Custom protocol parsing method and system based on xml configuration file
Through a custom protocol parsing method based on xml configuration files, a global hash table is generated and a custom protocol is parsed using the identification module, which solves the problem of slow resolution of custom protocols in the existing technology, and achieves fast and accurate protocol parsing and code maintenance.
Patent Information
- Application Number
- CN202211667388.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-23
- Publication Date
- 2025-07-01
- Estimated Expiration
- 2042-12-23
AI Technical Summary
The prior art lacks the configuration and parsing methods for automated and rapid processing of custom protocols, especially for custom protocols that are not within the scope of common protocols.
Using a custom protocol resolution method based on xml configuration files, a global hash table is generated by scanning the xml configuration files in the network security device directory, a field attribute is extracted, and a recognition module is used to obtain protocol names and field values to achieve rapid resolution of the custom protocol.
It realizes rapid parsing of custom protocols, improves analysis speed and data accuracy, is conducive to code development and maintenance, and simplifies the framework consistency of custom protocols.
Smart Images

Figure CN115988107B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of network and infrastructure security technologies, and particularly to a method and system for custom protocol parsing based on an xml configuration file. Background Art
[0002] In network communication, the transfer of information requires an agreed-upon transfer method. Different scenarios require different agreements. Although there are currently many protocols to solve data transmission problems in various scenarios, everyone's needs are different, and it is impossible to meet everyone's needs with the same rule. Currently, the contradiction between the growing need for network transmission and the backward reality is gradually increasing. Facing different scenarios and different needs, the need for custom protocols is flexible and necessary.
[0003] Currently, there is no automated and rapid processing method for the configuration and protocol parsing of custom protocols that have a fixed message format but are not within the scope of common protocols. Summary of the Invention
[0004] In view of this, embodiments of the present disclosure provide a method and system for custom protocol parsing based on an xml configuration file, and a new custom protocol parsing method is disclosed, which has a fast parsing speed, high data accuracy rate, and is beneficial to the development and maintenance of code.
[0005] In a first aspect, embodiments of the present disclosure provide a method for custom protocol parsing based on an xml configuration file, the method comprising:
[0006] Scanning an xml configuration file in a specific directory of a network security device, extracting multiple field attributes of the xml configuration file, and generating multiple nodes;
[0007] Based on the multiple nodes, constructing a global hash table;
[0008] The key value of the global hash table is the protocol name;
[0009] Extracting the protocol number of an input data packet, and obtaining the corresponding protocol name through an identification module;
[0010] Based on the protocol name, determining the corresponding field attributes in the global hash table, and obtaining the values of the corresponding fields in the data packet; the field attributes include field names;
[0011] Based on the field name and the value of the corresponding field, obtaining a parsing log.
[0012] Optionally, the field attributes further include an offset, a length, a data type, and an encoding type.
[0013] Optionally, the identification module includes:
[0014] A storage module, configured to store a feature mapping relationship and a protocol mapping relationship;
[0015] A customization module, configured to customize the data packet and determine an identification feature;
[0016] A first analysis module, configured to parse the identification feature based on the feature mapping relationship to obtain a protocol number;
[0017] A second analysis module, configured to obtain a protocol name according to the protocol mapping relationship and the protocol number.
[0018] Optionally, the identification feature includes a protocol name, a protocol port range, a major class number, an application number, a three-layer protocol type, and a four-layer protocol type.
[0019] Optionally, the three-layer protocol type includes IPV4 and IPV6;
[0020] The four-layer protocol type includes TCP and UDP.
[0021] Optionally, the method further includes field attribute determination, specifically:
[0022] Based on the offset, the length, the data type, and the encoding type, obtain field attributes in the global hash table;
[0023] Obtain the value of the corresponding field of the field attribute and set the field attribute to the marked state;
[0024] Determine whether the field attribute of the obtained message is in the marked state;
[0025] If it is in the unmarked state, obtain the value of the corresponding field from the beginning.
[0026] Optionally, the xml configuration file is configured with the protocol name of the custom protocol and the field attribute.
[0027] Optionally, the parsing log is stored in a database.
