arrow
Return

PRoRE: A Protocol Message Structure Reconstruction Method Based on Execution Slice Embedding

delete2026-01-01
delete0
PRE
AI
Y
Yuyao Huang
H
Hui‐Kuo G. Shu
F
Fei Kang *
DOI:10.32604/cmc.2025.071552delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Message structure reconstruction is a critical task in protocol reverse engineering, aiming to recover protocol field structures without access to source code. It enables important applications in network security, including malware analysis and protocol fuzzing. However, existing methods suffer from inaccurate field boundary delineation and lack hierarchical relationship recovery, resulting in imprecise and incomplete reconstructions. In this paper, we propose PRoRE, a novel method for reconstructing protocol field structures based on program execution slice embedding. PRoRE extracts code slices from protocol parsing at runtime, converts them into embedding vectors using a data flow-sensitive assembly language model, and performs hierarchical clustering to recover complete protocol field structures. Evaluation on two datasets containing 12 protocols shows that PRoRE achieves an average F1 score of 0.85 and a cophenetic correlation coefficient of 0.189, improving by 19% and 0.126% respectively over state-of-the-art methods (including BINPRE, TuPNI, NETLIFTER, and QwQ-32B-preview), demonstrating significant superiority in both accuracy and completeness of field structure recovery. Case studies further validate the effectiveness of PRoRE in practical malware analysis scenarios.
Keywords:
Protocol reverse engineering
program slicing
code embedding
hierarchical clustering

Journal

C
CMC-Computers Materials & Continua
IF:
1.7
Papers:
518
Citations:
0

Organization

No organization information available