arrow
Return

Similarity-based Field Inference for Unknown Binary Network Protocols

delete2025-12-18
delete0
PRE
AI
X
Xiuwen Sun *
Y
Yu Chen
李慧盈 cover
李慧盈 (Huiying Li)
L
Linlin Xia
J
Jie Cui
仲红 (Hong Zhong)
DOI:10.1016/j.comnet.2025.111948delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Protocol reverse engineering refers to the process of inferring specifications or semantics for unknown network protocols, which is a critical capability for comprehensive analysis and performance evaluation of network systems. Existing work mainly focuses on extracting protocol fields, often overlooking the challenge of accurately identifying variable-length fields. In this paper, we propose FLINT for reconstructing complete fields format of unknown binary network protocols through static trace analysis. FLINT first clusters messages by structural similarity and separates protocol headers from payloads using information entropy. It then incorporates message length features and performs location-aware association analysis to identify candidate variable-length fields. These candidates are refined using sequence alignment to infer exact boundaries. Subsequently, variable-length fields are normalized via zero-padding, and bit-level similarity is computed across horizontal adjacent offsets. The remaining field boundaries are ultimately identified by detecting inflection points in the fitted similarity curve. We evaluate FLINT across multiple real-world network traces spanning sixteen diverse protocols. Experimental results show that FLINT outperforms state-of-the-art approaches, achieving high precision, recall, and F1-scores in the extraction of both variable-length and fixed-length fields.

Journal

Computer Networks cover
Computer Networks
IF:
4.6
Papers:
1.5K
Citations:
1.6W

Organization

No organization information available