首页> 外文会议>International Conference on Cloud Computing and Security >Detection of Jitterbug Covert Channel Based on Partial Entropy Test
【24h】

Detection of Jitterbug Covert Channel Based on Partial Entropy Test

机译:基于局部熵测试的Jitterbug隐蔽通道检测

获取原文

摘要

Jitterbug is a typical delay-based covert timing channel and supplies reliable covert communication in a passive manner. The existing entropy-based detection scheme based on training samples may suffer from model mismatching, which results in detection performance deterioration. In this paper, a new detection method for Jitterbug based on partial entropy test is proposed. A fixed binning strategy without training samples is used to obtain bins distribution feature. The first-order entropy is calculated for several sets of partial successive bins and the weighted mean is used to calculate the final entropy value to distinguish Jitterbug from legitimate traffic. Furthermore, the influence of detection performance caused by network jitter is also discussed. Experimental results show that the proposed detection method achieves high detection performance and is less affected by network jitter.
机译:Jitterbug是典型的基于延迟的隐蔽定时通道,并以被动方式提供可靠的隐蔽通信。现有的基于训练样本的基于熵的检测方案可能会出现模型不匹配的情况,从而导致检测性能下降。提出了一种基于局部熵检验的抖动检测方法。无需训练样本的固定装箱策略用于获得装箱分布特征。为几组部分连续的仓位计算一阶熵,并使用加权平均值计算最终熵值,以将Jitterbug与合法流量区分开。此外,还讨论了网络抖动对检测性能的影响。实验结果表明,该检测方法具有较高的检测性能,受网络抖动的影响较小。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号