A study on the covert channel detection of TCP/IP header using support vector machine

被引:0
|
作者
Sohn, T [1 ]
Seo, JT
Moon, J
机构
[1] Korea Univ, Ctr Informat Secur Technol, Seoul 136701, South Korea
[2] ETRI, Natl Secur Res Inst, Taejon, South Korea
关键词
intrusion detection; covert channel; support vector machine; TCP/IP protocol;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Nowadays, threats of information security have become a big issue in internet environments. Various security solutions are used as such problems' countermeasure; IDS, Firewall and VPN. However, a TCP/IP protocol based Internet basically has great vulnerability of protocol itself. It is especially possible to establish a covert channel using TCP/IP header fields such as identification, sequence number, acknowledgement number, timestamp and so on[3]. In this paper, we focus on the covert channels using identification field of IP header and the sequence number field of TCP header. To detect such covert channels, our approach uses a Support Vector Machine which has excellent performance in pattern classification problems. Our experiments showed that the proposed method could discern the abnormal cases(including covert channels) from normal TCP/IP traffic using a Support Vector Machine.
引用
下载
收藏
页码:313 / 324
页数:12
相关论文
共 50 条
  • [1] Evaluation of the IP Identification Covert Channel Anomalies Using Support Vector Machine
    Shehab, Manal
    Korany, Noha
    Sadek, Nayera
    2021 IEEE 26TH INTERNATIONAL WORKSHOP ON COMPUTER AIDED MODELING AND DESIGN OF COMMUNICATION LINKS AND NETWORKS (CAMAD), 2021,
  • [2] Covert channel detection in the ICMP payload using support vector machine
    Sohn, T
    Moon, J
    Lee, S
    Lee, D
    Lim, J
    COMPUTER AND INFORMATION SCIENCES - ISCIS 2003, 2003, 2869 : 828 - 835
  • [3] Support vector machine based ICMP covert channel attack detection
    Sohn, T
    Noh, T
    Moon, J
    COMPUTER NETWORK SECURITY, 2003, 2776 : 461 - 464
  • [4] IP Covert Channel Detection
    Cabuk, Serdar
    Brodley, Carla E.
    Shields, Clay
    ACM TRANSACTIONS ON INFORMATION AND SYSTEM SECURITY, 2009, 12 (04)
  • [5] Covert Channel Detection Using Machine Learning
    Cavusoglu, Imge Gamze
    Alemdar, Hande
    Onur, Ertan
    2020 28TH SIGNAL PROCESSING AND COMMUNICATIONS APPLICATIONS CONFERENCE (SIU), 2020,
  • [6] Header Based Email Spam Detection Framework Using Support Vector Machine (SVM) Technique
    Khamis, Siti Aqilah
    Foozy, Cik Feresa Mohd
    Aziz, Mohd Firdaus Ab
    Rahim, Nordiana
    RECENT ADVANCES ON SOFT COMPUTING AND DATA MINING (SCDM 2020), 2020, 978 : 57 - 65
  • [7] Distributed denial of service detection using TCP/IP header and traffic measurement analysis
    Limwiwatkul, L
    Rungsawang, A
    IEEE INTERNATIONAL SYMPOSIUM ON COMMUNICATIONS AND INFORMATION TECHNOLOGIES 2004 (ISCIT 2004), PROCEEDINGS, VOLS 1 AND 2: SMART INFO-MEDIA SYSTEMS, 2004, : 605 - 610
  • [8] Network based detection of passive covert channels in TCP/IP
    Tumoian, E
    Anikeev, M
    LCN 2005: 30TH CONFERENCE ON LOCAL COMPUTER NETWORKS, PROCEEDINGS, 2005, : 802 - 807
  • [9] Detection of TCP covert channel based on Markov model
    Jiangtao Zhai
    Guangjie Liu
    Yuewei Dai
    Telecommunication Systems, 2013, 54 : 333 - 343
  • [10] Detection of TCP covert channel based on Markov model
    Zhai, Jiangtao
    Liu, Guangjie
    Dai, Yuewei
    TELECOMMUNICATION SYSTEMS, 2013, 54 (03) : 333 - 343