Automatic Discovery of Protocol Signatures

LU Lin,LUO Jun-yong,LIU Yan,LI Ming-tao
DOI: https://doi.org/10.3969/j.issn.1671-0673.2012.05.018
2012-01-01
Abstract:The frequent combination of some bytes on fixed positions in data packets is an important kind of signature for application-layer protocol identification.The classic Apriori algorithm in data mining has good signature accuracy and coverage,but also has inherent defects such as large-scale candidate item sets and repeated database scanning.This paper improves the Apriori algorithm based on deep packets inspection.The improved algorithm can automatically look for frequent patterns which might be a combination of byte values and character types.The experiments show that the signatures generated by the new method are good for protocols recognition and this method can adapt to protocol version updating,and perform well in discovering features of unknown protocols.
What problem does this paper attempt to address?