Research and Development of Wireless Protocol Automatic Analyzer 


Vol. 46,  No. 8, pp. 852-860, Aug.  2019
10.5626/JOK.2019.46.8.852


PDF

  Abstract

Automatic Protocol Reverse Engineering (APRE) defines automatic analysis of the format, semantics, and parameters of an unknown protocol. APRE can be used to detect malware that is distributed on the network, or for security and suitability verification of protocols that have been defined own their own. Conventional APRE studies have been conducted mostly on text-based protocols and wired protocols. As the number of wireless devices increases, there is an increasing need for a protocol analyzer for wireless protocols. Therefore, in this paper, research and development of the protocol automatic analyzer were performed by considering the characteristics of the wireless protocols. For the analysis of the wireless protocol, this study analyzed the messages in binary units. We propose a method to calculate the message distance by assigning a weight according to the packet acquisition time interval to perform clustering among similar messages. As a result of collecting and analyzing the messages according to the IEEE 802.11 protocol using the proposed method, we could correctly classify 95.1% message types among 800messages, and the degree of conciseness was 3.6. By using one of the existing APRE tools, Netzob, 92.1% precision was obtained with the conciseness of 3.5. Consequently, the proposed method showed better performance than Netzob.


  Statistics
Cumulative Counts from November, 2022
Multiple requests among the same browser session are counted as one view. If you mouse over a chart, the values of data points will be shown.


  Cite this article

[IEEE Style]

W. Bang, Y. Jeon, S. Shim, K. Kim, J. W. Yoon, "Research and Development of Wireless Protocol Automatic Analyzer," Journal of KIISE, JOK, vol. 46, no. 8, pp. 852-860, 2019. DOI: 10.5626/JOK.2019.46.8.852.


[ACM Style]

Woorim Bang, Youngbae Jeon, Shinwoo Shim, Kwangsoo Kim, and Ji Won Yoon. 2019. Research and Development of Wireless Protocol Automatic Analyzer. Journal of KIISE, JOK, 46, 8, (2019), 852-860. DOI: 10.5626/JOK.2019.46.8.852.


[KCI Style]

방우림, 전영배, 심신우, 김광수, 윤지원, "무선 프로토콜 자동 분석기 연구 및 개발," 한국정보과학회 논문지, 제46권, 제8호, 852~860쪽, 2019. DOI: 10.5626/JOK.2019.46.8.852.


[Endnote/Zotero/Mendeley (RIS)]  Download


[BibTeX]  Download



Search




Journal of KIISE

  • ISSN : 2383-630X(Print)
  • ISSN : 2383-6296(Electronic)
  • KCI Accredited Journal

Editorial Office

  • Tel. +82-2-588-9240
  • Fax. +82-2-521-1352
  • E-mail. chwoo@kiise.or.kr