A network steganographic information encoding and mapping method, device and medium
By using multi-dimensional feature segmentation and encoding rules, secret information is segmented and mapped to multiple dimensions of IPv6 addresses, solving the problems of insufficient information capacity and security in existing network steganography methods, and achieving efficient and flexible information hiding.
Patent Information
- Application Number
- CN202411943626.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-27
- Publication Date
- 2026-01-23
- Estimated Expiration
- 2044-12-27
AI Technical Summary
Existing network steganography methods based on IP source addresses have low hiding capacity and low address utilization, making it difficult to achieve efficient information hiding.
By creating service nodes to record auxiliary information and employing multi-dimensional feature partitioning and encoding rules, secret information is segmented and mapped to multiple dimensions of IPv6 addresses, including prefixes, subnet identifiers, and interface identifiers, thereby achieving efficient encoding and mapping of information.
It increases the capacity of steganographic information, enhances concealment and security, adapts to different network environments, is highly flexible, and can be combined with other steganographic technologies to achieve cross-protocol steganographic information transmission.
Smart Images

Figure CN119814295B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to a network steganography information coding and mapping method, device and medium, belonging to the technical field of network communication and security. BACKGROUND
[0002] Big data analysis can skip data content and only mine intelligence from data background. When the communication behavior is found, the person using the ciphertext communication is very prominent, thereby becoming the key object of monitoring and analysis. Modern communication security not only requires content confidentiality, but also hopes to hide the process. Steganography technology is a technology for embedding secret messages in various carriers (such as digital images, audio, video or text) to achieve covert communication, which is an effective means to deal with big data intelligence acquisition and a necessary supplement to encryption technology.
[0003] Network steganography is a steganography method based on network protocol, which constructs a covert channel to transmit secret information. Specifically, the method mines the redundant fields in the network protocol and the rule loopholes of the network protocol, and places secret information in the network data packet, thereby realizing the transmission of secret information. Compared with text, image, audio, video and other steganography methods, network steganography can avoid network devices such as intermediate network nodes. At the same time, network steganography has transparency, that is, users have no direct perception of network data stream when accessing data.
[0004] Common network steganography methods mainly include storage type, time sequence type, hybrid type and other covert channels. The storage type network steganography generally selects to modify the header, payload and the like of the network protocol. The time sequence type network steganography refers to a network steganography method that embeds secret information by modifying the data packet stream structure and using the characteristic change of the time sequence during data transmission. The hybrid type network steganography refers to the combination of storage type and time sequence type network steganography methods. Other network steganography methods mainly hide secret information through the length information of the data packet and the classification information of the IP source address.
[0005] The method based on IP source address classification hides secret messages through the classification of the data packet source address field, and selects to use the IP address existing in the public network, which really exists in the network, so it is not easy to attract the attention of attackers. The method solves the existing network steganography method based on data packet field modification.
[0006] The existing IP source address-based network steganography method uses data source address classification and multi-dimensional feature mapping to combine information hiding according to information encoding rules, address classification and mapping rules. Specifically, the communication parties use different IP source addresses to represent a number of binary digital encodings. The service node is used to record the basic information and communication state of the communication parties, and the integrity of the secret information is confirmed by the service node. However, the existing IP source address classification-based method has low hiding capacity and low address utilization. Therefore, it is necessary to study more efficient related network steganography methods. SUMMARY
[0007] The application aims to provide a network steganography information encoding and mapping method, device and medium, which realizes fine utilization of IPv6 address space and efficient steganography. Different encoding and mapping rules are formulated for different address classifications, so that the steganography information capacity is maximized, the concealment is stronger, and the flexibility and security are good.
[0008] To achieve the above-mentioned purpose, the application realizes the following technical solutions:
[0009] A service node is created for recording auxiliary information of sending hidden secret messages, and the auxiliary information includes real IP addresses, IP address classification and number, multi-dimensional feature number and total number of data packets;
[0010] The sending party registers with the service node, and the registration information includes the real IP addresses and ports of the sending and receiving parties;
[0011] The binary information encoding and address mapping of the hidden secret messages to be sent are performed, and data packets are generated and sent to the service node of the sending party;
[0012] The service node establishes a communication connection and registers the total number of data packets of this communication, and then sends the total number of data packets to the receiving party;
[0013] After the sending party finishes sending, the receiving party checks whether the number of received data packets is consistent with the total number of data packets sent by the service node;
[0014] When the number of data packets is consistent, the receiving party decodes the binary string corresponding to the known information encoding rule and address mapping rule.
