{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,6]],"date-time":"2026-08-06T17:58:24Z","timestamp":1786039104088,"version":"3.56.0"},"reference-count":51,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2017,1,25]],"date-time":"2017-01-25T00:00:00Z","timestamp":1485302400000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["J Comput Virol Hack Tech"],"published-print":{"date-parts":[[2018,2]]},"DOI":"10.1007\/s11416-016-0289-8","type":"journal-article","created":{"date-parts":[[2017,1,25]],"date-time":"2017-01-25T07:28:06Z","timestamp":1485329286000},"page":"53-68","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":58,"title":["State of the art of network protocol reverse engineering tools"],"prefix":"10.1007","volume":"14","author":[{"given":"Julien","family":"Duch\u00eane","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Colas","family":"Le Guernic","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Eric","family":"Alata","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Vincent","family":"Nicomette","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Mohamed","family":"Ka\u00e2niche","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2017,1,25]]},"reference":[{"issue":"2","key":"289_CR1","doi-asserted-by":"publisher","first-page":"87","DOI":"10.1016\/0890-5401(87)90052-6","volume":"75","author":"D Angluin","year":"1987","unstructured":"Angluin, D.: Learning regular sets from queries and counterexamples. Inf. Comput. 75(2), 87\u2013106 (1987). doi:\n                        10.1016\/0890-5401(87)90052-6","journal-title":"Inf. Comput."},{"key":"289_CR2","doi-asserted-by":"publisher","unstructured":"Antunes, J., Neves, N., Verissimo, P.: Reverse engineering of protocols from network traces. In: 2011 18th Working Conference on Reverse Engineering (WCRE), pp. 169\u2013178. IEEE, New York, NY (2011). doi:\n                        10.1109\/WCRE.2011.28","DOI":"10.1109\/WCRE.2011.28"},{"key":"289_CR3","unstructured":"Beddoe, M.: Network Protocol Analysis using Bioinformatics Algorithms. (2004). \n                        http:\/\/www.4tphi.net\/~awalters\/PI\/pi.pdf"},{"key":"289_CR4","unstructured":"Beddoe, M.: Protocol Informatics Project. (2004). \n                        http:\/\/www.4tphi.net\/~awalters\/PI\/PI.html"},{"key":"289_CR5","unstructured":"Bohlin, T., Jonsson, B.: Regular Inference for Communication Protocol Entities. Technical Report 2008-024, Department of Information Technology, Uppsala University, Uppsala University, Sweden (2008)"},{"key":"289_CR6","unstructured":"Bossert, G.: Exploiting Semantic for the Automatic Reverse Engineering of Communication Protocols. PhD thesis, Supelec (2014)"},{"key":"289_CR7","doi-asserted-by":"publisher","unstructured":"Bossert, G., Guihery, F., Hiet, G.: Towards automated protocol reverse engineering using semantic information. In: Proceedings of the 9th ACM Symposium on Information, Computer and Communications Security, pp. 51\u201362. ACM, Kyoto (2014). doi:\n                        10.1145\/2590296.2590346","DOI":"10.1145\/2590296.2590346"},{"key":"289_CR8","doi-asserted-by":"publisher","unstructured":"Bossert, G., Hiet, G., Henin, T.: Modelling to simulate botnet command and control protocols for the evaluation of network intrusion detection systems. In: 2011 Conference on Network and Information Systems Security (SAR-SSI), pp. 1\u20138. IEEE, La Rochelle (2011). doi:\n                        10.1109\/SAR-SSI.2011.5931397","DOI":"10.1109\/SAR-SSI.2011.5931397"},{"key":"289_CR9","unstructured":"Caballero, J., Grieco, G., Marron, M., Lin, Z., Urbina, D.: ARTISTE: Automatic Generation of