NOMS 2018 - 2018 IEEE/IFIP Network Operations and Management Symposium 2018
DOI: 10.1109/noms.2018.8406311
|View full text |Cite
|
Sign up to set email alerts
|

Inference of network unknown protocol structure using CSP(Contiguous Sequence Pattern) algorithm based on tree structure

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
3
1

Citation Types

0
4
0

Year Published

2020
2020
2024
2024

Publication Types

Select...
5
1

Relationship

1
5

Authors

Journals

citations
Cited by 7 publications
(4 citation statements)
references
References 10 publications
0
4
0
Order By: Relevance
“…Through interactive syntax inference technology, it automatically learned to generate the protocol state machine. Shim et al [60] studied the specification extraction of unknown protocols, using the Apriori-based CSP(Contiguous Sequence Pattern) machine learning algorithm to extract the protocol common strings, and using the tree structure-based CSP algorithm to extract the static fields of the protocol. It can extract all the static fields that are not used often but are possible.…”
Section: A Vulnerabilities In Designmentioning
confidence: 99%
“…Through interactive syntax inference technology, it automatically learned to generate the protocol state machine. Shim et al [60] studied the specification extraction of unknown protocols, using the Apriori-based CSP(Contiguous Sequence Pattern) machine learning algorithm to extract the protocol common strings, and using the tree structure-based CSP algorithm to extract the static fields of the protocol. It can extract all the static fields that are not used often but are possible.…”
Section: A Vulnerabilities In Designmentioning
confidence: 99%
“…The proposed method collects more than two message flows, performs pre-processing that extracts messages from the collected data, and then clusters messages of the same type using the k-means algorithm. Common fields are then extracted from the clustered messages using the Apriori algorithm [22] and messages of the same type are merged using these extracted fields.…”
Section: Introductionmentioning
confidence: 99%
“…For each type, this system uses contiguous sequence pattern (CSP) algorithms to extract a common substring that defines the field. 22 The structure of the messages is analyzed after field definitions. Finally, the sequence and structure of the message types can be used to identify the types of messages used at industrial sites, the meaning of the fields, and the commands transmitted by the network traffic.…”
Section: Introductionmentioning
confidence: 99%
“…These grouped messages are defined as one type. For each type, this system uses contiguous sequence pattern (CSP) algorithms to extract a common substring that defines the field 22 . The structure of the messages is analyzed after field definitions.…”
Section: Introductionmentioning
confidence: 99%