{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,27]],"date-time":"2026-07-27T17:59:22Z","timestamp":1785175162645,"version":"3.55.0"},"reference-count":47,"publisher":"Elsevier BV","license":[{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-017"},{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"},{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-012"},{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-004"}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["Computer Networks"],"published-print":{"date-parts":[[2026,9]]},"DOI":"10.1016\/j.comnet.2026.112520","type":"journal-article","created":{"date-parts":[[2026,7,13]],"date-time":"2026-07-13T23:38:48Z","timestamp":1783985928000},"page":"112520","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":0,"special_numbering":"C","title":["StruFSM: Byte-level structural modeling for protocol finite state machine inference"],"prefix":"10.1016","volume":"287","author":[{"ORCID":"https:\/\/orcid.org\/0009-0009-9919-4653","authenticated-orcid":false,"given":"Zhen","family":"Wang","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Sen","family":"Zhao","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yuhang","family":"Lu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yimo","family":"Ren","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Zhaoteng","family":"Yan","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0009-3429-1639","authenticated-orcid":false,"given":"Yubo","family":"Li","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Hong","family":"Li","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Hongsong","family":"Zhu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"78","reference":[{"issue":"3","key":"10.1016\/j.comnet.2026.112520_b1","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/2840724","article-title":"A survey of automatic protocol reverse engineering tools","volume":"48","author":"Narayan","year":"2015","journal-title":"ACM Comput. Surv."},{"key":"10.1016\/j.comnet.2026.112520_b2","series-title":"Automatic state machine inference for binary protocol reverse engineering","author":"Yang","year":"2024"},{"key":"10.1016\/j.comnet.2026.112520_b3","doi-asserted-by":"crossref","unstructured":"Tammo Krueger, Hugo Gascon, Nicole Kr\u00e4mer, Konrad Rieck, Learning stateful models for network honeypots, in: Proceedings of the 5th ACM Workshop on Security and Artificial Intelligence, 2012, pp. 37\u201348.","DOI":"10.1145\/2381896.2381904"},{"key":"10.1016\/j.comnet.2026.112520_b4","doi-asserted-by":"crossref","first-page":"238","DOI":"10.1016\/j.comcom.2021.11.009","article-title":"Protocol reverse-engineering methods and tools: A survey","volume":"182","author":"Huang","year":"2022","journal-title":"Comput. Commun."},{"key":"10.1016\/j.comnet.2026.112520_b5","doi-asserted-by":"crossref","first-page":"53","DOI":"10.1007\/s11416-016-0289-8","article-title":"State of the art of network protocol reverse engineering tools","volume":"14","author":"Duch\u00eane","year":"2018","journal-title":"J. Comput. Virol. Hacking Tech."},{"key":"10.1016\/j.comnet.2026.112520_b6","series-title":"2017 IEEE Symposium on Security and Privacy","first-page":"483","article-title":"Verified models and reference implementations for the TLS 1.3 standard candidate","author":"Bhargavan","year":"2017"},{"key":"10.1016\/j.comnet.2026.112520_b7","unstructured":"Paul Fiterau-Brostean, Bengt Jonsson, Robert Merget, Joeri De Ruiter, Konstantinos Sagonas, Juraj Somorovsky, Analysis of {DTLS} implementations using protocol state fuzzing, in: 29th USENIX Security Symposium (USENIX Security 20), 2020, pp. 2523\u20132540."