• 文献检索
  • 文档翻译
  • 深度研究
  • 学术资讯
  • Suppr Zotero 插件Zotero 插件
  • 邀请有礼
  • 套餐&价格
  • 历史记录
应用&插件
Suppr Zotero 插件Zotero 插件浏览器插件Mac 客户端Windows 客户端微信小程序
定价
高级版会员购买积分包购买API积分包
服务
文献检索文档翻译深度研究API 文档MCP 服务
关于我们
关于 Suppr公司介绍联系我们用户协议隐私条款
关注我们

Suppr 超能文献

核心技术专利:CN118964589B侵权必究
粤ICP备2023148730 号-1Suppr @ 2026

文献检索

告别复杂PubMed语法,用中文像聊天一样搜索,搜遍4000万医学文献。AI智能推荐,让科研检索更轻松。

立即免费搜索

文件翻译

保留排版,准确专业,支持PDF/Word/PPT等文件格式,支持 12+语言互译。

免费翻译文档

深度研究

AI帮你快速写综述,25分钟生成高质量综述,智能提取关键信息,辅助科研写作。

立即免费体验

一种面向消息类型的协议逆向工程消息聚类方法。

A Type-Aware Approach to Message Clustering for Protocol Reverse Engineering.

机构信息

College of Computer, National University of Defense Technology, Changsha 410073, China.

School of Cyberspace Security, Hangzhou Dianzi University, Hangzhou 310018, China.

出版信息

Sensors (Basel). 2019 Feb 10;19(3):716. doi: 10.3390/s19030716.

DOI:10.3390/s19030716
PMID:30744187
原文链接:https://pmc.ncbi.nlm.nih.gov/articles/PMC6386832/
Abstract

Protocol Reverse Engineering (PRE) is crucial for information security of Internet-of-Things (IoT), and message clustering determines the effectiveness of PRE. However, the quality of services still lags behind the strict requirement of IoT applications as the results of message clustering are often coarse-grained with the intrinsic type information hidden in messages largely ignored. Aiming at this problem, this study proposes a type-aware approach to message clustering guided by type information. The approach regards a message as a combination of n-grams, and it employs the Latent Dirichlet Allocation (LDA) model to characterize messages with types and n-grams via inferring the type distribution of each message. The type distribution is finally used to measure the similarity of messages. According to this similarity, the approach clusters messages and further extracts message formats. Experimental results of the approach against Netzob in terms of a number of protocols indicate that the correctness and conciseness can be significantly improved, e.g., figures 43.86% and 3.87%, respectively for the CoAP protocol.

摘要

协议逆向工程(PRE)对于物联网(IoT)的信息安全至关重要,而消息聚类决定了 PRE 的有效性。然而,服务质量仍然落后于物联网应用的严格要求,因为消息聚类的结果通常是粗粒度的,消息中隐藏的固有类型信息在很大程度上被忽略了。针对这个问题,本研究提出了一种基于类型信息指导的消息聚类的方法。该方法将消息视为 n-gram 的组合,并通过推断每个消息的类型分布,使用潜在狄利克雷分配(LDA)模型来对带有类型和 n-gram 的消息进行特征化。最后,类型分布用于衡量消息的相似性。根据这种相似性,该方法对消息进行聚类,并进一步提取消息格式。该方法在 Netzob 上针对多个协议进行的实验结果表明,正确性和简洁性可以得到显著提高,例如,CoAP 协议的正确率提高了 43.86%,简洁性提高了 3.87%。

