中文版 | English
题名

Industrial Control Protocol Type Inference Using Transformer and Rule-based Re-Clustering

作者
DOI
发表日期
2024-05-23
ISSN
0743-166X
ISBN
979-8-3503-8351-5
会议录名称
会议日期
20-23 May 2024
会议地点
Vancouver, BC, Canada
摘要
The development of the Industrial Internet of Things (IIoT) is impeded by the lack of unknown protocol specifications. Protocol Reverse Engineering (PRE) plays a crucial role in inferring unpublished protocol specifications by analyzing traffic messages. Since different types within a protocol often have distinct formats, inferring the protocol type is essential for subsequent reverse analysis. Natural Language Processing (NLP) models have demonstrated remarkable capabilities in various sequence tasks, and traffic messages of unknown protocols can be analyzed as sequences. In this paper, we propose a framework for clustering unknown industrial control protocol types. Our framework utilizes a transformer-based auto-encoder network to train corresponding request and response messages, leveraging intermediate layer embedding vectors learned by the network for clustering. The clustering results are employed to extract candidate keywords and establish empirical rules. Subsequently, rule-based re-clustering is performed, and its effectiveness is evaluated based on previous clustering results. Through this re-clustering process, we identify the most effective combination of keywords that define the type. We evaluate the proposed framework using three general protocols that have different type rules and successfully separate the protocol internal types completely.
学校署名
其他
相关链接[IEEE记录]
收录类别
引用统计
成果类型会议论文
条目标识符http://sustech.caswiz.com/handle/2SGJ60CL/803315
专题工学院_计算机科学与工程系
作者单位
1.Department of Computing, The Hong Kong Polytechnic University
2.Department of Computer Science and Engineering, Southern University of Science and Technology
3.Shenzhen Key Laboratory of Safety and Security for Next Generation of Industrial Internet
4.College of Information Science and Engineering, China University of Petroleum-Beijing
5.Department of Computer Science, University of Reading
第一作者单位计算机科学与工程系
推荐引用方式
GB/T 7714
Yuhuan Liu,Yulong Ding,Jie Jiang,et al. Industrial Control Protocol Type Inference Using Transformer and Rule-based Re-Clustering[C],2024.
条目包含的文件
条目无相关文件。
个性服务
原文链接
推荐该条目
保存到收藏夹
查看访问统计
导出为Endnote文件
导出为Excel格式
导出为Csv格式
Altmetrics Score
谷歌学术
谷歌学术中相似的文章
[Yuhuan Liu]的文章
[Yulong Ding]的文章
[Jie Jiang]的文章
百度学术
百度学术中相似的文章
[Yuhuan Liu]的文章
[Yulong Ding]的文章
[Jie Jiang]的文章
必应学术
必应学术中相似的文章
[Yuhuan Liu]的文章
[Yulong Ding]的文章
[Jie Jiang]的文章
相关权益政策
暂无数据
收藏/分享
所有评论 (0)
[发表评论/异议/意见]
暂无评论

除非特别说明,本系统中所有内容都受版权保护,并保留所有权利。