Abstract

Protocol reverse engineering is essential to information security of industrial control systems. In this paper, we propose a V-gram method, which takes variable gram as input of XGBoost. In view of the periodic and structurally fixed characteristics of industrial control protocol, progressive multi-sequence alignment algorithm is used to cluster initial message samples for traffic with the same payload length. V-gram is generated after the variable domain and fixed domain of message sequences are separated, and feature words are extracted by XGBoost model. The states of data packets are classified and tagged with XGBoost, so as to realize the construction of FSM model. Experimental results show that the proposed approach is effective in mining junior semantic information for industrial control protocols.

Full Text
Paper version not known

Talk to us

Join us for a 30 min session where you can share your feedback and ask us any queries you have

Schedule a call

Disclaimer: All third-party content on this website/platform is and will remain the property of their respective owners and is provided on "as is" basis without any warranties, express or implied. Use of third-party content does not indicate any affiliation, sponsorship with or endorsement by them. Any references to third-party content is to identify the corresponding services and shall be considered fair use under The CopyrightLaw.