Extracting information from unknown protocols on CampusNet

被引:0
作者
Yu, Zhuanghui [1 ]
Huang, Yongzhong [1 ]
Guo, Shaozhong [1 ]
Zhou, Bei [1 ]
Ren, Hua [2 ]
机构
[1] Informat Engn Univ PLA, Zhengzhou, Peoples R China
[2] PLA Univ Foreign Languages, Luoyang, Peoples R China
来源
PROCEEDINGS OF THE 2007 1ST INTERNATIONAL SYMPOSIUM ON INFORMATION TECHNOLOGIES AND APPLICATIONS IN EDUCATION (ISITAE 2007) | 2007年
关键词
information extraction; message format; dynamic field;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
As information security has been increasingly concerned on our campus network, in inane occasions, it's highly useful to extract information from various network traces, including recognizing malware variants, detecting intrusion, and normalizing traffic. Traditionally, the extracting work often depends on the protocol specification. However, there are often no sufficient documents or time for parsing the protocol specified. We present Catcher, a system for semi-automatically extracting information from unknown protocols. The key novelty in our work is that we locate the information and pick it out directly. Catcher does not require knowledge of any protocol, it automatically parses packets given. In the afterward step, if the same type packets come up, it will recognize their and extract information out of them. In order to lest the effectiveness of our tool, we use Catcher to extract information over Hup and DNS (with no predefinitions of these protocols), as well as chat applications such as MSN, the result reveals that Catcher can extract information from unknown protocols effectively.
引用
收藏
页码:535 / +
页数:3
相关论文
共 9 条
  • [1] BORISOV N, 2007, P 14 ANN NETW DISTR
  • [2] CROVELLA M, 1996, P SIGMETRICS MAY
  • [3] GOPALRATHAM K, 2006, AUTOMATICALLY EXTRAC
  • [4] LEITA C, 2005, P 21 ANN COMP SEC AP
  • [5] MA J, 2006, P ACM IMC OCT
  • [6] NEEDLEMAN SB, 1970, J MOL BIOL, V443, P453
  • [7] PANG R, 2006, P 2006 INT MEAS C OC
  • [8] ZHANG Y, 2001, P ACM SIGCOMM INT ME
  • [9] 2004, PROTOCOL INFORMATICS