Dual-track Protocol Reverse Analysis Based on Share Learning
Weiyao Zhang, Xuying Meng, Yujun Zhang
Abstract
Private protocols, whose specifications are agnostic, are widely used in the Industrial Internet. While providing customized service, they also raise essential security concerns as well, due to their agnostic nature. The Protocol Reverse Analysis (PRA) techniques are developed to infer the specifications of private protocols. However, the conventional PRA techniques are far from perfection for the following reasons: (i) Error propagation: Canonical solutions strictly follow the "from keyword extraction to message clustering" serial structure, which deteriorates the performance for ignoring the interplay between the sub-tasks, and the error will flow and accumulate through the sequential workflow. (ii) Increasing diversity: As the protocols’ diversities of characteristics increase, tailoring for specific types of protocols becomes infeasible. To address these issues, we design a novel dual-track framework SPRA, and propose Share Learning, a new concept of protocol reverse analysis. Particularly, based on the share layer for protocol learning, SPRA builds a parallel workflow to co-optimize both the generative model for keyword extraction and the probability-based model for message clustering, which delivers automatic and robust syntax inference across diverse protocols and greatly improves the performance. Experiments on five real-world datasets demonstrate that the proposed SPRA achieves better performance compared with the state-of-art PRA methods.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Cited by top-tier papers1
Ask how each one uses itRelated papers
- NetPlier: Probabilistic Network Protocol Reverse Engineering from Message TracesYapeng Ye, Zhuo Zhang, Fei Wang, Xiangyu Zhang et al.NDSS 2021
- Industrial Control Protocol Type Inference Using Transformer and Rule-based Re-ClusteringYuhuan Liu, Yulong Ding, Jie Jiang, Bin Xiao et al.INFOCOM 2024 · 4 citations
- ICEPRE: ICS Protocol Reverse Engineering via Data-Driven Concolic ExecutionYibo Qu, Dongliang Fang, Zhen Wang, Jiaxing Cheng et al.ISSTA 2025 · 2 citations
- Message Type Identification of Binary Network Protocols using Continuous Segment SimilarityStephan Kleber, Rens W. van der Heijden, Frank KarglINFOCOM 2020 · 32 citations
- Reverse Engineering Industrial Protocols Driven By Control FieldsZhen Qin, Zeyu Yang, Yangyang Geng, Xin Che et al.INFOCOM 2024 · 17 citations
