首页> 外文会议>International Conference on Information Science and Applications >The Capacity of Undetectable On/Off Covert Channel
【24h】

The Capacity of Undetectable On/Off Covert Channel

机译:无法侦测开/关隐藏渠道的能力

获取原文

摘要

Almost all modern computer networks are based on TCP/IP protocol suite. However, structure features of IP allow constructing covert channels with high capacity using modification of inter-packets delays, packets' header fields and packets lengths. A technique to eliminate such channels is traffic normalization which means sending packets with equal lengths and fixed header fields with equal inter-packets delays that leads to significant decreasing of efficient communication channels capacity and missing of functional capabilities of network protocols. Another way to counteract covert channel is to detect an active channel. Nevertheless, an attacker can reduce the covert channel capacity purposely to make it undetectable. We investigate on/off covert channel and give recommendations to choose the parameters of ε-similarity detection method with specified threshold values of covert channels capacity.
机译:几乎所有现代计算机网络都基于TCP / IP协议套件。然而,IP的结构特征允许使用分组间延迟的修改,分组的标题字段和数据包长度构造具有高容量的隐蔽通道。消除这种通道的技术是交通归一化,其意味着向具有相等长度和固定的报头字段发送具有相等分组间延迟的分组,这导致高效的通信信道容量和网络协议的功能能力缺失的显着降低。抵消隐蔽信道的另一种方法是检测活动通道。然而,攻击者可以故意减少隐蔽的信道容量,以使其无法察觉。我们调查ON / OFF封面通道,并提出建议选择具有封闭通道容量的指定阈值的ε-相似性检测方法的参数。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号