作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2012, Vol. 38 ›› Issue (19): 277-280. doi: 10.3969/j.issn.1000-3428.2012.19.071

• 开发研究与设计技术 • 上一篇    下一篇

一种基于报文序列分析的半自动协议逆向方法

杜有翔,吴礼发,潘 璠,洪 征   

  1. (解放军理工大学指挥自动化学院,南京 210007)
  • 收稿日期:2011-11-28 出版日期:2012-10-05 发布日期:2012-09-29
  • 作者简介:杜有翔(1986-),男,硕士研究生,主研方向:逆向工程;吴礼发,教授、博士、博士生导师;潘 璠,博士研究生;洪 征,副教授、博士
  • 基金资助:
    江苏省自然科学基金资助项目(BK2011115)

A Semiautomatic Protocol Reverse Method Based on Message Sequence Analysis

DU You-xiang, WU Li-fa, PAN Fan, HONG Zheng   

  1. (Institute of Command Automation, PLA University of Science and Technology, Nanjing 210007, China)
  • Received:2011-11-28 Online:2012-10-05 Published:2012-09-29

摘要: 基于报文序列分析的协议逆向方法在自动化分析过程中缺乏对人工知识的引入。为此,提出一种半自动协议逆向方法。通过人工输入的方式,将先验知识加入到报文分析中,用于指导报文的语义推断,并对分析结果进行人工纠正。实验结果表明,该方法能提高报文分析的效率和准确率。

关键词: 协议逆向工程, 人工知识, 先验知识, 人工纠正, 语义推断, 语义验证

Abstract: Protocol reverse methods based on message sequence analysis are all automatic and lack of considering the human knowledge in the automatic analysis. This paper presents a semiautomatic method, which makes use of human knowledge. This method brings the prior knowledge into the process of analysis via manual input, which can induct the semantic inference of the samples in some degree. It can also correct the result of analysis manually. Experimental results show that this method not only can improve the efficiency, but also can increase the accuracy of analysis obviously.

Key words: protocol reverse engineering, human knowledge, priori knowledge, artificial correction, semantic inference, semantic verification

中图分类号: