姚羽(教授)

+

  • 博士生导师  硕士生导师
  • 电子邮箱:
  • 职务:复杂网络系统安全保障技术教育部工程研究中心主任
  • 学历:博士研究生毕业
  • 性别:男
  • 联系方式:yaoyu@mail.neu.edu.cn
  • 学位:博士
  • 毕业院校:东北大学
  • 所属院系:计算机科学与工程学院
  • 学科:
    计算机应用技术
    计算机软件与理论
    计算机系统结构

访问量:

开通时间:..

最后更新时间:..

切换语种:English

手机版
  • 论文成果

InSyfer: Industrial Control Protocols Syntax Inference via Graph Representation Learning

发布时间:2025-08-27  点击次数:

  • 发表刊物:IEEE Transactions on Dependable and Secure Computing
  • 影响因子:7.5
  • 摘要:Industrial control protocols (ICPs) play a significant role in ensuring dependable interconnection among devices in industrial environments. Protocol reverse engineering (PRE) techniques are commonly used to analyze a large number of agnostic and proprietary protocols based on network traffic traces or programs. However, conventional PRE methods face several challenges in reversing ICPs with complex data representations that contain rich structural features. In this work, we present a new perspective on message representation using the graph, and design a syntax inference framework for ICPs reverse analysis (InSyfer). Specifically, we propose a novel method to construct a single message graph for entire traces, automatically extracting syntactical similarity features. We also design an adaptive message clustering model that abstracts the clustering problem into a binary pairwise-classification framework to judge whether pairs of messages belong to the same groups and jointly optimizes it with feature extraction. The above design enables InSyfer to accurately identify message types and greatly improves the correctness of protocol format inference. We conduct extensive experiments to verify the effectiveness of InSyfer. Evaluations of four standard ICPs and two unknown protocols demonstrate that InSyfer outperforms the state-of-the-art PRE methods.
  • 关键字:Industrial control systems, message clustering, protocol reverse engineering, syntax analysis
  • 论文类型:SCI JCR Q1
  • 备注:https://ieeexplore.ieee.org/document/11122642
  • 学科门类:工学
  • 文献类型:JCR 一区
  • 一级学科:计算机科学与技术
  • 是否译文: