###
Journal of Software:2019.30(9):2733-2759

差分信息熵的网络时序型隐蔽信道检测
张宇飞,沈瑶,杨威,肖?汉,黄刘生
(中国科学技术大学 苏州研究院, 江苏 苏州 215123;中国科学技术大学 软件学院, 江苏 苏州 215123;中国科学技术大学 苏州研究院, 江苏 苏州 215123;中国科学技术大学 计算机科学与技术学院, 安徽 合肥 230026)
Detecting Covert Timing Channels Based on Difference Entropy
ZHANG Yu-Fei,SHEN Yao,YANG Wei,XIAO Yan-Han,HUANG Liu-Sheng
(Suzhou Research Institute, University of Science and Technology of China, Suzhou 215123, China;School of Software Engineering, University of Science and Technology of China, Suzhou 215123, China;Suzhou Research Institute, University of Science and Technology of China, Suzhou 215123, China;School of Computer Science and Technology, University of Science and Technology of China, Hefei 230026, China)
Abstract
Chart / table
Reference
Similar Articles
Article :Browse 100   Download 150
Received:October 18, 2016    Revised:September 05, 2017
> 中文摘要: 网络隐蔽信道是以合法网络通信信道作为载体建立的一种隐蔽通信技术.相比信息加密,网络隐蔽信道不仅隐藏了传输信息的内容,同时还隐藏了传输信息的行为,因而具有更强的隐蔽性.隐蔽信道技术的出现,使得网络通信中的信息安全和隐私保护受到了极大的威胁,尤其是间谍和其他不法分子可以利用隐蔽信道绕过系统的安全检查机制,窃取机密信息.因此,研究高效且准确率高的隐蔽信道检测技术势在必行.在分析和总结前人研究成果的基础上,提出了差分信息熵的概念,进而提出了基于差分熵的网络时序型隐蔽信道检测算法.首先给出了差分信息熵的定义和相关特性,然后给出了基于差分信息熵的隐蔽信道检测算法的实现原理,以及算法在具体实现过程中的参数设定,最后设计实验检测算法的性能和效果.实验结果表明,基于差分信息熵的检测算法可以有效检测IPCTC,TRCTC,JitterBug时序型隐蔽信道.
Abstract:Covert channel is a way to building confidential channels based on the legitimate channels (also named with ‘overt channel’). Compared with the encryption technology, covert channel has stronger covertness because it conceals the behavior of covert communication as well as the transmitted message it contains. The emergence of covert channels has threatened the information security and personal privacy in public Internet. Some hackers and criminals, in particular, adopt covert channels to steal secret information bypassing the inspection of security facilities. It is, therefore, crucial to design and deploy more efficient and accurate detection algorithm for covert channels. In this study, a detection algorithm is proposed for covert timing channels based on the difference entropy. First, the definition of difference entropy is introduced, then, the principle of the algorithm is proposed, and the description of the implementation of this algorithm and parameter optimization is given. Lastly, the performance of the detection algorithm is evaluated through experiments, and experimental results show that proposed algorithm is effective on the detection of the IPCTC, TRCTC, JitterBug covert timing channels.
文章编号:     中图分类号:TP393    文献标志码:
基金项目:国家自然科学基金(61572456);江苏省自然科学基金(BK20151241) 国家自然科学基金(61572456);江苏省自然科学基金(BK20151241)
Foundation items:National Natural Science Foundation of China (61572456); Natural Science Foundation of Jiangsu Province of China (BK20151241)
Reference text:

张宇飞,沈瑶,杨威,肖?汉,黄刘生.差分信息熵的网络时序型隐蔽信道检测.软件学报,2019,30(9):2733-2759

ZHANG Yu-Fei,SHEN Yao,YANG Wei,XIAO Yan-Han,HUANG Liu-Sheng.Detecting Covert Timing Channels Based on Difference Entropy.Journal of Software,2019,30(9):2733-2759