Self-adaptive hybrid covert channel construction method based on dynamic flow perception
By combining timing-type and storage-type covert channels in IPv6 networks, utilizing IPv6 protocol redundant fields and deep neural network models, and dynamically adjusting covert channel strategies, the problems of confidentiality and reliability of data transmission in IPv6 networks are solved, achieving efficient and secure data transmission.
Patent Information
- Application Number
- CN202510892742.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-30
- Publication Date
- 2025-09-26
AI Technical Summary
In the IPv6 network environment, traditional encryption algorithms change the data packet structure and traffic characteristics, which can easily attract the attention of attackers and lead to data leakage. In addition, the concealment and transmission reliability of a single covert channel in the network environment are insufficient.
Combining timing-type and storage-type covert channels, it monitors network traffic in real time, dynamically adjusts covert channel strategies, and utilizes redundant fields of the IPv6 protocol and deep neural network models to embed secret information and optimize communication efficiency and security.
Provides robust, flexible, and efficient covert communication solutions in complex network environments, improving the confidentiality and reliability of data transmission and adapting to changes in network load and congestion levels.
Smart Images

Figure CN120710751A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of secure communication technology, and in particular to a method for constructing an adaptive hybrid covert channel based on dynamic traffic perception. Background Art
[0002] With the rapid development of intelligent technologies such as the Internet of Things, cloud computing, and big data, various smart devices have rapidly become popular and connected to the internet worldwide, leading to an unprecedented explosion in data communication between devices. The IPv6 protocol, with its vast address space, flexible address allocation mechanism, and new features such as multicast and arbitrary addresses, not only effectively alleviates the problem of address resource constraints but also provides a broader technical space for future network communication architectures. However, due to the large number of devices and frequent communications in the IPv6 environment, the massive amount of data often contains sensitive information, personal privacy, and operational data of critical infrastructure, posing an increasingly severe security threat during transmission. While traditional data protection measures based on encryption algorithms can ensure the confidentiality of transmitted data content to a certain extent, encryption methods significantly alter the packet structure and traffic characteristics, easily attracting the attention of attackers and leading to data leaks.
[0003] Compared to traditional encryption techniques, covert channel technology can ensure that the structure and traffic characteristics of data packets are not significantly altered. It cleverly hides secret information in redundant fields or timing characteristics, effectively reducing the risk of attackers identifying and analyzing the data during transmission. Covert channels can be divided into timing-based covert channels and storage-based covert channels. Timing-based covert channels utilize the timing characteristics between data packets to transmit secret information, which is highly concealed but susceptible to factors such as network jitter and latency. Storage-based covert channels embed secret information by modifying redundant fields in the IPv6 protocol header. This is less susceptible to network conditions, but less concealed than timing-based covert channels.
[0004] Therefore, there is a need for an adaptive hybrid covert channel construction method that is highly concealed and not easily affected by the network environment. Summary of the Invention
[0005] In view of this, the present invention provides an adaptive hybrid covert channel construction method based on dynamic traffic perception. By monitoring the dynamic changes of network traffic in real time, combining the characteristics of timing-type and storage-type covert channels, and adjusting the covert channel construction strategy according to the traffic congestion level and network status, the security and concealment of data transmission are improved, while optimizing communication efficiency.
[0006] To this end, the present invention provides the following technical solutions: A method for constructing an adaptive hybrid covert channel based on dynamic traffic perception, comprising: Construct a hybrid covert channel including a timing covert channel and a storage covert channel; Real-time monitoring of network traffic conditions and calculation of network congestion levels; Determining the proportion of the timing-type covert channel and the storage-type covert channel in the hybrid covert channel based on the degree of network congestion; dividing the secret information to be sent according to the proportion to obtain the information to be sent by the timing-type covert channel and the information to be sent by the storage-type covert channel; The information to be sent through the timing type covert channel is sent through the timing type covert channel, and the information to be sent through the storage type covert channel is sent through the storage type covert channel.
