Abstract
An effective method for reverse engineering message format specification is proposed, which is a necessary step to extract the protocol’s state machine. First, separators are scanned and compared to accomplish protocol fields partitioned hierarchically, so as to determine the field boundaries recursively and achieve the basic field; second, the protocol candidate tokens are extracted by frequency statistics; finally, the logic feature selector is designed for filtering the logic feature keywords. The experimental valuation demonstrates the validation of partitioning fields and extracting logic feature keyword.
Get full access to this article
View all access options for this article.