[0015] Preferably, the binary information encoding and address mapping are as follows:
[0016] The secret information M is encrypted to form a bit stream of L bits;
[0017] According to the type and function of the IP source address, all addresses are divided into an IPv6 address classification set mapped by IPv4 and pure IPv6 address classification set ;
[0018] The secret information M is segmented according to the size of the multidimensional characteristics of the IPv6 address. The first segment after segmentation is designated as M1, and the remaining segments are designated as M2. The address corresponding to segment M1 is... The address corresponding to information segment M2 ;
[0019] Convert each information segment into a decimal identifier;
[0020] according to and The information encoding segment is mapped to the corresponding decimal identifier.
[0021] Preferably, the multidimensional features The calculation method is as follows:
[0022] ,
[0023] in, Indicates the first The size of the value range of each dimension; where The number of multidimensional features;
[0024] The secret information M The results after segmentation based on the size of the multidimensional features are as follows:
[0025] ,
[0026] in, Classify addresses The corresponding binary information segment, to Classify addresses The Middle The binary information segments corresponding to each dimension, among which ;
[0027] Preferably, the address The length of the corresponding binary information segment M1 for:
[0028] ,
[0029] in, Indicates address classification The total number of addresses contained in it.
[0030] The address The length of the corresponding information segment M2 for:
[0031] .
[0032] Preferably, for IPv4 address, only one-dimensional feature mapping is performed; for IPv6 address, multi-dimensional features of IPv6 address are used for mapping, which include address structure hierarchy, such as prefix, subnet identification and interface identification.
[0033] Preferably, the IPv6 address mapping mode is as follows:
[0034] ,
[0035] wherein, IPv4 mapped IPv6 address is IPv4 address, indicates IPv4 address in the corresponding IPv4 mapped IPv6 address, is a set of IPv4 mapped IPv6 addresses, is a set of IPv4 addresses, is a set of IPv4 addresses, is a set of IPv4 addresses, is a corresponding decimal number.
[0036] Preferably, the IPv6 address mapping mode is as follows:
[0037] ,
[0038] ,
[0039] wherein, IPv4 mapped IPv6 address is IPv4 address, indicates a set of prefixes, indicates a set of subnets, indicates a set of interface identifications, indicates a set of IPv4 addresses, is a corresponding decimal value, is a corresponding decimal value, is a corresponding decimal value. Advantages of the present application are as follows:
[0040] (1) The method based on IP source address classification only (comparative method) segments information by simple modulo operation and respectively maps to IPv4 mapped address (total 16) and pure IPv6 address (total 256). Information capacity depends on classification space size (16 IPv4 mapped addresses and 256 pure IPv6 addresses). This results in less information carried by IPv4 address, which is easy to cause resource waste in actual application.
[0041] (1) The method based on IP source address classification only (comparative method) segments information by simple modulo operation and respectively maps to IPv4 mapped address (total 16) and pure IPv6 address (total 256). Information capacity depends on classification space size (16 IPv4 mapped addresses and 256 pure IPv6 addresses). This results in less information carried by IPv4 address, which is easy to cause resource waste in actual application.
[0042] The present application introduces multiple features such as subnet identification and interface identification, each of which can independently carry information. The IPv6 address is composed of a prefix, subnet identification, and interface identification, each of which maps different secret information. Through the cooperative coding of multiple features, the information capacity is significantly improved, and the secret information that can be carried is greater.
[0043] (2) Flexibility
[0044] The multi-dimensional features (prefix, subnet identification, interface identification, etc.) in the method of the present application provide high flexibility, and the coding rules of each dimension can be dynamically adjusted according to the application scenario. It can adapt to different network environments (such as prefix dynamicization and specific service division) and the carrying needs of various information types. The flexible mapping method is more easily combined with other steganography techniques to achieve cross-protocol steganographic information transmission.
