Using of NLP Methods to Separate Traffic Packets of Different Protocols

Zalina Rusinova, Yury Chernyshov · 2023

Trace analysis is a protocol reverse engineering technique that aims to determine the behavior of unknown network protocols by examining network messages. One of the possible steps in the trace analysis may be to divide the traffic dump into separate groups in accordance with the protocol stacks of the packets. In this article, we propose an unsupervised learning method in which we use NLP approaches to get package embeddings and then divide them into groups using clustering. This method can be applied to raw packet data and does not require any domain knowledge to extract the relevant features. The results show that the obtained embeddings successfully capture the semantic information underlying the protocols and allow us to divide the traffic dump into clusters containing packets with the same protocol stack. The developed method of grouping network packets makes it possible to increase the efficiency of the network packet analysis process by jointly analyzing packets belonging to the same unknown protocol.

Read the paper · More papers on PaperTik