[0028] In a second aspect, an embodiment of the present disclosure further provides a custom protocol parsing system based on an xml configuration file, including:
[0029] A file acquisition module, configured to scan and obtain an xml configuration file in a specific directory of a network security device;
[0030] A node generation module, configured to extract multiple field attributes of the xml configuration file and generate multiple nodes;
[0031] A building module configured to build a global hash table based on multiple said nodes, where the key-value of the global hash table is the protocol name;
[0032] A protocol name acquisition module configured to extract the protocol number of the input data packet and obtain the corresponding protocol name through an identification module;
[0033] A field information acquisition module configured to determine the corresponding field attributes in the global hash table based on the protocol name and obtain the values of the corresponding fields in the data packet; the field attributes include field names;
[0034] A parsing log acquisition module configured to obtain a parsing log based on the field name and the value of the corresponding field.
[0035] Thirdly, an embodiment of the present disclosure further provides an electronic device, adopting the following technical solution:
[0036] The electronic device includes:
[0037] At least one processor; and,
[0038] A memory communicatively connected to the at least one processor; wherein,
[0039] The memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute any one of the above-mentioned custom protocol parsing methods based on an xml configuration file.
[0040] Fourthly, an embodiment of the present disclosure further provides a computer-readable storage medium, which stores computer instructions for causing a computer to execute any one of the above-mentioned custom protocol parsing methods based on an xml configuration file.
[0041] The custom protocol parsing method based on an xml configuration file provided by the embodiment of the present disclosure generates an xml configuration file by configuring the attribute information of the fields required for the custom protocol in the interface system and stores it in a specific directory. By parsing the configuration file, the attribute information of each field is obtained, and the protocol of the network packet is parsed in the identification module to obtain log information. The method is simple to implement, has a fast parsing speed, is beneficial to data maintenance, and is beneficial to the development and maintenance of code.
[0042] By setting an identification module for custom protocol parsing, which specifically parses custom protocols, the frameworks required for various custom protocols are the same, and there is no need for each custom protocol to have its own parsing function. This solution has less code volume, is simple to implement, has a fast parsing speed, and is beneficial to the development and maintenance of code.
[0043] The above description is only an overview of the technical solution of the present disclosure. In order to understand the technical means of the present disclosure more clearly, it can be implemented according to the content of the specification. And in order to make the above and other purposes, features and advantages of the present disclosure more obvious and understandable, the following preferred embodiments are specifically given, and in conjunction with the accompanying drawings, the details are described as follows. Description of the Drawings
[0044] In order to more clearly illustrate the technical solutions of the embodiments of the present disclosure, the accompanying drawings required for use in the embodiments will be briefly introduced below. Obviously, the accompanying drawings in the following description are only some embodiments of the present disclosure. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can be obtained based on these drawings.
[0045] Figure 1 It is a logical schematic diagram of a custom protocol parsing method based on an xml configuration file provided by an embodiment of the present disclosure.
[0046] Figure 2 It is a schematic diagram of the composition of an identification module provided by an embodiment of the present disclosure.
[0047] Figure 3 It is a schematic diagram of the composition of a custom protocol parsing system based on an xml configuration file provided by an embodiment of the present disclosure.
[0048] Figure 4 It is a principle block diagram of an electronic device provided by an embodiment of the present disclosure. Detailed Embodiments
[0049] The embodiments of the present disclosure will be described in detail below in conjunction with the accompanying drawings.
[0050] It should be clear that the following specific examples illustrate the implementation manners of the present disclosure. Those skilled in the art can easily understand other advantages and effects of the present disclosure from the content disclosed in this specification. Obviously, the described embodiments are only a part of the embodiments of the present disclosure, rather than all of the embodiments. The present disclosure can also be implemented or applied through other different specific implementation manners. Various details in this specification can also be modified or changed based on different viewpoints and applications without departing from the spirit of the present disclosure. It should be noted that, without conflict, the following embodiments and the features in the embodiments can be combined with each other. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present disclosure without creative efforts belong to the scope of protection of the present disclosure.
