Refining Network Message Segmentation with Principal Component Analysis

Autor: Kleber, Stephan, Kargl, Frank
Rok vydání: 2022
Předmět:
Zdroj: Proceedings of the Tenth Annual IEEE Conference on Communications and Network Security 2022. CNS. Austin, TX, USA
Druh dokumentu: Working Paper
Popis: Reverse engineering of undocumented protocols is a common task in security analyses of networked services. The communication itself, captured in traffic traces, contains much of the necessary information to perform such a protocol reverse engineering. The comprehension of the format of unknown messages is of particular interest for binary protocols that are not human-readable. One major challenge is to discover probable fields in a message as the basis for further analyses. Given a set of messages, split into segments of bytes by an existing segmenter, we propose a method to refine the approximation of the field inference. We use principle component analysis (PCA) to discover linearly correlated variance between sets of message segments. We relocate the boundaries of the initial coarse segmentation to more accurately match with the true fields. We perform different evaluations of our method to show its benefit for the message format inference and subsequent analysis tasks from literature that depend on the message format. We can achieve a median improvement of the message format accuracy across different real-world protocols by up to 100 %.
Databáze: arXiv