},{"key":"10.1016\/j.comnet.2026.112520_b8","series-title":"BooFuzz: Network protocol fuzzing for humans","author":"jtpereyda","year":"2023"},{"key":"10.1016\/j.comnet.2026.112520_b9","unstructured":"Jinsheng Ba, Marcel B\u00f6hme, Zahra Mirzamomen, Abhik Roychoudhury, Stateful greybox fuzzing, in: 31st USENIX Security Symposium (USENIX Security 22), 2022, pp. 3255\u20133272."},{"issue":"2","key":"10.1016\/j.comnet.2026.112520_b10","doi-asserted-by":"crossref","first-page":"16","DOI":"10.3390\/cryptography4020016","article-title":"Security and performance of single sign-on based on one-time pad algorithm","volume":"4","author":"Kihara","year":"2020","journal-title":"Cryptography"},{"key":"10.1016\/j.comnet.2026.112520_b11","doi-asserted-by":"crossref","DOI":"10.1016\/j.comnet.2023.109797","article-title":"Relational reasoning-based approach for network protocol reverse engineering","volume":"230","author":"Tang","year":"2023","journal-title":"Comput. Netw."},{"key":"10.1016\/j.comnet.2026.112520_b12","doi-asserted-by":"crossref","unstructured":"Juan Caballero, Heng Yin, Zhenkai Liang, Dawn Song, Polyglot: Automatic extraction of protocol message format using dynamic binary analysis, in: Proceedings of the 14th ACM Conference on Computer and Communications Security, 2007, pp. 317\u2013329.","DOI":"10.1145\/1315245.1315286"},{"key":"10.1016\/j.comnet.2026.112520_b13","unstructured":"Chia Yuan Cho, Domagoj Babi\u0107, Pongsin Poosankam, Kevin Zhijie Chen, Edward XueJun Wu, Dawn Song, {MACE}:{Model-inference-Assisted} concolic exploration for protocol and vulnerability discovery, in: 20th USENIX Security Symposium (USENIX Security 11), 2011."},{"key":"10.1016\/j.comnet.2026.112520_b14","series-title":"2009 30th IEEE Symposium on Security and Privacy","first-page":"110","article-title":"Prospex: Protocol specification extraction","author":"Comparetti","year":"2009"},{"issue":"3","key":"10.1016\/j.comnet.2026.112520_b15","doi-asserted-by":"crossref","first-page":"1070","DOI":"10.1016\/j.jnca.2013.01.013","article-title":"Position-based automatic reverse engineering of network protocols","volume":"36","author":"Luo","year":"2013","journal-title":"J. Netw. Comput. Appl."},{"key":"10.1016\/j.comnet.2026.112520_b16","doi-asserted-by":"crossref","DOI":"10.1016\/j.jnca.2020.102819","article-title":"ReFSM: Reverse engineering from protocol packet traces to test generation by extended finite state machines","volume":"171","author":"Lin","year":"2020","journal-title":"J. Netw. Comput. Appl."},{"key":"10.1016\/j.comnet.2026.112520_b17","doi-asserted-by":"crossref","DOI":"10.1016\/j.jnca.2021.103249","article-title":"A progressive learning method on unknown protocol behaviors","volume":"197","author":"Sun","year":"2022","journal-title":"J. Netw. Comput. Appl."},{"key":"10.1016\/j.comnet.2026.112520_b18","doi-asserted-by":"crossref","DOI":"10.1109\/COMST.2025.3545541","article-title":"Unmasking the internet: A survey of fine-grained network traffic analysis","author":"Feng","year":"2025","journal-title":"IEEE Commun. Surv. & Tutorials"},{"key":"10.1016\/j.comnet.2026.112520_b19","doi-asserted-by":"crossref","DOI":"10.1109\/TNET.2024.3468350","article-title":"Crafting binary protocol reversing via deep learning with knowledge-driven augmentation","author":"Zhao","year":"2024","journal-title":"IEEE\/ACM Trans. Netw."},{"key":"10.1016\/j.comnet.2026.112520_b20","series-title":"Wireless Artificial Intelligent Computing Systems and Applications","isbn-type":"print","doi-asserted-by":"crossref","first-page":"119","DOI":"10.1007\/978-981-96-8725-1_10","article-title":"EHFC: Enhanced format clustering via pre-trained traffic model","author":"Wang","year":"2025","ISBN":"https:\/\/id.crossref.org\/isbn\/9789819687251"},{"key":"10.1016\/j.comnet.2026.112520_b21","doi-asserted-by":"crossref","first-page":"113","DOI":"10.1007\/s10044-008-0141-y","article-title":"A survey of graph edit distance","volume":"13","author":"Gao","year":"2010","journal-title":"Pattern Anal. Appl."