[0051] Note that the following description relates to various aspects of embodiments within the scope of the appended claims. It will be apparent that the aspects described herein can be embodied in a wide variety of forms, and any specific structure and / or function described herein is illustrative only. Based on this disclosure, those skilled in the art will understand that one aspect described herein can be implemented independently of any other aspect, and two or more of these aspects can be combined in various ways. For example, any number of the aspects set forth herein can be used to implement an apparatus and / or practice a method. Additionally, this apparatus can be implemented and this method can be practiced using other structures and / or functionality in addition to one or more of the aspects set forth herein.
[0052] It should also be noted that the diagrams provided in the following embodiments only schematically illustrate the basic concept of the present disclosure. Only the components related to the present disclosure are shown in the diagrams, rather than being drawn according to the number, shape, and size of the components in actual implementation. The type, quantity, and ratio of each component in actual implementation can be arbitrarily changed, and the component layout type may also be more complex.
[0053] In addition, in the following description, specific details are provided to facilitate a thorough understanding of the examples. However, those skilled in the art will understand that the aspects can be practiced without these specific details.
[0054] Referring to Figure 1 and Figure 2 , the first aspect of the present application discloses a custom protocol parsing method based on an xml configuration file. The method includes the following steps:
[0055] S100, scan the xml configuration file in a specific directory of the network security device, extract multiple field attributes of the xml configuration file, and generate multiple nodes.
[0056] Among them, the generation method of the xml configuration file is: after the network security device is started, configure the attribute information of the field values of the custom protocol in the system interface to generate the xml configuration file. That is, the xml configuration file is configured with the protocol name and field attributes of the custom protocol. In this application, the configuration file in xml format is used to save the field attributes, which is convenient to intuitively view the values of each field attribute and is beneficial for users to configure the attributes of each field.
[0057] Further, the generation method of the node is: read the xml configuration file line by line, read the attributes of each field, and then generate a corresponding node.
[0058] S200. Based on multiple nodes, construct a global hash table, where the key-value of the global hash table is the protocol name; each node is inserted into the linked list corresponding to the custom protocol, and the linked list of each custom protocol is hung on the global hash bucket, using the protocol name as the search key-value of the global hash table.
[0059] S300. Extract the protocol number of the input data packet and obtain the corresponding protocol name through the recognition module. Specifically, when the data packet arrives at the network device, through protocol recognition, recognize the protocol number of the custom protocol, and obtain the protocol name through the protocol number in the recognition module.
[0060] Specifically, the recognition module includes a storage module, a custom module, a first analysis module, and a second analysis module. The storage module is used to store the feature mapping relationship and the protocol mapping relationship as the basis for custom parsing of subsequent data packets.
[0061] The custom module is used to customize the data packet, determine the recognition features, and form a unity with the storage module. Through the setting of the custom module, data packets that are not within the scope of the general protocol can also be processed.
[0062] Among them, the recognition features include protocol name, protocol port range, major class number, application number, three-layer protocol type, and four-layer protocol type.
[0063] The first analysis module is used to parse the recognition features based on the feature mapping relationship to obtain the protocol number; the second analysis module is used to obtain the protocol name according to the protocol mapping relationship and the protocol number.
[0064] In this embodiment, the three-layer protocol types include IPV4 and IPV6; the four-layer protocol types include TCP and UDP.
[0065] Through the set recognition module for custom protocol parsing, specifically perform custom protocol parsing. The frameworks required for various custom protocols are consistent, and there is no need for each custom protocol to have its own parsing function. This solution has less code volume, is simple to implement, has a fast parsing speed, and is conducive to code development and maintenance.
[0066] S400. Based on the protocol name, determine the corresponding field attributes in the global hash table and obtain the values of the corresponding fields in the data packet; among them, the field attributes include field name, offset, length, data type, and encoding type.
[0067] Specifically, in the global hash table, use the obtained protocol name as the search key-value, query the various field attributes corresponding to this protocol in the global hash table, traverse the protocol field attribute array, and read the value of this field in the message according to the attributes such as offset, length, data type, and encoding type of each field in the array.
[0068] Further, the method further includes field attribute determination, specifically:
[0069] Based on the offset, length, data type, and encoding type, obtain field attributes in the global hash table;
[0070] Obtain the value of the corresponding field of the field attribute, and set the field attribute to the marked state;
[0071] When the next message arrives, determine whether the obtained field attribute is in the marked state. If it is in the marked state, it indicates that the corresponding value of the field attribute has been obtained, and there is no need to obtain the value of the corresponding field from the beginning; if it is not in the marked state, the value of the corresponding field needs to be obtained from the beginning.