[0007] Furthermore, the network congestion level is defined by the target group's actual network traffic data transmission time interval, including:
[0008] in, Indicates the degree of network congestion; Indicates the target group's actual network traffic data transmission time interval The cumulative distribution function of Indicates the target group's actual network traffic data transmission time interval The reference line function value of It is the total number of real network traffic data transmission intervals of the target group in the current network environment.
[0009] Furthermore, the proportion of the sequential covert channel in the hybrid covert channel includes:
[0010] in, It is a preset constant obtained by least squares fitting based on a large number of experimental results. e is the base of the natural logarithm, and K represents the degree of network congestion.
[0011] Furthermore, the information to be sent through the time-series covert channel is , where R represents the proportion of sequential covert channels in hybrid covert channels, and n represents the total number of bits of secret information converted into binary bit strings; The information to be sent through the storage-type covert channel: ,in Indicates rounding down.
[0012] Furthermore, the storage-type covert channel includes: determining a field carrier of the binary secret information, and dividing the binary secret information into a predetermined length according to the field carrier as a target bit string; Determine the basic structure of the data packet and the fields for storing secret information; The secret information target bit string is embedded into a preset field of the data packet.
[0013] Furthermore, the time-series covert channel includes: Determine the transmission time interval of data packets in the target group's real network traffic data and calculate the corresponding cumulative probability distribution; Based on the transmission time intervals of data packets in the target group's real network traffic data and the corresponding cumulative probability distribution, a deep neural network model is used to output a mapping from transmission time intervals to cumulative distribution probability values and an inverse mapping from cumulative distribution probability values to transmission time intervals. Encoding the coded symbol values of the binary secret information using a simulated fountain code technique, and assigning a probability interval to each coded symbol value to obtain a mapping relationship between the coded symbol value and the probability; the sender determines the transmission time interval distribution of the data packet to be sent based on the inverse mapping and the random probability value within the probability interval, and sends the data packet using the transmission time interval as the sending time interval; The receiver receives the real network traffic data of the target group and determines the arrival time interval distribution of the data packets as the transmission time interval distribution; and determines the probability value corresponding to the transmission time interval based on the transmission time interval distribution through the mapping; The coding symbol value corresponding to the transmission time interval is determined by combining the mapping relationship between the coding symbol value and the probability and the probability value corresponding to the transmission time interval.
[0014] Furthermore, the field carrier of the binary secret information includes: a traffic category field, a hop limit field, a flow label field, an option field of a hop-by-hop option extension header, and a reserved field of a fragment extension header.
[0015] Furthermore, the deep neural network includes: The output value is limited to between 0 and 1 through the Sigmoid activation function.
[0016] Furthermore, a cubic spline interpolation method is used to calculate the cumulative distribution probability value of the transmission time interval, and an inverse mapping from the cumulative distribution probability value to the transmission time interval is obtained.
[0017] Advantages and positive effects of the present invention: The hybrid covert channel construction method based on dynamic traffic perception in an IPv6 environment provided by the present invention optimizes the covert channel construction strategy based on real-time traffic analysis, so that it can adapt to changes in different network loads and congestion levels, ensuring the reliability and confidentiality of data covert transmission, thereby meeting the requirements of both communicating parties for secure communication.
[0018] 1) Considering that the basic header and extension header in the IPv6 protocol have abundant redundant fields, the values of these fields are usually not modified or paid attention to in normal communication. Based on the characteristics of redundant fields, an IPv6 multi-field storage covert channel is designed. By rationally utilizing the field values, the stability of information transmission is guaranteed.
[0019] 2) Considering the temporal regularity of data transmission in networks, a deep neural network model is used to simulate and predict the dynamic characteristics of real network traffic data for the target group. This model accurately captures the temporal characteristics of network traffic, providing a robust temporal framework for the encryption of secret information and ensuring the confidentiality of information transmission.
[0020] 3) The simulated fountain code technology is used to encode secret information, improving the information's anti-interference ability in noise interference and packet loss environments, thereby ensuring the reliability and security of information transmission.
