2021
DOI: 10.1109/ojcoms.2021.3118697
|View full text |Cite
|
Sign up to set email alerts
|

Detection of Covert Timing Channel Based on Time Series Symbolization

Abstract: Covert Timing Channels(CTCs) is a technique to leak information. CTCs only modify inter-arrival time sequence(IATs) between packets, consequently, traditional network security mechanisms, such as firewalls and proxies, can not effectively detect CTCs. If CTCs are maliciously utilized by criminals, will pose a great threat to network security. Classic CTCs detection methods, such as KS-test, Entropy-test, etc, not only have less universality and robustness, but also require more sampled IATs to detect CTCs, the… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
3
1
1

Citation Types

0
5
0

Year Published

2022
2022
2024
2024

Publication Types

Select...
2
2
1
1

Relationship

0
6

Authors

Journals

citations
Cited by 8 publications
(5 citation statements)
references
References 22 publications
0
5
0
Order By: Relevance
“…According to Wu et al [53], there are three types of classic detection methods for CTCs: entropy-based, ML, and statistical-based methods. Ali summed up the drawbacks of the aforementioned techniques as follows:…”
Section: Covert Channel Detectionmentioning
confidence: 99%
See 1 more Smart Citation
“…According to Wu et al [53], there are three types of classic detection methods for CTCs: entropy-based, ML, and statistical-based methods. Ali summed up the drawbacks of the aforementioned techniques as follows:…”
Section: Covert Channel Detectionmentioning
confidence: 99%
“…To get around these shortcomings. Wu et al [53] proposed a time series symbolization-based detection technique for CTC identification. They convert interarrival times into symbolic representation using the k-Means clustering technique.…”
Section: Covert Channel Detectionmentioning
confidence: 99%
“…Additionally, the effectiveness of employing several machine learning methods for CTC detection across various encoding schemes and flow capacities was investigated by the authors in [14]. A symbolic CTC detection model was recently proposed by Wu et al in [15]. The traffic inter-arrival times were intended to be transformed into symbolic time series by their model.…”
Section: Related Workmentioning
confidence: 99%
“…Finally, Wu et al tested the detectability of different covert timing channels using ϵ-similarity, KS test, Entropy and Corrected Conditional Entropy tests as well as regularity metric in [30]. This is the only current work that evaluates the ϵ-similarity, and the authors reported that two of the tested channels where detectable with an accuracy of 98% and 100%, while JitterBug and TRCC were not detectable.…”
Section: Improvements and Derivatives Of The Detection Heuristicsmentioning
confidence: 99%