Reverse Engineering of Protocols From Network Traces
Communication protocols determine how network components interact with each other. Therefore, the ability to derive a specification of a protocol can be useful in various contexts, such as to support deeper black-box testing or effective defense mechanisms. Unfortunately, it is often hard to obtain the specification because systems implement closed (i.e., undocumented) protocols, or because a time consuming translation has to be performed, from the textual description of the protocol to a format readable by the tools. To address these issues, the authors propose a new methodology to automatically infer a specification of a protocol from network traces, which generates automata for the protocol language and state machine.