ICEPRE: ICS Protocol Reverse Engineering via Data-Driven Concolic Execution
Yibo Qu, Dongliang Fang, Zhen Wang, Jiaxing Cheng, Shuaizong Si, Yongle Chen, Limin Sun
Abstract
With the advancement of digital transformation, Industrial Control Systems (ICS) are becoming increasingly open and intelligent. However, inherent vulnerabilities in ICS protocols pose significant security threats to devices and systems. The proprietary nature of ICS protocols complicates the security analysis and deployment of protective mechanisms for ICS. Protocol reverse engineering aims to infer the syntax, semantics, and state machines of protocols in the absence of official specifications. Traditional protocol reverse engineering tools face considerable limitations due to the lack of executable environments, incomplete inference strategies, and low-quality network traffic. In this paper, we present ICEPRE, a novel data-driven protocol reverse engineering method based on concolic execution, which uniquely integrates network trace with static analysis. Unlike conventional methods that rely on executable environments, ICEPRE statically tracks the program's parsing process for specific input messages. Furthermore, we employ an innovative field boundary inference strategy to infer the protocol's syntax by analyzing how the protocol parser handles different fields. Our evaluation demonstrates that ICEPRE significantly outperforms previous protocol reverse engineering tools in field boundary inference, achieving an F1 score of 0.76 and a perfection score of 0.67, while DynPRE, BinaryInferno, Nemeys, and Netzob yield (0.65, 0.35), (0.42, 0.14), (0.39, 0.09), and (0.27, 0.10), respectively. These results underscore the superior overall performance of our method. Additionally, ICEPRE exhibits exceptional performance with proprietary protocols in real-world scenarios, highlighting its practical applicability in downstream applications.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get cbc2bdfc-6d4e-471b-b10c-1660f675dd10Cited by top-tier papers1
Ask how each one uses itRelated papers
- DynPRE: Protocol Reverse Engineering via Dynamic InferenceZhengxiong Luo, Kai Liang, Yanyang Zhao, Feifan Wu et al.NDSS 2024
- BinPRE: Enhancing Field Inference in Binary Analysis Based Protocol Reverse EngineeringJiayi Jiang, Xiyuan Zhang, Chengcheng Wan, Haoyi Chen et al.CCS 2024 · 8 citations
- Reverse Engineering Industrial Protocols Driven By Control FieldsZhen Qin, Zeyu Yang, Yangyang Geng, Xin Che et al.INFOCOM 2024 · 17 citations
- Breaking the Traffic Barrier: Unveiling Multi-Format of Protocols via Autonomous Program ExplorationDingzhao Xue, Yibo Qu, Bowen Jiang, Xin Chen et al.ASE 2025
- NetPlier: Probabilistic Network Protocol Reverse Engineering from Message TracesYapeng Ye, Zhuo Zhang, Fei Wang, Xiangyu Zhang et al.NDSS 2021