[0072] S500, based on the field name and the value of the corresponding field, obtain the parsing log, that is, form a parsing log from multiple field information. The parsing log can be stored in the database and can be displayed on the system interface, facilitating users to view the log information parsed by the custom protocol. The present invention can be applied to the network security device system to parse the custom protocol, generate the parsing log, and display it in the interface system.
[0073] The solution disclosed in this application is based on the product of the network security device. By configuring the attribute information of the fields required by the custom protocol in the interface system, generating an xml configuration file, storing it in a specific directory, parsing the configuration file, obtaining the attribute information of each field, and in the parsing plugin (i.e., the recognition module), parsing the network message to obtain the log information, the implementation method is simple, the parsing speed is fast, which is beneficial to data maintenance and beneficial to the development and maintenance of the code.
[0074] This application uses an xml configuration file to store the configuration of the custom protocol, and uses a global hash table to store the configuration data of the custom protocol. The field data of each custom protocol is a node of the hash table. The number of configuration tables is small, effectively improving the rate of querying the field information belonging to the configuration data of the message in the hash table.
[0075] Refer to Figure 3 , the second aspect of this application discloses a custom protocol parsing system based on an xml configuration file, including a file acquisition module, a node generation module, a construction module, a protocol name acquisition module, a field information acquisition module, and a parsing log acquisition module.
[0076] The file acquisition module is configured to scan and obtain the xml configuration file in the specific directory of the network security device;
[0077] The node generation module is configured to extract multiple field attributes of the xml configuration file and generate multiple nodes;
[0078] The building module is configured to build a global hash table based on multiple nodes, and the key value of the global hash table is the protocol name;
[0079] The protocol name acquisition module is configured to extract the protocol number of the input data packet and obtain the corresponding protocol name through the recognition module;
[0080] The field information acquisition module is configured to determine the corresponding field attributes in the global hash table based on the protocol name and obtain the values of the corresponding fields in the data packet; the field attributes include field names;
[0081] The parsing log acquisition module is configured to obtain the parsing log based on the field name and the value of the corresponding field.
[0082] The electronic device according to an embodiment of the present disclosure includes a memory and a processor. The memory is used to store non-transitory computer-readable instructions. Specifically, the memory may include one or more computer program products, and the computer program products may include various forms of computer-readable storage media, such as volatile memory and / or non-volatile memory. The volatile memory may include, for example, random access memory (RAM) and / or cache memory, etc. The non-volatile memory may include, for example, read-only memory (ROM), hard disk, flash memory, etc.
[0083] The processor may be a central processing unit (CPU) or other forms of processing units with data processing capabilities and / or instruction execution capabilities, and may control other components in the electronic device to perform desired functions. In an embodiment of the present disclosure, the processor is used to run the computer-readable instructions stored in the memory, so that the electronic device executes all or part of the steps of the custom protocol parsing method based on the xml configuration file in the foregoing embodiments of the present disclosure.
[0084] Those skilled in the art should understand that, in order to solve the technical problem of how to obtain good user experience effects, this embodiment may also include well-known structures such as communication buses and interfaces, and these well-known structures should also be included in the protection scope of the present disclosure.
[0085] As Figure 4 It is a schematic structural diagram of an electronic device provided by an embodiment of the present disclosure. It shows a schematic structural diagram of an electronic device suitable for implementing the electronic device in the embodiments of the present disclosure. Figure 4 The shown electronic device is only an example and should not bring any limitations to the functions and usage scope of the embodiments of the present disclosure.
[0086] As Figure 4As shown, the electronic device may include a processing device (such as a central processing unit, a graphics processing unit, etc.), which may perform various appropriate actions and processes according to the program stored in the read-only memory (ROM) or the program loaded from the storage device into the random access memory (RAM). In the RAM, various programs and data required for the operation of the electronic device are also stored. The processing device, ROM, and RAM are connected to each other through a bus. The input / output (I / O) interface is also connected to the bus.