[0021] 4) Taking into account the diversity and complexity of traffic in the IPv6 network environment, the construction scheme of the hybrid covert channel is intelligently adjusted according to the real-time monitored network traffic characteristics, combining the advantages of the timing-based covert channel and the storage-based covert channel to ensure the concealment and reliability of the transmission process.
[0022] Based on the above, this invention has broad application prospects in the field of covert communications, especially for covert data transmission in IPv6 networks. The proposed adaptive hybrid covert channel construction method based on dynamic traffic awareness can provide a stable and reliable solution for covert communications under varying network loads and traffic conditions. Furthermore, it has certain reference value for future research on covert communication technologies based on deep learning and network traffic analysis. BRIEF DESCRIPTION OF THE DRAWINGS
[0023] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative labor.
[0024] Figure 1 This is a flow chart of the adaptive hybrid covert channel construction method based on dynamic traffic perception in Example 1.
[0025] Figure 2 This is the system model diagram of Example 1.
[0026] Figure 3 This is a framework diagram of the storage-type covert channel of Example 1.
[0027] Figure 4 This is a framework diagram of the time-series covert channel of Example 1.
[0028] Figure 5 This is a diagram showing the distribution of real network traffic data of the target group fitted by the deep neural network model of Example 1.
[0029] Figure 6 This is a comparison chart of the secret information transmission bit error rate under different network congestion levels in Example 2.
[0030] Figure 7 This is a comparison chart of the bit error rate of secret information transmission under different channel interferences in Example 2.
[0031] Figure 8 This is a comparison chart of the Kolmogorov-Smirnov test values under different covert channels in Example 2.
[0032] Figure 9 This is a comparison chart of the Kullback-Leibler divergence test under different covert channels in Example 2.
[0033] Figure 10 This is a comparison chart of the effectiveness of the SVM detection system in detecting covert channels in Example 2. DETAILED DESCRIPTION
[0034] In order to enable those skilled in the art to better understand the solutions of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the embodiments described are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of the present invention.
[0035] It should be noted that the terms "first", "second", etc. in the description and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that the numbers used in this way can be interchanged where appropriate, so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0036] This invention combines a timing-based covert channel with a storage-based covert channel, proposing a hybrid covert channel that combines both timing and storage characteristics. This hybrid channel effectively addresses the shortcomings of a single covert channel in terms of concealment and transmission reliability. By combining the advantages of both covert channels, the invention improves transmission stability during communication while maintaining high concealment. Furthermore, based on the congestion level of the target group's real-world network traffic data, an adaptive covert channel optimization method is designed that dynamically adjusts the covert channel's structure and parameters, thereby providing a more robust, flexible, and efficient covert communication solution in complex network environments.
[0037] A method for constructing an adaptive hybrid covert channel based on dynamic traffic perception, comprising: Design an IPv6 multi-field storage covert channel: Utilize the multiple field characteristics of the IPv6 protocol to hide secret information in different fields of the data packet.
[0038] Design a temporal covert channel based on deep neural network and simulated fountain code: use deep neural network to model the transmission interval, and combine the simulated fountain code technology to embed secret information into the transmission time interval.
[0039] Since time-series covert channels are easily affected by the network environment, a traffic-adaptive covert channel optimization method is used to intelligently select the optimal covert channel solution to ensure optimal concealment and transmission efficiency under different network conditions.
[0040] Example 1 Combine Figure 1 As shown in FIG, the adaptive hybrid covert channel construction method based on dynamic traffic perception in an IPv6 environment includes the following steps: S1: Utilizes the multiple field characteristics of the IPv6 protocol to hide secret information in the traffic label, flow category, and hop limit of the basic header, as well as the hop-by-hop options header and fragment extension header of the extended header, as an IPv6 multi-field storage-type covert channel to improve the confidentiality and robustness of information transmission.
[0041] S2: Use deep neural networks to model the transmission intervals and combine them with simulated fountain code technology to embed secret information into the transmission time intervals as a temporal covert channel.
[0042] S3: By integrating the advantages and disadvantages of timing-based covert channels and storage-based covert channels, and based on a traffic-adaptive covert channel optimization algorithm, it intelligently selects the optimal covert channel solution to ensure optimal concealment and transmission efficiency under different network conditions.