[0045] (3) Security
[0046] The multi-dimensional mapping of the present application distributes information to multiple feature dimensions (prefix, subnet identification, interface identification), significantly improving the dispersion of steganographic traffic. Attackers need to monitor multiple dimensions simultaneously to infer the steganographic pattern, increasing the difficulty of detection and analysis. Through dynamic prefix and diversified mapping of features, steganographic communication has stronger randomness and uncertainty, further enhancing security. BRIEF DESCRIPTION OF DRAWINGS
[0047] The accompanying drawings are included to provide a further understanding of the present application, and constitute a part of the specification, which together with the embodiments of the present application, serve to explain the present application, and do not constitute a limitation on the present application.
[0048] Fig. 1 The present application is a method flowchart.
[0049] Fig. 2 The present application is a transmission flowchart. DETAILED DESCRIPTION
[0050] The technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, not all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor are within the scope of protection of the present application.
[0051] Embodiment 1
[0052] As Figs. 1-2As shown, a network steganographic information encoding and mapping method combines IP source address classification and multi-dimensional feature mapping to achieve fine utilization and efficient steganography of IPv6 address space. By formulating different encoding and mapping rules for different address classifications, the steganographic information capacity is maximized, the concealment is stronger, and good flexibility and security are provided. It includes:
[0053] S1: Create a service node for recording auxiliary information for sending hidden secret messages, which includes real IP addresses, IP address classification and number, multi-dimensional feature number, and total number of packets.
[0054] As a refinement of the above embodiment, recording the real IP address helps to trace the source of the message. The IP address classification and number are used for decoding secret information. The total number of data packets is used to confirm the transmission integrity between the two parties, preventing the loss or damage of steganographic information due to packet loss.
[0055] S2: The sender registers with the service node, and the registration information includes the real IP address and port of the sender and receiver.
[0056] S3: Perform binary information encoding and address mapping on the hidden secret message to be sent, and generate data packets, and send a request to the sender to the service node.
[0057] S4: The service node establishes a communication connection and registers the total number of data packets for this communication, and then sends the total number of data packets to the receiver.
[0058] S5: After the sender finishes sending, the receiver checks whether the number of received data packets is consistent with the total number of data packets sent by the service node.
[0059] S6: When the number of data packets is consistent, the receiver decodes the binary string corresponding to the known information encoding rule and address mapping rule.
[0060] As a refinement of the above embodiment, the information encoding method is as follows:
[0061] The secret information M is encrypted and forms a bit stream file of L bits, and is represented as: .
[0062] According to the type and function of the IP source address, all addresses S are divided into IPv4 mapped IPv6 address classification set and pure IPv6 address classification set . The address starts with a fixed prefix ::FFFF, indicating that it comes from IPv4 mapping. An address defined completely according to the IPv6 standard without a mapping prefix. According to the classification rule, the binary secret information M is split into two parts M1 and M2, and respectively corresponds to and Information segment. M is divided according to the size of the multi-dimensional feature , and is further divided into several segments:
[0063] ,
[0064] Among them, is the address classification corresponding binary information segment, to is the address classification corresponding binary information segment of the dimension, wherein .
[0065] M1 and M2 are segmented according to the address feature dimension respectively. For M1, since the scale is small, the IPv4 mapping address has single characteristics, and does not need to be divided according to multi-dimensional features. Therefore, M1 is only divided into one segment B1, and the length is:
[0066] ,
[0067] Among them, represents the total number of addresses contained in the address classification .
[0068] For M2, the overall length is:
[0069] ,
[0070] Since the pure IPv6 address has rich feature dimensions, it is divided into several segments, i.e. to , which respectively correspond to different IPv6 address features, such as prefix P, subnet identification E, interface identification I, etc. The length of each segment satisfies the following formula. Among them, is the size of the value range of the i-th dimension. Further description about this dimension will be expanded later. Information coding refers to converting each segment into decimal and representing it as .
[0071] ,
[0072] Among them, is the number of multi-dimensional features.
