Protocol Structure and Sequence Detection Method for Multi-Protocol Analysis 


Vol. 49,  No. 4, pp. 556-566, Apr.  2024
10.7840/kics.2024.49.4.556


PDF
  Abstract

This paper introduces a protocol structure and sequence detection method designed for multi-protocol analysis in the field of protocol reverse engineering, with the aim of mitigating cyber threats such as malware and system hacking. Multi-protocol data, involving two or more undefined protocols, requires effective protocol classification. To address this, our study employs a hierarchical clustering method for multi-protocol classification, enhancing the performance and reducing the computational complexity of the protocol structure and sequence detection algorithm by removing payload of messages. The proposed method is evaluated using both a frequent sequence detection algorithm with a sliding window and a Contiguous Sequential Pattern (CSP) algorithm for protocol structure and sequence detection. Results demonstrate that the inclusion of hierarchical clustering and payload removal in both the frequent sequence detection algorithm and the CSP algorithm leads to notable performance enhancements.

  Statistics
Cumulative Counts from November, 2022
Multiple requests among the same browser session are counted as one view. If you mouse over a chart, the values of data points will be shown.


  Related Articles
  Cite this article

[IEEE Style]

H. Cho, J. Park, M. Chae, H. Lee, W. Lim, "Protocol Structure and Sequence Detection Method for Multi-Protocol Analysis," The Journal of Korean Institute of Communications and Information Sciences, vol. 49, no. 4, pp. 556-566, 2024. DOI: 10.7840/kics.2024.49.4.556.

[ACM Style]

Hyunwoo Cho, Jihwan Park, Myoungho Chae, Haeyoung Lee, and Wansu Lim. 2024. Protocol Structure and Sequence Detection Method for Multi-Protocol Analysis. The Journal of Korean Institute of Communications and Information Sciences, 49, 4, (2024), 556-566. DOI: 10.7840/kics.2024.49.4.556.

[KICS Style]

Hyunwoo Cho, Jihwan Park, Myoungho Chae, Haeyoung Lee, Wansu Lim, "Protocol Structure and Sequence Detection Method for Multi-Protocol Analysis," The Journal of Korean Institute of Communications and Information Sciences, vol. 49, no. 4, pp. 556-566, 4. 2024. (https://doi.org/10.7840/kics.2024.49.4.556)
Vol. 49, No. 4 Index