...
首页> 外文期刊>Security and Communications Networks >A novel comprehensive steganalysis of transmission control protocol/Internet protocol covert channels based on protocol behaviors and support vector machine
【24h】

A novel comprehensive steganalysis of transmission control protocol/Internet protocol covert channels based on protocol behaviors and support vector machine

机译:基于协议行为和支持向量机的传输控制协议/ Internet协议隐蔽通道的新型综合隐写分析

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

Covert channels are malicious conversations disguised in legitimate network communications, allowing information leak to the unauthorized or unknown receiver. Various network steganographic schemes that modify the header fields of transmission control protocol/Internet protocol (TCP/IP) have been proposed in recent years. People before conducted detection research based on the surface content of the header field and did not take into account the differences between the behavior characters of covert channels and the inherent behavior regularities of the header fields. Up to date, there is little comprehensive research on the steganalysis against the storage covert channels. In this paper, we focus on the detection of storage covert channels and introduce a novel comprehensive detection method based on the protocol behaviors. The protocol behavior characters are utilized to evaluate the regularities or correlations of header fields between adjacent packets according to the conventional use. First, the behavior features of the header fields in TCP/IP are extracted; a support vector machine is then applied to the behavior feature sets for discovering the existence of covert channels. Some recognized covert channel tools are detected in our detection experiment. Experimental results and discussion show that our detection method is of effectiveness. Copyright (c) 2014 John Wiley & Sons, Ltd.
机译:隐蔽通道是合法网络通信中伪装的恶意对话,使信息泄露给未经授权或未知的接收者。近年来,已经提出了各种修改传输控制协议/互联网协议(TCP / IP)的报头字段的网络隐写方案。之前的人们是基于头域的表面内容进行检测研究的,没有考虑隐蔽通道的行为特征与头域的固有行为规律之间的差异。迄今为止,针对存储秘密通道的隐写分析尚缺乏全面的研究。在本文中,我们将重点放在存储隐蔽通道的检测上,并介绍一种基于协议行为的新型综合检测方法。根据常规用途,协议行为特征用于评估相邻分组之间的报头字段的规则性或相关性。首先,提取TCP / IP中标头字段的行为特征;然后将支持向量机应用于行为特征集,以发现隐蔽通道的存在。我们的检测实验中检测到一些公认的隐蔽通道工具。实验结果和讨论表明我们的检测方法是有效的。版权所有(c)2014 John Wiley&Sons,Ltd.

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号