Concealed channel detection method based on multi-scale flow analysis technology

A covert channel and detection method technology, which is applied to instruments, character and pattern recognition, digital transmission systems, etc., can solve the problem that covert channels cannot have in-depth detection, so as to improve comprehensiveness and accuracy, ensure transmission security, and reduce The effect of false positive rate and false negative rate

Active Publication Date: 2020-08-25
NAT COMP NETWORK & INFORMATION SECURITY MANAGEMENT CENT +1
View PDF5 Cites 3 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

[0003] In view of the above problems, the present invention provides a covert channel detection method based on multi-scale flow analysis technology, which uses multi-scale deep analysis technology to analyze the characteristics of network data in three dimensions: single data packet, session flow and communication flow, A multi-scale covert channel detection model is established to solve the current problem that the covert channel cannot be comprehensively and deeply detected due to the variety of covert channels, thereby reducing the false alarm rate and false negative rate of covert channel detection, and improving the detection of covert channels. The comprehensiveness and accuracy of the detection helps to ensure the security of network information transmission

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • Concealed channel detection method based on multi-scale flow analysis technology
  • Concealed channel detection method based on multi-scale flow analysis technology
  • Concealed channel detection method based on multi-scale flow analysis technology

Examples

Experimental program
Comparison scheme
Effect test

Embodiment

[0059] Such as figure 1 As shown, a covert channel detection method based on multi-scale flow analysis technology, including the following steps:

[0060] S1. Obtain information about the scene to be detected and analyzed, and collect network traffic data in the scene to be detected and analyzed through DPDK;

[0061] S2. Perform preprocessing on the collected network traffic data, and obtain a single data packet, session flow and communication flow from three dimensions respectively;

[0062] S3. Establishing a corresponding metadata database according to the relevant characteristics of a single data packet, a session flow, and a communication flow;

[0063] S4. Import the obtained single data packet, session flow and communication flow into the corresponding metadata database for black-and-white matching to obtain prior knowledge;

[0064] S5. Establish a multi-scale feature analysis model based on the combination of relevant features and prior knowledge of a single data p...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to view more

PUM

No PUM Login to view more

Abstract

The invention discloses a concealed channel detection method based on a multi-scale flow analysis technology, and the method comprises the following steps: obtaining the information of a detection andanalysis scene, and collecting the network traffic data in the detection and analysis scene through DPDK; preprocessing the collected network traffic data to obtain a single data packet, a session flow and a communication flow; establishing a corresponding meta-database according to the related characteristics of the single data packet, the session flow and the communication flow; importing the obtained single data packet, session flow and communication flow into the corresponding meta-database for black and white matching to obtain priori knowledge; establishing a multi-scale feature analysis model; and importing the obtained single data packet, session flow and communication flow into the multi-scale feature analysis model for analysis and detection, and generating a detection report. According to the invention, the false alarm rate and missing report rate of concealed channel detection can be effectively reduced, the comprehensiveness and accuracy of concealed channel detection areimproved, and the transmission security of network information is ensured.

Description

technical field [0001] The invention relates to the technical field of covert channel detection methods, in particular to a covert channel detection method based on multi-scale flow analysis technology. Background technique [0002] As a kind of "private channel in the network, invisible channel in the channel, and non-channel channel", the network covert channel has the characteristics of cross-network heterogeneity, diverse protocols, polymorphic applications, arbitrary hidden positions, and complex hidden methods. Many traditional security detection devices are deployed, but there are still a large amount of unidentifiable data and protocols, and these communications cannot be inspected and supervised. Most of the traditional covert channel detection technologies are aimed at single-type and single-scale detection schemes, with poor generalization ability and unable to be effective for new multi-modal network covert channels. It is urgent to propose new ideas and new meth...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to view more

Application Information

Patent Timeline
no application Login to view more
Patent Type & Authority Applications(China)
IPC IPC(8): H04L29/06H04L12/26G06K9/62
CPCH04L63/1416H04L63/20H04L43/04H04L43/06G06F18/24155
Inventor 张健高强唐彰国林星辰李焕洲陈禹
Owner NAT COMP NETWORK & INFORMATION SECURITY MANAGEMENT CENT
Who we serve
  • R&D Engineer
  • R&D Manager
  • IP Professional
Why Eureka
  • Industry Leading Data Capabilities
  • Powerful AI technology
  • Patent DNA Extraction
Social media
Try Eureka
PatSnap group products