https://cdn.ncbi.nlm.nih.gov/pmc/blobs/8bd0/6386832/032e0c4ca0f7/sensors-19-00716-g007.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/8bd0/6386832/f7cda15c8bed/sensors-19-00716-g001.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/8bd0/6386832/31aa7ee98e6f/sensors-19-00716-g002.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/8bd0/6386832/aa2f1d08cabe/sensors-19-00716-g003.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/8bd0/6386832/a0f263baf9b2/sensors-19-00716-g004.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/8bd0/6386832/5fe2d48011b3/sensors-19-00716-g005.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/8bd0/6386832/3b2b55d7ca91/sensors-19-00716-g006.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/8bd0/6386832/032e0c4ca0f7/sensors-19-00716-g007.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/8bd0/6386832/f7cda15c8bed/sensors-19-00716-g001.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/8bd0/6386832/31aa7ee98e6f/sensors-19-00716-g002.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/8bd0/6386832/aa2f1d08cabe/sensors-19-00716-g003.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/8bd0/6386832/a0f263baf9b2/sensors-19-00716-g004.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/8bd0/6386832/5fe2d48011b3/sensors-19-00716-g005.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/8bd0/6386832/3b2b55d7ca91/sensors-19-00716-g006.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/8bd0/6386832/032e0c4ca0f7/sensors-19-00716-g007.jpg

相似文献

1
A Type-Aware Approach to Message Clustering for Protocol Reverse Engineering.一种面向消息类型的协议逆向工程消息聚类方法。
Sensors (Basel). 2019 Feb 10;19(3):716. doi: 10.3390/s19030716.
2
Lightweight CoAP-Based Bootstrapping Service for the Internet of Things.用于物联网的轻量级基于CoAP的引导服务。
Sensors (Basel). 2016 Mar 11;16(3):358. doi: 10.3390/s16030358.
3
LOADng-IoT: An Enhanced Routing Protocol for Internet of Things Applications over Low Power Networks.LOADng-IoT:适用于低功耗网络的物联网应用的增强型路由协议。
Sensors (Basel). 2019 Jan 3;19(1):150. doi: 10.3390/s19010150.
4
A Mechanism for Reliable Mobility Management for Internet of Things Using CoAP.一种使用受限应用协议(CoAP)的物联网可靠移动性管理机制。
Sensors (Basel). 2017 Jan 12;17(1):136. doi: 10.3390/s17010136.
5
Impact of CoAP and MQTT on NB-IoT System Performance.CoAP 和 MQTT 对 NB-IoT 系统性能的影响。
Sensors (Basel). 2018 Dec 20;19(1):7. doi: 10.3390/s19010007.
6
Context-Aware Gossip-Based Protocol for Internet of Things Applications.面向物联网应用的上下文感知闲聊协议。
Sensors (Basel). 2018 Jul 11;18(7):2233. doi: 10.3390/s18072233.
7
Implementation and Evaluation of Four Interoperable Open Standards for the Internet of Things.物联网四项可互操作开放标准的实施与评估
Sensors (Basel). 2015 Sep 22;15(9):24343-73. doi: 10.3390/s150924343.
8
MultiFuzz: A Coverage-Based Multiparty-Protocol Fuzzer for IoT Publish/Subscribe Protocols.MultiFuzz:一种用于物联网发布/订阅协议的基于覆盖的多方协议模糊测试器。
Sensors (Basel). 2020 Sep 11;20(18):5194. doi: 10.3390/s20185194.
9
IoT Service Clustering for Dynamic Service Matchmaking.用于动态服务匹配的物联网服务聚类
Sensors (Basel). 2017 Jul 27;17(8):1727. doi: 10.3390/s17081727.
10
Development of Virtual Resource Based IoT Proxy for Bridging Heterogeneous Web Services in IoT Networks.基于虚拟资源的物联网代理的开发,用于弥合物联网网络中异构 Web 服务之间的差距。
Sensors (Basel). 2018 May 26;18(6):1721. doi: 10.3390/s18061721.

引用本文的文献

1
A Compact and Flexible UHF RFID Tag Antenna for Massive IoT Devices in 5G System.一种用于5G系统中大量物联网设备的紧凑灵活超高频射频识别标签天线。
Sensors (Basel). 2020 Oct 8;20(19):5713. doi: 10.3390/s20195713.