[0087] Generally, the following devices may be connected to the I / O interface: an input device including, for example, a sensor or a visual information acquisition device, etc.; an output device including, for example, a display screen, etc.; a storage device including, for example, a magnetic tape, a hard disk, etc.; and a communication device. The communication device may allow the electronic device to communicate with other devices (such as edge computing devices) wirelessly or wiredly to exchange data. Although Figure 4 an electronic device with various devices is shown, it should be understood that it is not required to implement or have all the shown devices. Instead, more or fewer devices may be implemented or had.
[0088] In particular, according to an embodiment of the present disclosure, the process described above with reference to the flowchart may be implemented as a computer software program. For example, an embodiment of the present disclosure includes a computer program product, which includes a computer program carried on a non-transitory computer-readable medium, and the computer program includes program codes for executing the method shown in the flowchart. In such an embodiment, the computer program may be downloaded and installed from the network through the communication device, or installed from the storage device, or installed from the ROM. When the computer program is executed by the processing device, all or part of the steps of the custom protocol parsing method based on the xml configuration file of the embodiments of the present disclosure are executed.
[0089] For a detailed description of this embodiment, reference may be made to the corresponding descriptions in the foregoing embodiments, and details will not be repeated here.
[0090] A computer-readable storage medium according to an embodiment of the present disclosure stores non-temporary computer-readable instructions. When the non-temporary computer-readable instructions are run by a processor, all or part of the steps of the custom protocol parsing method based on the xml configuration file of the foregoing embodiments of the present disclosure are executed.
[0091] The above-mentioned computer-readable storage medium includes but is not limited to: optical storage media (such as CD-ROMs and DVDs), magneto-optical storage media (such as MOs), magnetic storage media (such as magnetic tapes or removable hard disks), media with built-in rewritable non-volatile memories (such as memory cards), and media with built-in ROMs (such as ROM cartridges).
[0092] For a detailed description of this embodiment, reference may be made to the corresponding descriptions in the foregoing embodiments, which will not be elaborated herein.
[0093] The basic principles of the present disclosure have been described above in conjunction with specific embodiments. However, it should be noted that the advantages, benefits, effects, etc. mentioned in the present disclosure are only examples and not limitations. It cannot be considered that these advantages, benefits, effects, etc. are essential for each embodiment of the present disclosure. Additionally, the specific details disclosed above are only for illustrative and facilitating understanding purposes and not limitations. The above details do not limit the present disclosure to necessarily implementing with the above specific details.
[0094] In the present disclosure, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. The block diagrams of devices, apparatuses, equipment, and systems involved in the present disclosure are only illustrative examples and do not intend to require or imply that they must be connected, arranged, and configured in the manner shown in the block diagrams. As those skilled in the art will recognize, these devices, apparatuses, equipment, and systems can be connected, arranged, and configured in any manner. Words such as "including", "comprising", "having", etc. are open-ended terms meaning "including but not limited to" and can be used interchangeably with each other. The word "or" and "and" used herein refer to the word "and / or" and can be used interchangeably with each other unless the context clearly indicates otherwise. The word "such as" used herein refers to the phrase "such as but not limited to" and can be used interchangeably with each other.
[0095] In addition, as used herein, the "or" used in the listing of items starting with "at least one" indicates a separate listing, so that for example, the listing of "at least one of A, B, or C" means A or B or C, or AB or AC or BC, or ABC (i.e., A and B and C). Furthermore, the term "exemplary" does not mean that the described examples are preferred or better than other examples.
[0096] It should also be noted that in the systems and methods of the present disclosure, each component or each step can be decomposed and / or recombined. These decompositions and / or recombinations should be regarded as equivalent solutions of the present disclosure.
[0097] Various changes, substitutions, and alterations to the technology described herein can be made without departing from the teachings defined by the appended claims. Additionally, the scope of the claims of this disclosure is not limited to the specific aspects of the processes, machines, manufactures, compositions of events, means, methods, and acts described above. Processes, machines, manufactures, compositions of events, means, methods, or acts that are currently available or later to be developed that perform substantially the same function or achieve substantially the same result as the corresponding aspects described herein can be utilized. Accordingly, the appended claims include such processes, machines, manufactures, compositions of events, means, methods, or acts within their scope.
