Discoverer: Automatic Protocol Reverse Engineering from Network Traces

Discoverer: Automatic Protocol Reverse Engineering from Network Traces
复制标题

DOI:
--
复制
发表时间:
2007-08
期刊:
--
影响因子:
--
通讯作者:
Weidong Cui;Jayanthkumar Kannan;Helen J. Wang
Weidong Cui;Jayanthkumar Kannan;Helen J. Wang
中科院分区:
其他
文献类型:
--
作者:
Weidong Cui;Jayanthkumar Kannan;Helen J. Wang

文献摘要

被引文献

相似文献

应用程序级协议规范对许多安全应用程序都很有用,包括执行深度数据包检测和流量规范化的入侵预防和检测,以及生成应用程序网络输入以发现潜在漏洞的渗透测试。然而,目前在推导协议规范方面的实践主要是手动的。在本文中,我们提出了发现者,一个工具,自动逆向工程的协议消息格式的应用程序,从其网络跟踪。Discoverer的一个关键属性是,它通过推断在许多应用程序级协议的消息格式中常见的协议习惯用法,以独立于协议的方式运行。我们通过比较我们推断的格式与从Ethereal获得的真实格式,评估了Discoverer在一个文本协议(HTTP)和两个二进制协议(RPC和CIFS/SMB)上的有效性[5]。对于所有三种协议,超过90%的推断格式恰好对应于一种真实格式;一种真实格式平均反映在五种推断格式中;我们的推断格式覆盖了超过95%的消息,这些消息属于30-40%的真实格式在跟踪中观察到。
Application-level protocol specifications are useful for many security applications, including intrusion prevention and detection that performs deep packet inspection and traffic normalization, and penetration testing that generates network inputs to an application to uncover potential vulnerabilities. However, current practice in deriving protocol specifications is mostly manual. In this paper, we present Discoverer, a tool for automatically reverse engineering the protocol message formats of an application from its network trace. A key property of Discoverer is that it operates in a protocol-independent fashion by inferring protocol idioms commonly seen in message formats of many application-level protocols. We evaluated the efficacy of Discoverer over one text protocol (HTTP) and two binary protocols (RPC and CIFS/SMB) by comparing our inferred formats with true formats obtained from Ethereal [5]. For all three protocols, more than 90% of our inferred formats correspond to exactly one true format; one true format is reflected in five inferred formats on average; our inferred formats cover over 95% of messages, which belong to 30-40% of true formats observed in the trace.