🤖 AI Summary
Existing FSM extraction methods suffer from limited scalability, incomplete coverage of protocol specifications, and inadequate handling of natural language ambiguity in RFC documents. To address these challenges, we propose FlowFSM—a novel framework that integrates large language model (LLM) agents, prompt chaining, and stepwise chain-of-thought reasoning to enable high-accuracy, fully automated extraction of protocol state machines from RFCs. FlowFSM decomposes the extraction task into modular subtasks, employs multi-stage rule generation, and incorporates hallucination suppression mechanisms to enhance reliability in state identification and transition inference. Experimental evaluation on FTP and RTSP protocols demonstrates a 42.7% reduction in erroneous transitions and achieves 98.3% state coverage. This work establishes a scalable, robust paradigm for protocol modeling, formal verification, and vulnerability discovery—bridging the gap between natural-language protocol specifications and precise, executable state-machine representations.
📝 Abstract
Finite-State Machines (FSMs) are critical for modeling the operational logic of network protocols, enabling verification, analysis, and vulnerability discovery. However, existing FSM extraction techniques face limitations such as scalability, incomplete coverage, and ambiguity in natural language specifications. In this paper, we propose FlowFSM, a novel agentic framework that leverages Large Language Models (LLMs) combined with prompt chaining and chain-of-thought reasoning to extract accurate FSMs from raw RFC documents. FlowFSM systematically processes protocol specifications, identifies state transitions, and constructs structured rule-books by chaining agent outputs. Experimental evaluation across FTP and RTSP protocols demonstrates that FlowFSM achieves high extraction precision while minimizing hallucinated transitions, showing promising results. Our findings highlight the potential of agent-based LLM systems in the advancement of protocol analysis and FSM inference for cybersecurity and reverse engineering applications.