首页> 外文会议>IEEE International Conference on Intelligence and Security Informatics >Raising flags: Detecting covert storage channels using relative entropy
【24h】

Raising flags: Detecting covert storage channels using relative entropy

机译:提升标志:使用相对熵检测隐蔽存储通道

获取原文

摘要

This paper focuses on one type of Covert Storage Channel (CSC) that uses the 6-bit TCP flag header in TCP/IP network packets to transmit secret messages between accomplices. We use relative entropy to characterize the irregularity of network flows in comparison to normal traffic. A normal profile is created by the frequency distribution of TCP flags in regular traffic packets. In detection, the TCP flag frequency distribution of network traffic is computed for each unique IP pair. In order to evaluate the accuracy and efficiency of the proposed method, this study uses real regular traffic data sets as well as CSC messages using coding schemes under assumptions of both clear text, composed by a list of keywords common in Unix systems, and encrypted text. Moreover, smart accomplices may use only those TCP flags that are ever appearing in normal traffic. Then, in detection, the relative entropy can reveal the dissimilarity of a different frequency distribution from this normal profile. We have also used different data processing methods in detection: one method summarizes all the packets for a pair of IP addresses into one flow and the other uses a sliding moving window over such a flow to generate multiple frames of packets. The experimentation results, displayed by Receiver Operating Characteristic (ROC) curves, have shown that the method is promising to differentiate normal and CSC traffic packet streams. Furthermore the delay of raising an alert is analyzed for CSC messages to show its efficiency.
机译:本文重点介绍一种隐蔽存储通道(CSC),它使用TCP / IP网络数据包中的6位TCP标志头在同伙之间传输秘密消息。与正常流量相比,我们使用相对熵来表征网络流量的不规则性。正常配置文件是由常规流量数据包中TCP标志的频率分布创建的。在检测中,针对每个唯一IP对计算网络流量的TCP标志频率分布。为了评估所提方法的准确性和效率,本研究使用了真实的常规流量数据集以及使用编码方案的CSC消息,这些假定均由明文(由Unix系统中常见的关键字列表组成)和加密文本组成。此外,智能同谋可能只使用那些在正常流量中出现的TCP标志。然后,在检测中,相对熵可以揭示出与该正态分布不同的频率分布的不相似性。我们在检测中还使用了不同的数据处理方法:一种方法将一对IP地址的所有数据包汇总为一个流,另一种方法在此类流上使用滑动移动窗口以生成多个帧的数据包。通过接收器工作特性(ROC)曲线显示的实验结果表明,该方法有望区分正常流量和CSC流量数据包流。此外,针对CSC消息分析了发出警报的延迟,以显示其效率。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号