基于状态标注的协议状态机逆向方法
发布时间:2018-09-06 14:44
【摘要】:协议状态机可以描述一个协议的行为,帮助理解协议的行为逻辑。面向文本类协议,首先利用统计学方法提取表示报文类型的语义关键字;然后利用邻接矩阵描述报文类型之间的时序关系,基于时序关系进行协议状态标注,构建出协议的状态转换图。实验表明,该方法可以正确地描述出报文类型的时序关系,抽象出准确的状态机模型。
[Abstract]:Protocol state machines can describe the behavior of a protocol and help to understand its behavioral logic. For text-class protocols, the semantic keywords representing message types are extracted by statistical method, then the temporal relationships between message types are described by adjacency matrix, and the protocol status is annotated based on temporal relationships. The state transition diagram of the protocol is constructed. Experimental results show that the proposed method can correctly describe the temporal relationships of message types and abstract accurate state machine models.
【作者单位】: 信息工程大学;
【基金】:国家973计划项目(2011CB311801) 河南省科技创新人才计划项目(114200510001)
【分类号】:TP393.08
[Abstract]:Protocol state machines can describe the behavior of a protocol and help to understand its behavioral logic. For text-class protocols, the semantic keywords representing message types are extracted by statistical method, then the temporal relationships between message types are described by adjacency matrix, and the protocol status is annotated based on temporal relationships. The state transition diagram of the protocol is constructed. Experimental results show that the proposed method can correctly describe the temporal relationships of message types and abstract accurate state machine models.
【作者单位】: 信息工程大学;
【基金】:国家973计划项目(2011CB311801) 河南省科技创新人才计划项目(114200510001)
【分类号】:TP393.08
【参考文献】
相关期刊论文 前6条
1 李伟明;张爱芳;刘建财;李之棠;;网络协议的自动化模糊测试漏洞挖掘方法[J];计算机学报;2011年02期
2 郝耀辉;郭渊博;刘伟;李景锋;;基于有限自动机的密码协议入侵检测方法[J];计算机应用研究;2008年01期
3 潘t,
本文编号:2226677
本文链接:https://www.wllwen.com/guanlilunwen/ydhl/2226677.html