Hybrid Data Structure Signatures from Binary Code Executions. Technical Report TR-IMDEA-SW-2012-001, IMDEA Software Institute, Madrid (2012)"},{"key":"289_CR10","doi-asserted-by":"publisher","unstructured":"Caballero, J., Poosankam, P., Kreibich, C., Song, D.: Dispatcher: enabling active botnet infiltration using automatic protocol reverse-engineering. In: Proceedings of the 16th ACM Conference on Computer and Communications Security, CCS \u201909, pp. 621\u2013634. ACM, New York, NY (2009). doi:\n                        10.1145\/1653662.1653737","DOI":"10.1145\/1653662.1653737"},{"key":"289_CR11","unstructured":"Caballero, J., Song, D.: Rosetta: Extracting Protocol Semantics Using Binary Analysis with Applications to Protocol Replay and NAT Rewriting. Technical Report CMU-CyLab-07-014, Carnegie Mellon University, Pittsburgh (2007)"},{"issue":"2","key":"289_CR12","doi-asserted-by":"publisher","first-page":"451","DOI":"10.1016\/j.comnet.2012.08.003","volume":"57","author":"J Caballero","year":"2013","unstructured":"Caballero, J., Song, D.: Automatic protocol reverse-engineering: message format extraction and field semantics inference. Comput. Netw. 57(2), 451\u2013474 (2013). doi:\n                        10.1016\/j.comnet.2012.08.003","journal-title":"Comput. Netw."},{"key":"289_CR13","doi-asserted-by":"publisher","unstructured":"Caballero, J., Yin, H., Liang, Z., Song, D.: Polyglot: automatic extraction of protocol message format using dynamic binary analysis. In: Proceedings of the 14th ACM Conference on Computer and Communications Security, CCS \u201907, pp. 317\u2013329. ACM, New York, NY (2007). doi:\n                        10.1145\/1315245.1315286","DOI":"10.1145\/1315245.1315286"},{"key":"289_CR14","unstructured":"Caballero\u00a0Bayerri, J.: Grammar and Model Extraction for Security Applications Using Dynamic Program Binary Analysis. Ph.D. thesis, Carnegie Mellon University, Pittsburgh, PA (2010)"},{"key":"289_CR15","unstructured":"Campana, G.: Fuzzgrind: un outil de fuzzing automatique. In: Symposium sur la Scurit des Technologies de l\u2019Information et de la Communication, SSTIC. SSTIC, Rennes (2009)"},{"key":"289_CR16","unstructured":"Campana, G.: Fuzzgrind: an automatic fuzzing tool. In: Hack. lu. Hack. lu, Luxembourg (2009)"},{"key":"289_CR17","doi-asserted-by":"publisher","unstructured":"Cho, C.Y., Babi D., Shin, E.C.R., Song, D.: Inference and analysis of formal models of botnet command and control protocols. In: Proceedings of the 17th ACM Conference on Computer and Communications Security, CCS \u201910, pp. 426\u2013439. ACM, New York, NY (2010). doi:\n                        10.1145\/1866307.1866355","DOI":"10.1145\/1866307.1866355"},{"key":"289_CR18","unstructured":"Cho, C.Y., Babi, D., Poosankam, P., Chen, K.Z., Wu, E.X., Song, D.: MACE: model-inference-assisted concolic exploration for protocol and vulnerability discovery. In: Proceedings of the 20th USENIX Conference on Security, SEC\u201911, p.\u00a019. USENIX Association, Berkeley, CA (2011)"},{"key":"289_CR19","unstructured":"Chow, J.: Understanding Data Lifetime. Ph.D. thesis, Stanford University, Stanford, CA (2006)"},{"key":"289_CR20","doi-asserted-by":"publisher","unstructured":"Comparetti, P., Wondracek, G., Kruegel, C., Kirda, E.: Prospex: protocol specification extraction. In: 2009 30th IEEE Symposium on Security and Privacy, pp. 110\u2013125. IEEE, Berkeley (2009). doi:\n                        10.1109\/SP.2009.14","DOI":"10.1109\/SP.2009.14"},{"key":"289_CR21","unstructured":"Cui, W., Kannan, J., Wang, H.J.: Discoverer: automatic protocol reverse engineering from network traces. In: Proceedings