[0098] The foregoing description of the disclosed aspects is provided to enable any person skilled in the art to make or use the present disclosure. Various modifications to these aspects will be readily apparent to those skilled in the art, and the general principles defined herein can be applied to other aspects without departing from the scope of the present disclosure. Thus, the present disclosure is not intended to be limited to the aspects shown herein but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.
[0099] The foregoing description has been presented for purposes of illustration and description. Furthermore, this description is not intended to limit the embodiments of the present disclosure to the form disclosed herein. Although numerous example aspects and embodiments have been discussed above, those skilled in the art will recognize some of their variations, modifications, alterations, additions, and subcombinations.
Claims
1. A custom protocol parsing method based on an xml configuration file, characterized in that, The method includes: Scanning the xml configuration files in a specific directory of a network security device, extracting multiple field attributes of the xml configuration files, and generating multiple nodes; Based on the nodes, constructing a global hash table; the key value of the global hash table is the protocol name; Extracting the protocol number of the input data packet, and obtaining the corresponding protocol name through an identification module; Based on the protocol name, determining the corresponding field attributes in the global hash table, and obtaining the values of the corresponding fields in the data packet; the field attributes include field names; Based on the field names and the values of the corresponding fields, obtaining a parsing log; The identification module includes: A storage module configured to store a feature mapping relationship and a protocol mapping relationship; A custom module configured to customize the data packet and determine identification features; A first analysis module configured to parse the identification features based on the feature mapping relationship to obtain a protocol number; A second analysis module configured to obtain a protocol name according to the protocol mapping relationship and the protocol number.
2. The custom protocol parsing method according to claim 1, wherein The field attributes further include an offset, a length, a data type, and an encoding type.
3. The custom protocol parsing method according to claim 1, characterized in that The identification features include a protocol name, a protocol port range, a major class number, an application number, a three-layer protocol type, and a four-layer protocol type.
4. The custom protocol parsing method according to claim 3, wherein The three-layer protocol types include IPV4 and IPV6; The four-layer protocol types include TCP and UDP.
5. The custom protocol parsing method according to claim 2, wherein It further includes a field attribute determination; the specific field attribute determination is: Based on the offset, the length, the data type, and the encoding type, obtaining field attributes in the global hash table; Obtaining the values of the corresponding fields of the field attributes, and setting the field attributes to a marked state; Judging whether the field attributes of the obtained message are in a marked state; If it is in a non-marked state, obtaining the values of the corresponding fields from the beginning.
6. The custom protocol parsing method according to claim 1, wherein The xml configuration file is configured with the protocol names of custom protocols and the field attributes.
7. The custom protocol parsing method according to claim 1, characterized in that, The parsing log is stored in a database.
8. A custom protocol parsing system based on an xml configuration file, characterized in that, It includes: A file acquisition module configured to scan and obtain xml configuration files in a specific directory of a network security device; A node generation module configured to extract multiple field attributes of the xml configuration files and generate multiple nodes; A construction module configured to construct a global hash table based on multiple nodes, and the key value of the global hash table is the protocol name; A protocol name acquisition module configured to extract the protocol number of the input data packet and obtain the corresponding protocol name through an identification module; A field information acquisition module configured to determine the corresponding field attributes in the global hash table based on the protocol name, and obtain the values of the corresponding fields in the data packet; the field attributes include field names; A parsing log acquisition module configured to obtain a parsing log based on the field names and the values of the corresponding fields; The identification module includes: A storage module configured to store a feature mapping relationship and a protocol mapping relationship; A custom module configured to customize the data packet and determine identification features; A first analysis module configured to parse the identification features based on the feature mapping relationship to obtain a protocol number; A second analysis module, configured to obtain a protocol name according to the protocol mapping relationship and the protocol number.
9. An electronic device, characterized in that, The electronic device includes: At least one processor; and, A memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the custom protocol parsing method based on the xml configuration file according to any one of claims 1-7.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions for causing a computer to execute the custom protocol parsing method based on the xml configuration file according to any one of claims 1-7.
Citation Information
Patent Citations
A realization method of a self-defined protocol based on a protocol analysis framework
CN109842629A
Message protocol analysis method and device
CN112118232A