BFIS: Efficient Unknown Protocol Feature Extraction Method For Satellite Communication Systems
Published in APSIPA ASC 2025, 2025
With the rapid development of fields such as the Internet and satellite communications, the number of network protocol types has gradually increased, including numerous proprietary or unknown protocols. However, most research has focused on common network protocols, neglecting satellite communication protocols. Given the relatively simple features of captured bitstream data, extracting key bitstream sequences as protocol features is an effective method for satellite protocol feature extraction. Based on the analysis of satellite protocol structures, including DVB compliant with ETSI standards, this paper proposes a feature extraction method utilizing the BFIS algorithm and frequent sequence splicing via the FSS algorithm. This approach dynamically stores subsequence frequencies in a feature-analysis matrix, calculates similarities between different modes, and is employed to extract features of unknown satellite protocols based on DVB. The clustering results are then mapped to actual protocols. Experimental results on both simulated satellite protocol data and the ISCX VPN-nonVPN dataset show that the BFIS algorithm significantly improves accuracy, achieving 97.62% accuracy on DVB datasets and 95.16% accuracy on ISCX VPN-nonVPN dataset, demonstrating its effectiveness in extracting satellite protocol features.
Recommended citation: Xianwen Ling, Kun Zhang∗ and Rong Tong, Dianying Chen http://lingxianwen.github.io/files/paper4.pdf