},{"key":"10.1016\/j.comnet.2026.112520_b22","unstructured":"Stephan Kleber, Henning Kopp, Frank Kargl, {NEMESYS}: Network message syntax reverse engineering by analysis of the intrinsic structure of individual messages, in: 12th USENIX Workshop on Offensive Technologies (WOOT 18), 2018."},{"issue":"7","key":"10.1016\/j.comnet.2026.112520_b23","first-page":"3491","article-title":"ProbMinHash\u2013a class of locality-sensitive hash algorithms for the (probability) Jaccard similarity","volume":"34","author":"Ertl","year":"2020","journal-title":"IEEE Trans. Knowl. Data Eng."},{"key":"10.1016\/j.comnet.2026.112520_b24","series-title":"2016 International Conference on Electrical, Electronics, and Optimization Techniques","first-page":"61","article-title":"Document clustering: TF-IDF approach","author":"Bafna","year":"2016"},{"key":"10.1016\/j.comnet.2026.112520_b25","doi-asserted-by":"crossref","unstructured":"Andrew Trotman, Antti Puurula, Blake Burgess, Improvements to BM25 and language models examined, in: Proceedings of the 19th Australasian Document Computing Symposium, 2014, pp. 58\u201365.","DOI":"10.1145\/2682862.2682863"},{"key":"10.1016\/j.comnet.2026.112520_b26","doi-asserted-by":"crossref","first-page":"82641","DOI":"10.1109\/ACCESS.2020.2991074","article-title":"Network-based bag-of-words model for text classification","volume":"8","author":"Yan","year":"2020","journal-title":"IEEE Access"},{"issue":"1","key":"10.1016\/j.comnet.2026.112520_b27","doi-asserted-by":"crossref","first-page":"155","DOI":"10.1017\/S1351324916000334","article-title":"Word2Vec","volume":"23","author":"Church","year":"2017","journal-title":"Nat. Lang. Eng."},{"key":"10.1016\/j.comnet.2026.112520_b28","series-title":"ACL 2019-57th Annual Meeting of the Association for Computational Linguistics","article-title":"What does BERT learn about the structure of language?","author":"Jawahar","year":"2019"},{"key":"10.1016\/j.comnet.2026.112520_b29","series-title":"Graph attention networks","author":"Veli\u010dkovi\u0107","year":"2017"},{"key":"10.1016\/j.comnet.2026.112520_b30","article-title":"Inductive representation learning on large graphs","volume":"30","author":"Hamilton","year":"2017","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"10.1016\/j.comnet.2026.112520_b31","doi-asserted-by":"crossref","unstructured":"Ziniu Hu, Yuxiao Dong, Kuansan Wang, Yizhou Sun, Heterogeneous graph transformer, in: Proceedings of the Web Conference 2020, WWW\u201920, 2020, pp. 2704\u20132710.","DOI":"10.1145\/3366423.3380027"},{"key":"10.1016\/j.comnet.2026.112520_b32","series-title":"Netresec - Network Forensics","author":"Hjelmvik","year":"2025"},{"issue":"8","key":"10.1016\/j.comnet.2026.112520_b33","doi-asserted-by":"crossref","first-page":"1745","DOI":"10.1109\/TMC.2018.2866249","article-title":"Classifying IoT devices in smart environments using network traffic characteristics","volume":"18","author":"Sivanathan","year":"2018","journal-title":"IEEE Trans. Mob. Comput."},{"key":"10.1016\/j.comnet.2026.112520_b34","series-title":"CAIDA - Center for Applied Internet Data Analysis","year":"2025"},{"key":"10.1016\/j.comnet.2026.112520_b35","series-title":"Iti","year":"2018"},{"key":"10.1016\/j.comnet.2026.112520_b36","first-page":"21002","article-title":"Generalized focal loss: Learning qualified and distributed bounding boxes for dense object detection","volume":"33","author":"Li","year":"2020","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"10.1016\/j.comnet.2026.112520_b37","article-title":"Pytorch: An imperative style, high-performance deep learning library","volume":"32","author":"Paszke","year":"2019","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"10.1016\/j.comnet.2026.112520_b38","doi-asserted-by":"crossref","DOI":"10.1016\/j.comnet.2020.107296","article-title":"Clustering of unknown protocol messages based on format comparison","volume":"179","author":"Sun","year":"2020","journal-title":"Comput. Netw."