Abstract：Reverse parsing unknown network protocol is of great significance in many network security applications. Most of the existing protocol reverse parsing methods can not handle the encryption protocol or get the semantic information of the protocol field. To solve this problem, a network protocol parsing technique based on dataflow analysis was proposed. According to the data flow recording tool developed on Pin platform, it could parse the network protocol with the aid of the dependence analysis based data flow tracking technology, as well as obtain the protocol format and semantic information of each protocol field. The experimental results show that the technique can parse out the protocol format correctly, especially for the encryption protocol, and extract the program behavior semantics of each protocol field.
戴理 舒辉 黄荷洁. 基于数据流分析的网络协议逆向解析技术[J]. 计算机应用, 2013, 33(05): 1217-1221.
DAI Li SHU Hui HUANG Hejie. Network protocol reverse parsing technique based on dataflow analysis. Journal of Computer Applications, 2013, 33(05): 1217-1221.