...
首页> 外文期刊>Telecommunication systems: Modeling, Analysis, Design and Management >Detection of TCP covert channel based on Markov model
【24h】

Detection of TCP covert channel based on Markov model

机译:基于马尔可夫模型的TCP隐蔽通道检测

获取原文
获取原文并翻译 | 示例
           

摘要

Network covert channel is a covert communication method by hiding covert messages into overt network packets. In recent years, with the development of various hiding methods, network covert channel has become a new kind of threat for network security. The covert channel that uses the redundancies existing in TCP protocol to make hiding is called TCP covert channel. In this paper, the behaviors of TCP flows are modeled by the Markov chain composed of the states of TCP packets. And the abnormality caused by TCP covert channel is described by the difference between the overt and covert TCP transition probability matrix. The detection method based on MAP is proposed to detect the covert communication hidden in TCP flows under various applications such as HTTP, FTP, TELNET, SSH and SMTP. Experiments show that the proposed algorithm achieves better detection performance than the existing methods.
机译:网络秘密通道是一种通过将秘密消息隐藏到明显的网络数据包中的秘密通信方法。近年来,随着各种隐藏方法的发展,网络隐蔽通道已成为对网络安全的一种新型威胁。使用TCP协议中存在的冗余进行隐藏的隐蔽通道称为TCP隐蔽通道。在本文中,TCP流的行为是由由TCP数据包状态组成的马尔可夫链建模的。 TCP隐秘通道引起的异常用隐性和隐性TCP转换概率矩阵之差来描述。提出了一种基于MAP的检测方法,以检测HTTP,FTP,TELNET,SSH和SMTP等各种应用下TCP流中隐藏的隐蔽通信。实验表明,该算法比现有算法具有更好的检测性能。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号