An Investigation of Interaction and Information Needs for Protocol Reverse Engineering Automation

Honorable Mention
Explainable AI (XAI)AI-Assisted Decision-Making & AutomationAlgorithmic Transparency & AuditabilitySoftware Engineers & DevelopersCybersecurity Engineers

Research Background and Problem Statement

  • Identified Problems or Challenges:
    Automated Protocol Reverse Engineering (ProtocolREing) tools have limited practical application due to their lack of user interactivity. As a result, reverse engineers (ProtocolREs) tend to perform this task manually or use simple visualization tools.

  • Importance of the Problem:
    ProtocolREing is a core task in malware analysis and cybersecurity, especially when analyzing complex embedded systems and non-executable software. Improved tools can enhance efficiency and reduce operational complexity.

  • Research Motivation and Related Work:
    Current studies primarily focus on human-computer interaction (HCI) in software reverse engineering (SoftwareREing), while human factors research in ProtocolREing remains unexplored. The authors aim to fill this gap by understanding the processes and needs of ProtocolREs to guide the interaction design of next-generation tools.

Proposed Solution

  • Proposed Approach:
    The authors propose designing better automated interfaces for ProtocolREing, developing HCI-optimized support tools, and understanding user needs through interviews with reverse engineers and prototype design.

  • Innovative Aspects of the Solution:

    1. Introduced an iterative loop model tailored to the ProtocolREing workflow, focusing on field boundary identification and data type inference.
    2. Designed and tested a paper prototype of an automated interface, incorporating the strengths of current tools while adding user feedback and rapid interaction mechanisms.
    3. Identified specific information and interaction needs in ProtocolRE, such as requirements for data distribution, statistical information, and explainable automated feedback.
  • Implementation Steps and Key Techniques:

    1. Interview Design: Conducted semi-structured interviews with 16 professional ProtocolREs to understand their needs and workflows.
    2. Prototype Development: Designed five views (including Decimal-Hexadecimal View, Split-Merge View, Data Type Decoding, Histogram, etc.) by integrating existing tool functionalities and HCI literature.
    3. Coding Analysis of Information and Interaction Needs: Performed open and axial coding based on interview results to extract key themes and patterns.
    4. Iterative Research Model: Developed a flowchart for ProtocolREing, including field boundary marking, data type inference, and contextual information integration.

Research Outcomes

  • Specific Findings:

    1. The core tasks of ProtocolRE focus on identifying and iteratively refining field boundaries and data types.
    2. The process involves close interaction and diverse needs (e.g., dynamic data visualization, explainable data support, seamless integration with other tools).
    3. The new iterative research model highlights the importance of rapid hypothesis switching and validation, particularly in human-computer collaboration.
  • Experimental or Evaluation Results:

    • The prototype views successfully revealed the limitations of current ProtocolREing tools, such as the lack of user-defined field boundaries or data types and insufficient explanation capabilities for automated suggestions.
    • Most participants acknowledged the importance of the Histogram View and Split-Merge View for initial exploration but suggested hiding redundant information to avoid visual fatigue.
  • Advantages Over Existing Solutions:

    1. Emphasized user interaction with automated tools, enabling users to guide automated analysis through rapid feedback mechanisms.
    2. Provided visualization support for data distribution and type inference, allowing analysts to validate hypotheses more quickly.
    3. Specifically addressed the unique needs of ProtocolREing (e.g., fast-paced iterative testing and flexible format support), achieving higher adaptability compared to traditional static tools like Wireshark and CyberChef.
  • Limitations and Future Directions:

    1. Limitations:

      • Limited sample size, with only 16 experts.
      • The use of paper prototypes restricted the simulation of real interaction environments.
      • No experiments were conducted to analyze differences in needs between industry novices and experts.
    2. Future Directions:

      • Develop actual tools based on the prototype design and test them with embedded or malware samples.
      • Expand the sample size to include novices and a broader range of professionals to verify generalizability.
      • Explore intersections with the code analysis domain (SoftwareREing) to study commonalities and differences between the two tasks.
      • Enhance collaborative validation modules to support the automatic generation of protocol parsing scripts and integration with other tools (e.g., Wireshark).

Quick Actions

Share

Share this page

ios_share

https://hci.top/en/papers/chi/188937/2025

AdRecommended

Learn AI Coding at CodeNow

open_in_newOpen DOI Link
DOI: https://dl.acm.org/doi/10.1145/3706598.3713630
At a Glance

Paper Snapshot

fact_check
dataset
Source
CHI
calendar_month
Year
2025
emoji_events
Award
Honorable Mention
group
Authors
4 authors
sell
Subtopics
Explainable AI (XAI), AI-Assisted Decision-Making & Automation, Algorithmic Transparency & Auditability
work
Professions
Software Engineers & Developers, Cybersecurity Engineers
article
Content Status
Full text indexed
hub
Related Papers
3 related papers