The article describes a method for restoring the structure of network traffic with zero prior knowledge. The importance of the problem being solved is explained (government authorities requirements and recent incidents in the field of information security). A brief description of the existing approaches is given. The general architecture of the proposed method based on the previous research of the authors is described [5]. Incoming packets are divided into groups according to the format of the transmitted data, for each group a prediction is made of the presence of a field boundary for each offset inside the packet. Groups of packets with a prediction confidence value less than the specified one are processed by a method working with variable-length fields using the ideas of genetic algorithms: mutations are selected iteratively for a set of proposed boundaries, a quality metric is calculated for each mutation, the best mutations are transferred to the next step.
Original languageEnglish
Title of host publicationProceedings - 2023 IEEE Ural-Siberian Conference on Biomedical Engineering, Radioelectronics and Information Technology, USBEREIT 2023
Subtitle of host publicationbook
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages324-327
Number of pages4
ISBN (Electronic)979-835033605-4
DOIs
Publication statusPublished - 15 May 2023
Event2023 IEEE Ural-Siberian Conference on Biomedical Engineering, Radioelectronics and Information Technology (USBEREIT) - Yekaterinburg, Russian Federation
Duration: 15 May 202317 May 2023

Conference

Conference2023 IEEE Ural-Siberian Conference on Biomedical Engineering, Radioelectronics and Information Technology (USBEREIT)
Period15/05/202317/05/2023

ID: 41989256