Font Size: a A A

Context sensitive and secure parser generation for deep packet inspection of binary protocol

Posted on:2018-01-24Degree:M.SType:Thesis
University:Queen's University (Canada)Candidate:El Shakankiry, AliFull Text:PDF
GTID:2448390005458298Subject:Computer Science
Abstract/Summary:
Network protocol parsers constantly dissect a large number of network data to place into internal data structures for further processing by traffic analysis systems. Many network protocol parsers are hand-written for performance reasons, and lack the security required to run on mission-critical networks. We propose an approach that automatically generates custom protocol parsers to process network traffic to be used as part of an Intrusion Detection System. The user is provided a specification language in which they can define the protocols they need to analyse. This thesis looks at command and control/industrial control networks that are characterized by a limited number of known protocols. We present a robust, secure, and high-performing solution that deals with the issues that have only partially been addressed in this domain.
Keywords/Search Tags:Protocol
Related items