Invention Grant
- Patent Title: Automatic parsing of binary-based application protocols using network traffic
-
Application No.: US15271920Application Date: 2016-09-21
-
Publication No.: US10218598B2Publication Date: 2019-02-26
- Inventor: Ignacio Bermudez , Marios Iliofotou , Marco Mellia , Ram Keralapura , Maurizio Matteo Munafo
- Applicant: Narus, Inc.
- Applicant Address: US CA Sunnyvale
- Assignee: Narus, Inc.
- Current Assignee: Narus, Inc.
- Current Assignee Address: US CA Sunnyvale
- Agency: Kwan & Olynick LLP
- Main IPC: H04L12/26
- IPC: H04L12/26 ; G06F17/30 ; G06N99/00 ; G06F8/53 ; H04L12/24 ; H04L29/06 ; H04L12/58

Abstract:
A method for analyzing a binary-based application protocol of a network. The method includes obtaining conversations from the network, extracting content of a candidate field from a message in each conversation, calculating a randomness measure of the content to represent a level of randomness of the content across all conversation, calculating a correlation measure of the content to represent a level of correlation, across all of conversations, between the content and an attribute of a corresponding conversation where the message containing the candidate field is located, and selecting, based on the randomness measure and the correlation measure, and using a pre-determined field selection criterion, the candidate offset from a set of candidate offsets as the offset defined by the protocol.
Public/Granted literature
- US20170012853A1 AUTOMATIC PARSING OF BINARY-BASED APPLICATION PROTOCOLS USING NETWORK TRAFFIC Public/Granted day:2017-01-12
Information query