DocumentCode
717469
Title
Automatic protocol field inference for deeper protocol understanding
Author
Bermudez, Ignacio ; Tongaonkar, Alok ; Iliofotou, Marios ; Mellia, Marco ; Munafo, Maurizio M.
Author_Institution
Symantec Corp., CA, USA
fYear
2015
fDate
20-22 May 2015
Firstpage
1
Lastpage
9
Abstract
Security tools have evolved dramatically in the recent years to combat the increasingly complex nature of attacks, but to be effective these tools need to be configured by experts that understand network protocols thoroughly. In this paper we present FieldHunter, which automatically extracts fields and infers their types; providing this much needed information to the security experts for keeping pace with the increasing rate of new network applications and their underlying protocols. FieldHunter relies on collecting application messages from multiple sessions and then applying statistical correlations is able to infer the types of the fields. These statistical correlations can be between different messages or other associations with meta-data such as message length, client or server IPs. Our system is designed to extract and infer fields from both binary and textual protocols. We evaluated FieldHunter on real network traffic collected in ISP networks from three different continents. FieldHunter was able to extract security relevant fields and infer their nature for well documented network protocols (such as DNS and MSNP) as well as protocols for which the specifications are not publicly available (such as SopCast) and from malware such as (Ramnit).
Keywords
Internet; invasive software; meta data; statistical analysis; telecommunication traffic; transport protocols; DNS; FieldHunter; ISP network; Internet protocol; Internet service provider; MSNP; Microsoft notification protocol; Ramnit; SopCast; automatic protocol field inference; binary protocol; client IP; domain name system; field extraction; malware; message length; metadata; network protocol; network traffic; protocol understanding; security tool; server IP; statistical correlation; textual protocol; Correlation; Entropy; IP networks; Protocols; Radiation detectors; Security; Servers;
fLanguage
English
Publisher
ieee
Conference_Titel
IFIP Networking Conference (IFIP Networking), 2015
Conference_Location
Toulouse
Type
conf
DOI
10.1109/IFIPNetworking.2015.7145307
Filename
7145307
Link To Document