[0043] S1 includes: S1-1: Parse the txt file carrying secret information to obtain binary secret information; determine the field carrier of the secret information, divide the binary secret information into preset lengths according to the field carrier, and obtain the target bit string of the secret information.
[0044] S1-2: Determine the basic structure of the data packet, including: destination address, source address, transmission protocol, and preset fields for storing secret information.
[0045] S1-3: Embed the secret information target bit string into a data packet with a preset structure.
[0046] The target bit string of secret information is embedded into a preset field in the data packet. Using a pseudo-random selector driven by a pre-shared key between the sender and receiver, the flow label and flow category in the basic IPv6 header, as well as the corresponding fields in the Hop-by-Hop Options and Fragment headers in the extension headers, are dynamically selected and combined to embed the secret information.
[0047] S1-4: Select the appropriate protocol to send the data packet based on the constructed data packet and network conditions to ensure the integrity and confidentiality of the information.
[0048] S2 includes the following steps: S2-1: Encode the binary secret information by simulating the fountain code to obtain the encoding symbol value of the binary secret information; Define a binary secret information set , where k is the total number of information nodes.
[0049] Each symbolic node is generated by No. Column and secret information bit string Multiply to get a set of symbolic nodes :
[0050] in, is a A matrix where each matrix element Representative The information node and The weights between symbolic nodes.
[0051] S2-2: Determine the transmission time interval of data packets in the target group's real network traffic data and calculate the corresponding cumulative probability distribution.
[0052] 1) Define the transmission time difference between adjacent data packets in the target group's real network traffic data as the transmission time interval, and the calculation formula is:
[0053] Among them, i represents the packet sequence number in the target group’s real network traffic data, represents the i-th transmission time interval, Indicates the number of data packets in the target group's real network traffic data. Represents event time, where each data point represents the event time of a data packet; the transmission time interval IAT is the difference between the event times of adjacent consecutive data packets.
[0054] 2) All transmission time intervals of the target group's real network traffic data Sort from small to large to get the ascending sequence of transmission time intervals .
[0055] And calculate the cumulative distribution probability corresponding to the ascending sequence of transmission time intervals. The calculation formula is:
[0056] Among them, the number of packets of the target group’s real network traffic data is , then there are N transmission time intervals; The cumulative probability distribution function representing the time interval between packet transmissions.
[0057] S2-3: Fit the transmission time interval distribution of the target group's real network traffic data through a deep neural network model.
[0058] 1) Based on the transmission time intervals of data packets in the target group's real network traffic data and the corresponding cumulative probability distribution, a deep neural network model is used to output a mapping from transmission time intervals to cumulative distribution probability values, and an inverse mapping from cumulative distribution probability values to transmission time intervals.
[0059] The ascending sequence of transmission time intervals obtained by S2-2 and its corresponding cumulative probability value Input the deep neural network model for learning to obtain the mapping from transmission time interval to cumulative distribution probability value , and use the interpolation function to obtain the inverse mapping from the cumulative distribution probability value to the transmission time interval .
[0060] 2) The sender assigns a probability interval to each coded symbol based on the inverse mapping to determine the transmission time interval distribution of the data packet to be sent: For each Uniformly distribute probability intervals , realize each symbol node Corresponding to a probability interval , and using the inverse mapping The transmission time interval distribution of the data packets to be sent in the real network traffic data of the time-series covert channel target group is obtained, and the formula is expressed as:
[0061] in, Indicates that in the probability interval Randomly pick a value from for inverse mapping.
[0062] The sender distributes the transmission time interval As the sending time interval, the information is sent.
[0063] S2-4: The receiver receives the target group's real network traffic data and determines the encoding symbol value through inverse mapping.
[0064] 1) The receiver receives the real network traffic data of the target group and determines the transmission time interval distribution of the data packets. Based on the transmission time interval distribution, the probability value corresponding to the data packet transmission time interval is determined by mapping.