},{"key":"10.1016\/j.comnet.2026.112520_b39","series-title":"USENIX Security Symposium","first-page":"1","article-title":"Discoverer: Automatic protocol reverse engineering from network traces.","author":"Cui","year":"2007"},{"key":"10.1016\/j.comnet.2026.112520_b40","series-title":"2022 IEEE Symposium on Security and Privacy","first-page":"51","article-title":"Automated attack synthesis by extracting finite state machines from protocol specification documents","author":"Pacheco","year":"2022"},{"key":"10.1016\/j.comnet.2026.112520_b41","series-title":"Inferring state machine from the protocol implementation via large language model","author":"Wei","year":"2024"},{"key":"10.1016\/j.comnet.2026.112520_b42","series-title":"Proceedings of the 17th ACM Conference on Computer and Communications Security","first-page":"426","article-title":"Inference and analysis of formal models of botnet command and control protocols","author":"Cho","year":"2010"},{"key":"10.1016\/j.comnet.2026.112520_b43","doi-asserted-by":"crossref","DOI":"10.1016\/j.jnca.2025.104326","article-title":"Next-generation AI for advanced threat detection and security enhancement in DNS over HTTPS","author":"Ali","year":"2025","journal-title":"J. Netw. Comput. Appl."},{"key":"10.1016\/j.comnet.2026.112520_b44","doi-asserted-by":"crossref","DOI":"10.1016\/j.ins.2026.123430","article-title":"E3-DoH: Enhanced evolutionary encryption for DNS-over-HTTPS, DNS-over-TLS, and DNS-over-QUIC","author":"Ali","year":"2026","journal-title":"Inform. Sci."},{"key":"10.1016\/j.comnet.2026.112520_b45","article-title":"Proactive and privacy-preserving defense for DNS over HTTPS via federated AI attestation (PAFA-doh)","author":"Ali","year":"2025","journal-title":"Neural Netw."},{"issue":"1","key":"10.1016\/j.comnet.2026.112520_b46","doi-asserted-by":"crossref","first-page":"tyaf041","DOI":"10.1093\/cybsec\/tyaf041","article-title":"On the fog\u2019s frontline: a federated machine learning approach for industrial network threat detection and intrusion prevention","volume":"11","author":"Ali","year":"2025","journal-title":"J. Cybersecur."},{"issue":"1","key":"10.1016\/j.comnet.2026.112520_b47","doi-asserted-by":"crossref","first-page":"35","DOI":"10.1186\/s13635-025-00215-5","article-title":"Neuromorphic quantum adversarial learning (NQAL): a bio-inspired paradigm for DNS over HTTPS threat detection","volume":"2025","author":"Ali","year":"2025","journal-title":"EURASIP J. Inf. Secur."}],"container-title":["Computer Networks"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S1389128626005323?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S1389128626005323?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2026,7,27]],"date-time":"2026-07-27T17:00:08Z","timestamp":1785171608000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S1389128626005323"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,9]]},"references-count":47,"alternative-id":["S1389128626005323"],"URL":"https:\/\/doi.org\/10.1016\/j.comnet.2026.112520","relation":{},"ISSN":["1389-1286"],"issn-type":[{"value":"1389-1286","type":"print"}],"subject":[],"published":{"date-parts":[[2026,9]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"StruFSM: Byte-level structural modeling for protocol finite state machine inference","name":"articletitle","label":"Article Title"},{"value":"Computer Networks","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.comnet.2026.112520","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2026 Elsevier B.V. All rights are reserved, including those for text and data mining, AI training, and similar technologies.","name":"copyright","label":"Copyright"}],"article-number":"112520"}}