Detection of TCP covert channel based on Markov model

被引:7
|
作者
Zhai, Jiangtao [1 ]
Liu, Guangjie [1 ]
Dai, Yuewei [1 ]
机构
[1] Nanjing Univ Sci & Technol, Sch Automat, Nanjing 210094, Jiangsu, Peoples R China
关键词
TCP covert channel; Markov model; Covert channel detection; MAP;
D O I
10.1007/s11235-013-9737-7
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
Network covert channel is a covert communication method by hiding covert messages into overt network packets. In recent years, with the development of various hiding methods, network covert channel has become a new kind of threat for network security. The covert channel that uses the redundancies existing in TCP protocol to make hiding is called TCP covert channel. In this paper, the behaviors of TCP flows are modeled by the Markov chain composed of the states of TCP packets. And the abnormality caused by TCP covert channel is described by the difference between the overt and covert TCP transition probability matrix. The detection method based on MAP is proposed to detect the covert communication hidden in TCP flows under various applications such as HTTP, FTP, TELNET, SSH and SMTP. Experiments show that the proposed algorithm achieves better detection performance than the existing methods.
引用
下载
收藏
页码:333 / 343
页数:11
相关论文
共 50 条
  • [1] Detection of TCP covert channel based on Markov model
    Jiangtao Zhai
    Guangjie Liu
    Yuewei Dai
    Telecommunication Systems, 2013, 54 : 333 - 343
  • [2] A TCP-based Covert Channel with Integrity Check and Retransmission
    Bistarelli, Stefano
    Imparato, Andrea
    Santini, Francesco
    2023 20TH ANNUAL INTERNATIONAL CONFERENCE ON PRIVACY, SECURITY AND TRUST, PST, 2023, : 62 - 68
  • [3] A TCP-based covert channel with integrity check and retransmission
    Bistarelli, Stefano
    Imparato, Andrea
    Santini, Francesco
    INTERNATIONAL JOURNAL OF INFORMATION SECURITY, 2024, : 3481 - 3512
  • [4] Efficient Non-Linear Covert Channel Detection in TCP Data Streams
    Nafea, Hanaa
    Kifayat, Kashif
    Shi, Qi
    Qureshi, Kashif Naseer
    Askwith, Bob
    IEEE ACCESS, 2020, 8 : 1680 - 1690
  • [5] Network based detection of passive covert channels in TCP/IP
    Tumoian, E
    Anikeev, M
    LCN 2005: 30TH CONFERENCE ON LOCAL COMPUTER NETWORKS, PROCEEDINGS, 2005, : 802 - 807
  • [6] Detection of Covert Channels in TCP Retransmissions
    Zillien, Sebastian
    Wendzel, Steffen
    SECURE IT SYSTEMS, 2018, 11252 : 203 - 218
  • [7] Markov model based congestion control for TCP
    Suthaharan, S
    37TH ANNUAL SIMULATION SYMPOSIUM, PROCEEDINGS, 2004, : 285 - 292
  • [8] Covert Channel Detection: A Survey Based Analysis
    Gober, S. Zerafshan
    Javed, Barkha
    Saqib, Nazar Abbas
    2012 9TH INTERNATIONAL CONFERENCE ON HIGH CAPACITY OPTICAL NETWORKS AND EMERGING/ENABLING TECHNOLOGIES (HONET), 2012, : 57 - 64
  • [9] A study on the covert channel detection of TCP/IP header using support vector machine
    Sohn, T
    Seo, JT
    Moon, J
    INFORMATION AND COMMUNICATIONS SECURITY, PROCEEDINGS, 2003, 2836 : 313 - 324
  • [10] Stealthy Data Exfiltration via TCP Sequence Numbers based Covert Channel
    Goverman, Jonah
    Tekeoglu, Ali
    PROCEEDINGS OF THE 2021 IEEE INTERNATIONAL CONFERENCE ON COMPUTER, INFORMATION, AND TELECOMMUNICATION SYSTEMS (IEEE CITS 2021), 2021, : 44 - 48