• 中国计算机学会会刊
  • 中国科技核心期刊
  • 中文核心期刊

J4 ›› 2015, Vol. 37 ›› Issue (04): 682-691.

• 论文 • Previous Articles     Next Articles

Extraction and recognition of protocol fingerprint
based on protocol deviation  

LI Meijian,WANG Yongjun,XIE Peidai,HUANG Zhijian   

  1. (College of Computer,National University of Defense Technology,Changsha 410073,China)
  • Received:2013-11-01 Revised:2014-02-24 Online:2015-04-25 Published:2015-04-25

Abstract:

Since traditional protocol fingerprinting methods are usually time-consuming and cannot properly extract or recognize cryptographic protocols, we propose a novel protocol fingerprinting method based on protocol deviation. Protocol deviation describes the network behavior differentiations between different protocol implementations. Based on the dynamic binary analysis technology, the proposed method extracts protocol characteristics from the session stream level and the message level of protocol deviation. Experimental results show that the proposed method is not only feasible, but also provides a new idea for the fingerprinting of cryptographic protocol applications.

Key words: protocol deviation;protocol reverse engineering;protocol fingerprint;protocol signature