Professor
Supervisor of Doctorate Candidates
Supervisor of Master's Candidates
Academic Honor
2013 Excellent talents of the Ministry of education in the new century
Open Time: ..
The Last Update Time: ..
Hits:
Journal:IEEE Transactions on Network and Service Management
Summary:Protocol Format Inference is a pivotal step in the reverse engineering of proprietary protocols, yet its effectiveness is constrained by the scarcity of high-quality training data. In industrial control systems, the rigid and cyclical nature of traffic results in a “long-tail” distribution, where diverse functional scenarios are severely underrepresented. Existing generative approaches, primarily designed for fuzzing or intrusion detection, fail to resolve the intrinsic conflict between syntactic validity and semantic diversity required for protocol format inference. To bridge this gap, we propose FIGAN, a stage-wise decoupled generative framework tailored to synthesize high-fidelity traffic for protocol format inference. By isolating flexible distribution learning from rigid syntax enforcement, FIGAN liberates the generative process to extrapolate novel payload variations from a continuous latent space, effectively surmounting the limitations of sparse seed data. Specifically, the framework integrates three synergistic modules: first, heuristic pre-processing that constructs semantic templates as a prior knowledge base; second, a generative adversarial architecture optimized via discrete relaxation to explore high-dimensional payload patterns independently of syntax rules; and finally, a closed-loop verification mechanism that performs syntactic calibration and functional validation against simulated device responses. Evaluations on four real-world protocols (Modbus TCP, S7Comm, Omron FINS, and DNP3) demonstrate that FIGAN significantly outperforms state-of-the-art baselines.
Key Words:Communication system traffic, data augmentation ,generative adversarial networks, industrial control, inference algorithms
Indexed by:SCI JCR Q2
Note:https://xplorestaging.ieee.org/document/11626179
Discipline:Engineering
Document Type:JCR 一区
First-Level Discipline:Computer Science and Technology
Translation or Not:No