of 16th USENIX Security Symposium on USENIX Security Symposium, SS\u201907, pp. 14:1\u201314:14. USENIX Association, Berkeley, CA (2007)"},{"key":"289_CR22","unstructured":"Cui, W., Paxson, V., Weaver, N., Katz, R.H.: Protocol-independent adaptive replay of application dialog. In: Proceedings of the 13th Annual Network and Distributed System Security Symposium (NDSS). Internet Society, San Diego (2006). \n                        http:\/\/research.microsoft.com\/apps\/pubs\/default.aspx?id=153197"},{"key":"289_CR23","doi-asserted-by":"publisher","unstructured":"Cui, W., Peinado, M., Chen, K., Wang, H.J., Irun-Briz, L.: Tupni: automatic reverse engineering of input formats. In: Proceedings of the 15th ACM Conference on Computer and Communications Security, CCS \u201908, pp. 391\u2013402. ACM, New York, NY (2008). doi:\n                        10.1145\/1455770.1455820","DOI":"10.1145\/1455770.1455820"},{"key":"289_CR24","doi-asserted-by":"publisher","unstructured":"Cui, W., Peinado, M., Wang, H., Locasto, M.: ShieldGen: automatic data patch generation for unknown vulnerabilities with informed probing. In: IEEE Symposium on Security and Privacy, 2007. SP \u201907, pp. 252\u2013266. IEEE, Oakland (2007). doi:\n                        10.1109\/SP.2007.34","DOI":"10.1109\/SP.2007.34"},{"key":"289_CR25","unstructured":"Guihery, F., Bossert, G.: The future of protocol reversing and simulation applied on ZeroAccess. In: 29C3: 29th Chaos Communication Congress \u201912. C-3, Hambourg (2012)"},{"key":"289_CR26","unstructured":"Guihery, F., Bossert, G.: Netzob: un outil pour la rtro-conception de protocoles de communication. In: Symposium sur la Scurit des Technologies de l\u2019Information et de la Communication, SSTIC. SSTIC, Rennes (2012)"},{"key":"289_CR27","doi-asserted-by":"crossref","DOI":"10.1017\/CBO9781139194655","volume-title":"Grammatical Inference: Learning Automata and Grammars","author":"C Higuera de la","year":"2010","unstructured":"de la Higuera, C.: Grammatical Inference: Learning Automata and Grammars. Cambridge University Press, New York, NY (2010)"},{"key":"289_CR28","doi-asserted-by":"publisher","unstructured":"Krueger, T., Gascon, H., Krmer, N., Rieck, K.: Learning stateful models for network honeypots. In: Proceedings of the 5th ACM Workshop on Security and Artificial Intelligence, AISec \u201912, pp. 37\u201348. ACM, New York, NY (2012). doi:\n                        10.1145\/2381896.2381904","DOI":"10.1145\/2381896.2381904"},{"key":"289_CR29","doi-asserted-by":"publisher","unstructured":"Krueger, T., Krmer, N., Rieck, K.: ASAP: automatic semantics-aware analysis of network payloads. In: Dimitrakakis, C., Gkoulalas-Divanis, A., Mitrokotsa, A., Verykios, V.S., Saygin, Y. (eds.) Privacy and Security Issues in Data Mining and Machine Learning, No. 6549 in Lecture Notes in Computer Science, pp. 50\u201363. Springer, Berlin (2010). doi:\n                        10.1007\/978-3-642-19896-0_5","DOI":"10.1007\/978-3-642-19896-0_5"},{"key":"289_CR30","unstructured":"Leita, C.: SGNET: Automated Protocol Learning for the Observation of Malicious Threats. Ph.D. thesis, Universit de Nice (2008). \n                        http:\/\/www.eurecom.fr\/publication\/2709"},{"key":"289_CR31","doi-asserted-by":"publisher","unstructured":"Leita, C., Mermoud, K., Dacier, M.: ScriptGen: an automated script generation tool for Honeyd. In: Computer Security Applications Conference, 21st Annual, pp. 12\u2013214. IEEE, Tucson (2005). doi:\n                        10.1109\/CSAC.2005.49","DOI":"10.1109\/CSAC.2005.49"},{"key":"289_CR32","doi-asserted-by":"publisher","unstructured":"Li, X., Chen, L.: