...
首页> 外文期刊>International Journal of Network Security & Its Applications >Performance Analysis of Transport Layer Basedhybrid Covert Channel Detection Engine
【24h】

Performance Analysis of Transport Layer Basedhybrid Covert Channel Detection Engine

机译:基于传输层的混合隐蔽信道检测引擎性能分析

获取原文
           

摘要

Computer network is unpredictable due to information warfareand is prone to various attacks. Such attacks on network compromiseson the most important attribute, the privacy. Most of such attacksare devised using special communication channel called Covert Channel".The word Covert" stands for hidden or non-transparent.Network Covert Channel is concealed communication paths within legitimatenetwork communication that clearly violates security policies laiddown. Non-transparency in covert channel is also referred to as trapdoor.A trapdoor is unintended design within legitimate communication whosemotto is leak information. Subliminal channel, a variant of covert channelworks similarly as network covert channel except that trapdoor is setin cryptographic algorithm. A composition of covert channel with subliminalchannel is the Hybrid Covert Channel". Hybrid covert channelis the homogeneous or heterogeneous mixture of two or more variantsof covert channel either active at same instance or at different instanceof time. Detecting such malicious channel activity plays a vital role inremoving threat to legitimate network.In this paper, we introduce new detection engine for hybrid covert channelin transport layer visualized in TCP and SSL. A setup made onexperimental test bed (DE-HCC9) in RD Lab of our department. Thepurpose of this study is to introduce few performance metrics to evaluatedetection engine and also to understand the multi-trapdoor natureof covert channel
机译:由于信息战,计算机网络是不可预测的,并且容易受到各种攻击。对网络的此类攻击是最重要的属性,即隐私。大多数此类攻击是使用称为“ Covert Channel”的特殊通信通道设计的。“ Covert”一词表示隐藏或不透明。NetworkCovert Channel是合法网络通信中的隐蔽通信路径,显然违反了所制定的安全策略。隐蔽通道中的不透明也称为陷阱门。陷阱门是合法通信中的意外设计,其座右铭是泄漏信息。阈下通道(subliminal channel)是隐蔽通道的一种变体,其工作原理与网络隐秘通道类似,不同之处在于在加密算法中设置了陷门。混合隐蔽通道是两个或多个隐蔽通道变体的同质或异质混合物,它们在同一时间或不同时间处于活动状态。检测到这种恶意通道活动起着至关重要的作用本文介绍了一种新的TCP和SSL可视化传输层混合隐蔽通道检测引擎,在我院RD实验室的实验台上进行了设置,研究目的是介绍一些性能指标来评估检测引擎,并了解隐蔽通道的多活板门性质

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号