首页> 外文会议>IEEE International Conference on Communication Technology >Covert timing channel detection method based on random forest algorithm
【24h】

Covert timing channel detection method based on random forest algorithm

机译:基于随机森林算法的隐蔽定时信道检测方法

获取原文

摘要

Network stealth events emerging in endless stream, covert timing channel is one of the most difficult means to prevent. In order to further improve the detection rate of the covert timing channel under the condition of small embedded information length. In this paper, the detection method based on SVM is analyzed. On the basis of the above analysis, adds a variety of statistical features, and a detection method based on random forest algorithm is proposed. The Inter-Packet Delay sequence of the covert timing channel is described from the statistical features of each order, and the above characteristics are used as the communication fingerprint of the covert channel. Then, the classifier based on the random forest algorithm is trained according to the communication fingerprint of the sample, and the classifier is used to judge whether the channel to be detected is the normal channel. The experimental results show that the method can effectively detect the covert timing channel in the case where the length of the embedded information is small. Compared with existing related works, this method has a certain rate of improvement, and the importance of the proposed statistical features are evaluated.
机译:网络隐身事件层出不穷,隐秘的定时通道是最难预防的手段之一。为了在嵌入信息长度较小的情况下进一步提高隐蔽定时信道的检测率。本文分析了基于支持向量机的检测方法。在以上分析的基础上,增加了多种统计特征,提出了一种基于随机森林算法的检测方法。从每个阶的统计特征描述隐蔽定时信道的分组间延迟序列,并且上述特征用作隐蔽信道的通信指纹。然后,根据样本的通信指纹对基于随机森林算法的分类器进行训练,并利用该分类器判断待检测的信道是否为正常信道。实验结果表明,在嵌入信息长度较小的情况下,该方法可以有效地检测隐蔽定时信道。与现有的相关工作相比,该方法有一定的改进率,并对所提出的统计特征的重要性进行了评估。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号