[0065] The arrival time interval of data packets is used as the transmission time interval, and the transmission time interval distribution is mapped from the transmission time interval to the cumulative distribution probability value. , calculate the probability value of the time interval distribution of the target group's real network traffic data, the formula is expressed as:
[0066] in, Indicates the transmission time interval distribution of the target group’s real network traffic data packets, represents the mapping of transmission time interval to cumulative probability value, represents the probability corresponding to the i-th transmission time interval.
[0067] 2) Determine the coded symbol value corresponding to the transmission time interval based on the probability interval assigned to each coded symbol by the sender.
[0068] According to the probability value corresponding to the transmission time interval and the mapping relationship between the coded symbol value and the probability interval in S2-3, the coded symbol corresponding to the transmission time interval is determined. :
[0069] in, Indicates the probability value found The corresponding probability interval , and map to obtain the encoding symbols.
[0070] S2-5: The obtained coding symbol The encrypted binary secret information is obtained using the BP (Belief Propagation Decoding Algorithm) algorithm.
[0071] S3 includes the following steps: S3-1: Capture the real network traffic data of the target group and obtain the current network congestion level through the data packet transmission time interval.
[0072] Monitor the transmission time interval of data packets in the target group's real network traffic data and calculate its cumulative distribution function .
[0073] The interval of the transmission time interval of the data packets in the target group’s real network traffic data is defined as , then the corresponding reference line equation is .
[0074] The cumulative distribution probability value corresponding to each transmission time interval Function value with reference line The average distance is used as the degree of network congestion, and the calculation formula is:
[0075] in, is the total number of transmission time intervals of data packets in the real network traffic data of the target group; Indicates the degree of network congestion.
[0076] S3-2: Determine the ratio of information sent through storage-type covert channels and timing-type covert channels based on the current network congestion level.
[0077] Monitor the traffic status of the network in real time, and calculate the network congestion level using step S3-1 after a fixed time interval . And according to the degree of network congestion Determine the proportion of sequential covert channels in hybrid covert channels , the calculation formula is:
[0078] in, It is a preset constant obtained by least squares fitting a large number of experimental results. e is the base of the natural logarithm.
[0079] S3-3: Based on the proportion calculated in step S3-2 , processing the secret information that needs to be sent, so that the storage type covert channel and the timing type covert channel each send a certain proportion of secret information, improving the transmission reliability and ensuring confidentiality.
[0080] Example 2 Figure 2 This is a system diagram of the adaptive hybrid covert channel construction method based on dynamic traffic sensing in this embodiment. The system includes a sender, a receiver, and a transmission channel. The sender monitors network traffic in real time and adaptively selects either a timing-based covert channel or a storage-based covert channel to transmit secret information. The receiver decodes the received secret information to recover it.
[0081] Figure 3 The sender uses a data embedding tool to embed secret information into the IPv6 basic header and extension header to generate an IPv6 message carrying secret information.
[0082] Figure 4 This is a diagram of the timing-based covert channel framework in this embodiment. A deep neural network model is used to fit the target group's real-world network traffic data distribution. Secret information is then embedded into the packet transmission interval using simulated fountain codes and the fitted model for encoding and modulation. Upon receiving the corresponding packet, the receiver retrieves the secret information through the fitted model and BP decoding.
[0083] Figure 5 This figure shows the effect of fitting the deep neural network model to the target group's real network traffic data distribution in this embodiment. The deep neural network model fits the target group's real network traffic data distribution more closely, and the fitting effect is better than Weibull function fitting and two-state Markov modulation fitting methods.
[0084] The adaptive hybrid covert channel construction method based on dynamic traffic perception includes the following steps: S1 utilizes the multiple field characteristics of the IPv6 protocol to hide secret information in the traffic label, flow category and hop limit of the basic header, as well as the hop-by-hop options header and fragment extension header of the extended header, as an IPv6 multi-field storage-type covert channel to improve the confidentiality and robustness of information transmission.
[0085] S1-1: The parsing function module parses the txt file carrying the secret information, selects the field carrier of the secret information, divides the parsed binary secret information into field lengths that match the selected carrier, and obtains the target bit string of the secret information.