[0073] As a refinement of the above embodiment, the address mapping is specifically as follows:
[0074] For , due to its structural characteristics, only one-dimensional feature mapping is required, and the mapping rule is as follows:
[0075] ,
[0076] For , the multi-dimensional features of the IPv6 address are used for mapping. The relevant dimensions include the prefix P, the subnet identification E, and the interface identification I, etc. In particular, when the multi-dimensional features are the prefix P, the subnet identification E, and the interface identification I, respectively, there are , , ; the prefix P represents a set of network range prefixes , with a size of . The subnet identification E is used to distinguish a set of subnets , with a size of . The interface identification I is used to distinguish a set of hosts , with a size of . Then the bit number of the binary string of different dimensions is:
[0077] ,
[0078] Then M2 is divided into:
[0079] ,
[0080] The mapping rules are respectively:
[0081] ,
[0082] wherein represents the prefix set, represents the set of subnets, represents the set of interface identifications, represents the corresponding decimal value, represents the corresponding decimal value, represents the corresponding decimal value.
[0083] In particular, when the multi-dimensional features are the prefix P, the subnet identification E, and the interface identification I, respectively, there are
[0084]
[0085] That is: ;
[0086] The final steganographic address generation result is:
[0087] .
[0088] Encoding example:
[0089] Suppose the secret information M to be steganographed corresponds to the bit stream 10111010110011, with a length m = 14. The IP address space is divided into and . Among them, contains 16 addresses, with the following format:
[0090]
[0091] Among them, contains 256 addresses, which are:
[0092] (1) 2001:db8:85a3:1:: to 2001:db8:85a3:1::ff
[0093] (2) 2001:db8:85a3:2:: to 2001:db8:85a3:2::ff
[0094] (3) 2001:db8:85a3:3:: to 2001:db8:85a3:3::ff
[0095] (4) 2001:db8:85a3:4:: to 2001:db8:85a3:4::ff
[0096] According to the address classification ratio, the secret information M is divided into , . The split result is , .
[0097] Corresponding to decimal 11, corresponding to . Then, the multi-dimensional feature mapping is performed on corresponding. Suppose there is only a single value 2001:db8:1:: in the prefix set T1, that is, is 1, no further encoding is needed. The subnet identifier mapping has four choices, 2001:0db8:85a3:0001:: / 64, 2001:0db8:85a3:0002:: / 64, 2001:0db8:85a3:0003:: / 64, 2001:0db8:85a3:0004:: / 64, that is, is 4, then , i.e. 2001:0db8:85a3:0003:: / 64. The interface mapping identifies, whose range is 0 to 255 (hexadecimal FF), i.e. is 256, then is 0, then is 1, then The final stego address is: 2001:0db8:85a3:0003::b3.
[0098] Decoding example:
[0099] At the receiving side, suppose the IP address of the received data packet is ::FFFF:192.0.2.11 and 2001:0db8:85a3:0003::b3. The receiving side determines that they are and The address. For the SIPv4 address, the receiving side extracts 11 and converts it into binary 1011,. For the SIPv6 address, the receiving side extracts the length of each dimension according to the information table of the subnet identifier dimension , . In the information table of the subnet identifier dimension, it is found that 2001:0db8:85a3:0003:: / 64 is a binary 10 information segment. The hexadecimal b3 is extracted to obtain a binary information segment 10110011.
[0100] The embodiment of the present disclosure also provides a network steganography information coding and mapping device, comprising a processor and a memory. Optionally, the device can also comprise a communication interface and a bus. Wherein, the processor, the communication interface and the memory can complete the communication among each other through the bus. The communication interface can be used for information transmission. The processor can call the logical instructions in the memory to execute the network steganography information coding and mapping method of the above-mentioned embodiment.
[0101] In addition, the logical instructions in the above-mentioned memory can be realized in the form of a software functional unit and sold or used as an independent product, which can be stored in a computer readable storage medium.
[0102] The memory is a kind of computer readable storage medium, which can be used to store software programs, computer executable programs, such as program instructions / modules corresponding to the method in the embodiment of the present disclosure. The processor executes the program instructions / modules stored in the memory, thereby executing function application and data processing, i.e. realizing the network steganography information coding and mapping method in the above-mentioned embodiment.
