Qr code
中文
姚羽

Professor
Supervisor of Doctorate Candidates
Supervisor of Master's Candidates


Gender:Male
Alma Mater:东北大学
Education Level:With Certificate of Graduation for Doctorate Study
School/Department:计算机科学与工程学院
College: 计算机科学与工程学院
Administrative Position:复杂网络系统安全保障技术教育部工程研究中心主任
Discipline:Computer Applications Technology
Computer Software and Theory
Computer Architecture
Contact Information:

Academic Honor

2013   Excellent talents of the Ministry of education in the new century

Click:Times

Open Time: ..

The Last Update Time: ..

Current position: Home >> Scientific Research >> Paper Publications
FIGAN: Diversity-Oriented Traffic Generation for Industrial Protocol Format Inference

Hits:

Journal:IEEE Transactions on Network and Service Management

Summary:Protocol Format Inference is a pivotal step in the reverse engineering of proprietary protocols, yet its effectiveness is constrained by the scarcity of high-quality training data. In industrial control systems, the rigid and cyclical nature of traffic results in a “long-tail” distribution, where diverse functional scenarios are severely underrepresented. Existing generative approaches, primarily designed for fuzzing or intrusion detection, fail to resolve the intrinsic conflict between syntactic validity and semantic diversity required for protocol format inference. To bridge this gap, we propose FIGAN, a stage-wise decoupled generative framework tailored to synthesize high-fidelity traffic for protocol format inference. By isolating flexible distribution learning from rigid syntax enforcement, FIGAN liberates the generative process to extrapolate novel payload variations from a continuous latent space, effectively surmounting the limitations of sparse seed data. Specifically, the framework integrates three synergistic modules: first, heuristic pre-processing that constructs semantic templates as a prior knowledge base; second, a generative adversarial architecture optimized via discrete relaxation to explore high-dimensional payload patterns independently of syntax rules; and finally, a closed-loop verification mechanism that performs syntactic calibration and functional validation against simulated device responses. Evaluations on four real-world protocols (Modbus TCP, S7Comm, Omron FINS, and DNP3) demonstrate that FIGAN significantly outperforms state-of-the-art baselines.

Key Words:Communication system traffic, data augmentation ,generative adversarial networks, industrial control, inference algorithms

Indexed by:SCI JCR Q2

Note:https://xplorestaging.ieee.org/document/11626179

Discipline:Engineering

Document Type:JCR 一区

First-Level Discipline:Computer Science and Technology

Translation or Not:No