首页> 外文会议>International Conference on Cloud Computing and Security >Detection of Jitterbug Covert Channel Based on Partial Entropy Test
【24h】

Detection of Jitterbug Covert Channel Based on Partial Entropy Test

机译:基于部分熵测试的Jitterbug Covert通道检测

获取原文

摘要

Jitterbug is a typical delay-based covert timing channel and supplies reliable covert communication in a passive manner. The existing entropy-based detection scheme based on training samples may suffer from model mismatching, which results in detection performance deterioration. In this paper, a new detection method for Jitterbug based on partial entropy test is proposed. A fixed binning strategy without training samples is used to obtain bins distribution feature. The first-order entropy is calculated for several sets of partial successive bins and the weighted mean is used to calculate the final entropy value to distinguish Jitterbug from legitimate traffic. Furthermore, the influence of detection performance caused by network jitter is also discussed. Experimental results show that the proposed detection method achieves high detection performance and is less affected by network jitter.
机译:Jitterbug是一种基于典型的延迟封闭定时通道,并以被动方式提供可靠的隐蔽通信。基于训练样本的基于熵的检测方案可能遭受模型不匹配,这导致检测性能劣化。本文提出了一种基于部分熵试验的JITTERBUG的新检测方法。没有训练样本的固定分数策略用于获得箱体分配特征。为几组部分连续箱计算了一阶熵,并且加权均值用于计算最终的熵值,以区分Jitterbug与合法流量。此外,还讨论了网络抖动引起的检测性能的影响。实验结果表明,该检测方法达到了高检测性能,受网络抖动的影响较小。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号