Journal of Software:2011.22(zk2):17-26

(解放军信息工程大学 信息工程学院 网络工程系,河南 郑州 450002)
Flow Watermarking Scheme Based on Packet Reordering
ZHANG Lian-Cheng,WANG Zhen-Xing,XU Jing
(Department of Network Engineering, College of Information Engineering, PLA Information Engineering University, Zhengzhou 450002, China)
Article :Browse 2251   Download 3013
Received:February 15, 2011    Revised:May 31, 2011
> 中文摘要: 当前流水印载体局限于包载荷、流速率和包时间3 种.然而,基于包载荷的流水印技术与具体应用层协议有关,难以处理加密流量,且易被检测和过滤;基于流速率和基于包时间的流水印技术难以从根本上抵御时间扰乱,且存在易被检测、水印容量小等问题.采用包序作为流水印载体,提出一种基于包序重排的新型流水印技术PROFW.将纠错码理论引入到水印信息编码中,大大提高了PROFW 技术的鲁棒性,并引入概率调制思想,将包序重排程度控制在正常范围内,保证了PROFW 技术的隐蔽性.测试结果表明,PROFW 技术在保证隐蔽性的前提下,对于自然产生和主动引入的时间干扰和包乱序具有较强的鲁棒性.与当前典型流水印技术相比,PROFW 技术不但在应对时间扰乱和包乱序时的鲁棒性更强,而且提高了水印容量.
中文关键词: 流水印  包序重排  鲁棒性  纠错码  概率调制
Abstract:Watermark carriers of existing network flow watermarking schemes are limited to packet payload, traffic rate, and packet timing. However, packet payload is based on flow watermarking schemes, which depend on specific application protocols, such as telnet and rlogin, but encryted traffic and are invisible to traffic interceptors. At the same time, traffic rate and packet timing based ones are vulnerable to timing perturbation introduced by network transmission and attackers. Even worse, most of them have a low watermark capacity and are visible to multi-flow attack, mean-square autocorrelation attack and timing analysis attacks. This paper utilizes packet order as a watermark carrier and proposes a novel packet reordering based flow watermarking (PROFW) scheme. To achieve robustness against packet out-of-order pertubation, a theory of error correcting code is introduced into watermark encoding. Meanwhile, this paper utilizes a stochastic modulation approach to increase the stealthiness of PROFW scheme by controlling packet reordering degree not exceeding normal levels. Empirical results prove its robustness against timing and packet out-of-order pertubations, introduced by network transmission and deliberately by attackers. Compared with typical flow watermarking schemes, PROFW scheme, which has a higher watermark capacity, is more robust against timing and packet out-of-order pertubations.
基金项目:国家高技术研究发展计划(863)(2006AA01Z449, 2007AA01Z2A1); 国家重点基础研究发展计划(973)(2007CB307102) 国家高技术研究发展计划(863)(2006AA01Z449, 2007AA01Z2A1); 国家重点基础研究发展计划(973)(2007CB307102)
Foundation items:
