首页> 外文期刊>IEEE transactions on dependable and secure computing >Towards a Reliable Detection of Covert Timing Channels over Real-Time Network Traffic
【24h】

Towards a Reliable Detection of Covert Timing Channels over Real-Time Network Traffic

机译:在实时网络流量上实现对隐蔽定时通道的可靠检测

获取原文
获取原文并翻译 | 示例

摘要

Inter-packet delays (IPD) of legitimate network traffic can be exploited for information hiding purposes and distribution of secret and sensitive data. This process is known as Covert Timing Channel (CTC), which is usually used for malicious purposes. In this paper we propose a novel approach, CTC Real-Time Detection (CTCRTD) to detect such activities based on IPD distributions of network traffic. We present and leverage three different non-parametric statistical tests that can be used to generate distinct statistical test scores for overt and covert traffic IPDs. Our new detection approach is designed around two major benefits: First, the new detection approach can detect various CTC algorithms that have similar impact on network traffic IPD distributions. Second, our detection approach reliably detects covert communication over real-time network traffic with minimal lag between the start of covert activity and the point of detection. We have evaluated and verified the reliability and effectiveness of our detection approach utilizing a large number of overt and covert traffic streams and various scenarios of the proposed detection technique. The obtained results show that the new detection approach can precisely differentiate between overt and covert network traffic and detect covert communication activities over 90 percent of time on average.
机译:合法网络流量的数据包间延迟(IPD)可用于信息隐藏目的以及机密和敏感数据的分发。此过程称为隐蔽定时通道(CTC),通常用于恶意目的。在本文中,我们提出了一种新颖的方法,即CTC实时检测(CTCRTD),用于基于网络流量的IPD分布来检测此类活动。我们介绍并利用了三种不同的非参数统计测试,这些测试可用于为公开和隐蔽流量IPD生成不同的统计测试分数。我们的新检测方法围绕两个主要优点进行设计:首先,新检测方法可以检测对网络流量IPD分布具有类似影响的各种CTC算法。其次,我们的检测方法能够可靠地检测实时网络流量上的隐蔽通信,并且隐蔽活动的开始与检测点之间的延迟最小。我们已经评估和验证了我们的检测方法的可靠性和有效性,该方法利用了大量的公开和秘密交通流以及所提出的检测技术的各种场景。所获得的结果表明,这种新的检测方法可以精确地区分公开和隐蔽的网络流量,并平均检测90%以上时间的隐蔽通信活动。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号