A survey on methods of automatic protocol reverse engineering. In: 2011 Seventh International Conference on Computational Intelligence and Security (CIS), pp. 685\u2013689. IEEE, Hainan (2011). doi:\n                        10.1109\/CIS.2011.156","DOI":"10.1109\/CIS.2011.156"},{"key":"289_CR33","doi-asserted-by":"publisher","unstructured":"Lim, J., Reps, T., Liblit, B.: Extracting output formats from executables. In: 13th Working Conference on Reverse Engineering, 2006. WCRE \u201906, pp. 167\u2013178. IEEE, Benevento (2006). doi:\n                        10.1109\/WCRE.2006.29","DOI":"10.1109\/WCRE.2006.29"},{"key":"289_CR34","unstructured":"Lin, Z.: Reverse Engineering of Data Structures from Binary. Ph.D. thesis, Purdue University, West Lafayette, IA (2011)"},{"key":"289_CR35","unstructured":"Lin, Z., Jiang, X., Xu, D., Zhang, X.: Automatic protocol format reverse engineering through context-aware monitored execution. In: Proceedings of the 15th Annual Network and Distributed System Security Symposium (NDSS). Internet Society, San Diego (2008)"},{"key":"289_CR36","unstructured":"Lin, Z., Zhang, X., Xu, D.: Automatic reverse engineering of data structures from binary execution. In: Proceedings of the 17th Annual Network and Distributed System Security Symposium (NDSS). Internet Society, San Diego (2010)"},{"issue":"3","key":"289_CR37","doi-asserted-by":"crossref","first-page":"40","DOI":"10.1145\/2840724","volume":"48","author":"J Narayan","year":"2015","unstructured":"Narayan, J., Shukla, S.K., Clancy, T.C.: A survey of automatic protocol reverse engineering tools. ACM Comput. Surv. (CSUR) 48(3), 40 (2015)","journal-title":"ACM Comput. Surv. (CSUR)"},{"issue":"3","key":"289_CR38","doi-asserted-by":"publisher","first-page":"443","DOI":"10.1016\/0022-2836(70)90057-4","volume":"48","author":"SB Needleman","year":"1970","unstructured":"Needleman, S.B., Wunsch, C.D.: A general method applicable to the search for similarities in the amino acid sequence of two proteins. J. Mol. Biol. 48(3), 443\u2013453 (1970). doi:\n                        10.1016\/0022-2836(70)90057-4","journal-title":"J. Mol. Biol."},{"issue":"2","key":"289_CR39","doi-asserted-by":"crossref","first-page":"153","DOI":"10.1007\/BF02300753","volume":"19","author":"M Nei","year":"1983","unstructured":"Nei, M., Tajima, F., Tateno, Y.: Accuracy of estimated phylogenetic trees from molecular data. J. Mol. Evol. 19(2), 153\u2013170 (1983)","journal-title":"J. Mol. Evol."},{"key":"289_CR40","doi-asserted-by":"publisher","unstructured":"Nethercote, N., Seward, J.: Valgrind: a framework for heavyweight dynamic binary instrumentation. In: Ferrante, J., McKinley, K.S. (eds.) Proceedings of the ACM SIGPLAN 2007 Conference on Programming Language Design and Implementation, San Diego, CA, June 10\u201313, 2007, pp. 89\u2013100. ACM (2007). doi:\n                        10.1145\/1250734.1250746","DOI":"10.1145\/1250734.1250746"},{"key":"289_CR41","doi-asserted-by":"publisher","unstructured":"Newsome, J., Brumley, D., Franklin, J., Song, D.: Replayer: automatic protocol replay by binary analysis. In: Proceedings of the 13th ACM Conference on Computer and Communications Security, CCS \u201906, pp. 311\u2013321. ACM, New York, NY (2006). doi:\n                        10.1145\/1180405.1180444","DOI":"10.1145\/1180405.1180444"},{"key":"289_CR42","unstructured":"Samba Team: Opening Windows to a Wider World. \n                        http:\/\/www.samba.org"},{"key":"289_CR43","unstructured":"Slowinska, A., Stancescu, T., Bos, H.: Dynamic Data Structure Excavation. Technical Report IR-CS-55, Vrije Universiteit Amsterdam, Amsterdam (2010)"},{"key":"289_CR44","unstructured":"Slowinska, A., Stancescu, T., Bos, H.: Howard: a dynamic excavator for reverse engineering data structures. In: Proceedings of the 18th Annual Network and Distributed System Security Symposium (NDSS). Internet Society, San Diego (2011)"},{"key":"289_CR45","doi-asserted-by":"publisher","unstructured":"Wang, R., Wang, X., Zhang, K., Li, Z.: Towards automatic reverse engineering of software security configurations. In: Proceedings of the 15th ACM Conference on Computer and Communications Security, CCS \u201908, pp. 245\u2013256. ACM, Limerick (2008). doi:\n                        10.1145\/1455770.1455802","DOI":"10.1145\/1455770.1455802"},{"key":"289_CR46","doi-asserted-by":"publisher","unstructured":"Wang, Y., Zhang, Z., Guo, L.: Inferring protocol state machine from real-world trace. In: S.\u00a0Jha, R.\u00a0Sommer, C.\u00a0Kreibich (eds.) Recent Advances in Intrusion Detection, No. 6307 in Lecture Notes in Computer Science, pp. 498\u2013499. Springer, Berlin (2010). doi:\n                        10.1007\/978-3-642-15512-3_32","DOI":"10.1007\/978-3-642-15512-3_32"},{"key":"289_CR47","doi-asserted-by":"crossref","unstructured":"Wang, Y., Zhang, Z., Yao, D.D., Qu, B., Guo, L.: Inferring protocol state machine from network traces: a probabilistic approach. In: Lopez, J., Tsudik, G. (eds.) Applied Cryptography and Network Security, No. 6715 in Lecture Notes in Computer Science, pp. 1\u201318. Springer, Berlin (2011)","DOI":"10.1007\/978-3-642-21554-4_1"},{"key":"289_CR48","doi-asserted-by":"crossref","unstructured":"Wang, Z., Jiang, X., Cui, W., Wang, X., Grace, M.: ReFormat: automatic reverse engineering of encrypted messages. In: Backes, M., Ning, P. (eds.) Computer Security ESORICS 2009, No. 5789 in Lecture Notes in Computer Science, pp. 200\u2013215. Springer, Berlin (2009)","DOI":"10.1007\/978-3-642-04444-1_13"},{"key":"289_CR49","unstructured":"Wondracek, G., Comparetti, P.M., Kr\u00fcgel, C., Kirda, E.: Automatic network protocol analysis. In: Proceedings of the 15th Annual Network and Distributed System Security Symposium (NDSS). Internet Society, San Diego (2008). \n                        http:\/\/www.isoc.org\/isoc\/conferences\/ndss\/08\/papers\/13_automatic_network_protocol.pdf"},{"key":"289_CR50","unstructured":"Zalewski, M.: American Fuzzy Loop. \n                        http:\/\/lcamtuf.coredump.cx\/afl\/technical_details.txt"},{"key":"289_CR51","doi-asserted-by":"publisher","unstructured":"Zeng, J., Lin, Z.: Towards automatic inference of kernel object semantics from binary code. In: 18th International Symposium, RAID 2015, vol. 9404, pp. 538\u2013561. Springer, Kyoto (2015). doi:\n                        10.1007\/978-3-319-26362-5","DOI":"10.1007\/978-3-319-26362-5"}],"container-title":["Journal of Computer Virology and Hacking Techniques"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s11416-016-0289-8\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s11416-016-0289-8.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s11416-016-0289-8.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2018,2,23]],"date-time":"2018-02-23T04:46:55Z","timestamp":1519361215000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s11416-016-0289-8"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2017,1,25]]},"references-count":51,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2018,2]]}},"alternative-id":["289"],"URL":"https:\/\/doi.org\/10.1007\/s11416-016-0289-8","relation":{},"ISSN":["2263-8733"],"issn-type":[{"value":"2263-8733","type":"electronic"}],"subject":[],"published":{"date-parts":[[2017,1,25]]}}}