from standardized protocols through deep transfer learning to better understand proprietary protocols. TransRE first selects optimal source domains by analyzing inter-domain differences between the existing knowledge base and the target protocol. It then employs a neural network to extract representation features and applies domain adaptation techniques to optimize the syntax transfer model, enabling accurate inference of protocol formats. Our evaluation on 12 widely used protocols shows that TransRE identifies fields with a perfection score of 0.43, which is 1.48×-3.07× the performance achieved by five state-of-the-art methods. Furthermore, to demonstrate practical applicability, we enhanced an existing protocol fuzzer with TransRE for testing proprietary protocols in real-world network cameras and discovered four bugs.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext b63ee3ca-1812-4f69-8d34-56e446730052Builds on14
- HoMM: Higher-Order Moment Matching for Unsupervised Domain AdaptationChao Chen, Zhihang Fu, Zhihong Chen, Sheng Jin et al.AAAI 2020 · 254 citations
- ICS Protocol Fuzzing: Coverage Guided Packet Crack and GenerationZhengxiong Luo, Feilong Zuo, Yuheng Shen, Xun Jiao et al.DAC 2020 · 72 citations
- Automated Attack Synthesis by Extracting Finite State Machines from Protocol Specification DocumentsMaria Leonor Pacheco, Max von Hippel, Ben Weintraub, Dan Goldwasser et al.S&P 2022 · 58 citations
- Your Exploit is Mine: Automatic Shellcode Transplant for Remote ExploitsTiffany Bao, Ruoyu Wang, Yan Shoshitaishvili, David BrumleyS&P 2017 · 56 citations
- MPInspector: A Systematic and Automatic Approach for Evaluating the Security of IoT Messaging ProtocolsQinying Wang, Shouling Ji, Yuan Tian, Xuhong Zhang et al.USENIX Security 2021 · 45 citations
Related papers
- BinPRE: Enhancing Field Inference in Binary Analysis Based Protocol Reverse EngineeringJiayi Jiang, Xiyuan Zhang, Chengcheng Wan, Haoyi Chen et al.CCS 2024 · 8 citations
- ICEPRE: ICS Protocol Reverse Engineering via Data-Driven Concolic ExecutionYibo Qu, Dongliang Fang, Zhen Wang, Jiaxing Cheng et al.ISSTA 2025 · 2 citations
- Breaking the Traffic Barrier: Unveiling Multi-Format of Protocols via Autonomous Program ExplorationDingzhao Xue, Yibo Qu, Bowen Jiang, Xin Chen et al.ASE 2025
- DynPRE: Protocol Reverse Engineering via Dynamic InferenceZhengxiong Luo, Kai Liang, Yanyang Zhao, Feifan Wu et al.NDSS 2024
- Lifting Network Protocol Implementation to Precise Format Specification with Security ApplicationsQingkai Shi, Junyang Shao, Yapeng Ye, Mingwei Zheng et al.CCS 2023 · 15 citations