[0103] The memory can include a program storage area and a data storage area, wherein the program storage area can store an operating system, application programs required by at least one function; the data storage area can store data created according to the use of the terminal device, etc. In addition, the memory can include a high-speed random access memory, and can also include a non-volatile memory.
[0104] The embodiment of the present disclosure provides a computer readable storage medium, which stores computer executable instructions, and the computer executable instructions are configured to execute the network steganography information coding and mapping method.
[0105] The computer readable storage medium described above can be a transitory computer readable storage medium or a non-transitory computer readable storage medium.
[0106] Finally, it should be noted that: the above only for the preferred embodiments of the present application, and not for limiting the present application, although the foregoing embodiments of the present application have been described in detail, for those skilled in the art, it still can be modified, or equivalent replacement of part of the technical features recorded in the foregoing embodiments. Any modification, equivalent replacement, improvement, etc. made within the spirit and principles of the present application shall be included within the scope of protection of the present application.
Claims
1. A method for encoding and mapping steganographic information on a network, characterized in that, include: A service node is created to record auxiliary information for sending hidden secret messages. The auxiliary information includes the real IP address, IP address category and number, number of each multi-dimensional feature, and total number of data packets. The sending service node is registered, and the registration information includes the real IP addresses and ports of both the sender and receiver. The hidden secret message to be sent is encoded in binary information and mapped to an address, and a data packet is generated and sent to the sending service node. The service node establishes a communication connection, registers the total number of data packets in this communication, and then sends the total number of data packets to the receiver; After the sender finishes sending, the receiver checks whether the number of data packets received is consistent with the total number of data packets sent by the service node. When the number of data packets is the same, the receiver decodes them into corresponding binary strings according to the known information encoding rules and address mapping rules; The binary information encoding and address mapping are specifically implemented as follows: The secret information M is encrypted to form an L-bit bit stream; Based on the type and function of the IP source address, all addresses are divided into IPv6 address categories that map from IPv4. and pure IPv6 address classification set ; The secret information M is segmented according to the size of the multidimensional characteristics of the IPv6 address. The first segment after segmentation is designated as M1, and the remaining segments are designated as M2. The address corresponding to segment M1 is... The address corresponding to information segment M2 ; Convert each information segment into a decimal identifier; according to and The decimal identifier corresponding to the information encoding segment is used for address mapping; The multidimensional features The calculation method is as follows: , in, Indicates the first The size of the value range of each dimension; where The number of multidimensional features; The secret information M is segmented according to the size of the multidimensional features, and the result is as follows: , in, Classify addresses The corresponding binary information segment, to Classify addresses The Middle The binary information segments corresponding to each dimension, among which ; The address The length of the corresponding binary information segment M1 for: , in, Indicates address classification The total number of addresses contained in it; The address The length of the corresponding information segment M2 for: 。 2. The network steganography encoding and mapping method according to claim 1, characterized in that, for Addresses are mapped using only one-dimensional features. for The address is mapped using the multidimensional features of the IPv6 address, which include... Address structure hierarchy.
3. The network steganography encoding and mapping method according to claim 2, characterized in that, The The address mapping method is as follows: , in, express corresponding IP address in A set of IPv6 addresses mapped from IPv4. for The corresponding decimal number.
4. The network steganography encoding and mapping method according to claim 3, characterized in that, The The address mapping method is as follows: , , in, Represents the prefix set, Represents the set of subnets. Represents a set of interface identifiers. express The corresponding decimal value, express The corresponding decimal value, express The corresponding decimal value.
5. A network steganography encoding and mapping device, comprising a processor and a memory storing program instructions, characterized in that, The processor is configured to execute the network steganography encoding and mapping method as described in any one of claims 1-4 when running the program instructions.
6. A computer-readable storage medium, characterized in that, It stores a computer program that, when executed by a processor, implements the network steganography encoding and mapping method as described in any one of claims 1-4 above.
Citation Information
Patent Citations
Reliable network steganography method based on IP source address
CN112422511A