[0086] In this embodiment, the traffic class field and the hop limit field require 8 bits of secret information to be allocated to the destination field. The flow label field requires 20 bits. The options field of the hop-by-hop options extension header and the reserved field of the fragment extension header also require 8 bits.
[0087] S1-2: Data packet construction module, which sets the basic structure of the data packet, including the destination address, source address, and transmission protocol, and also presets fields to store secret information; S1-3: The embedding module embeds the target bit string of secret information into a pre-defined field in the data packet. Using a pseudo-random selector driven by the pre-shared key between the sender and receiver, it dynamically selects and combines the flow label and flow class in the IPv6 basic header, as well as the corresponding fields in the Hop-by-Hop Options and Fragment extension headers, to embed the secret information.
[0088] S1-4: Transmission protocol selection module, which selects the appropriate protocol to send the data packet based on the constructed data packet and network conditions to ensure the integrity and confidentiality of the information.
[0089] S2 uses deep neural networks to model transmission intervals and combines simulated fountain code technology to embed secret information into the transmission time intervals as a time-series covert channel.
[0090] S2-1: Encode the binary secret information by simulating the fountain code to obtain the encoding symbol value of the binary secret information; Define a binary secret information set , where k is the total number of information nodes.
[0091] Each symbolic node is generated by No. Column and secret information bit string Multiply to get a set of symbolic nodes :
[0092] in, is a A matrix where each matrix element Representative The information node and The weights between symbolic nodes.
[0093] S2-2: Determine the transmission time interval of data packets in the target group's real network traffic data and calculate the corresponding cumulative probability distribution.
[0094] 1) Define the transmission time difference between adjacent data packets in the target group's real network traffic data as the transmission time interval, and the calculation formula is:
[0095] Among them, i represents the packet sequence number in the target group’s real network traffic data, represents the i-th transmission time interval, Indicates the number of data packets in the target group's real network traffic data. Represents event time, where each data point represents the event time of a data packet; the transmission time interval IAT is the difference between the event times of adjacent consecutive data packets.
[0096] 2) All transmission time intervals of the target group's real network traffic data Sort from small to large to get the ascending sequence of transmission time intervals .
[0097] And calculate the cumulative distribution probability corresponding to the ascending sequence of transmission time intervals. The calculation formula is:
[0098] Among them, the number of packets of the target group’s real network traffic data is , then there are N transmission time intervals; The cumulative probability distribution function representing the time interval between packet transmissions.
[0099] S2-3: Fit the transmission time interval distribution of the target group's real network traffic data through a deep neural network model.
[0100] 1) Based on the transmission time intervals of data packets in the target group's real network traffic data and the corresponding cumulative probability distribution, a deep neural network model is used to output a mapping from transmission time intervals to cumulative distribution probability values, and an inverse mapping from cumulative distribution probability values to transmission time intervals.
[0101] The ascending sequence of transmission time intervals obtained by S2-2 and its corresponding cumulative probability value Input the deep neural network model for learning to obtain the mapping from transmission time interval to cumulative distribution probability value , and use the interpolation function to obtain the inverse mapping from the cumulative distribution probability value to the transmission time interval .
[0102] During the training process, the cumulative probability distribution of a deep neural network model may exceed the range of [0, 1]. To address model accuracy issues, the network depth of the deep neural network model is reasonably increased, and residual connections are introduced. To prevent this range from exceeding the range, the output value is limited to between 0 and 1 using the Sigmoid activation function. The Sigmoid activation function formula is as follows:
[0103] in, It is the output value of the activation function, which means mapping the input x to the (0,1) interval, where x is the input of the neuron and e is the base of the natural logarithm.
[0104] To complete the modulation and demodulation process of secret information, the inverse mapping must be obtained. Using the cubic spline interpolation method, the cumulative distribution probability value obtained after fitting the deep neural network model is calculated to obtain the inverse mapping. The calculation formula is:
[0105] in, The cumulative distribution probability value obtained after fitting the deep neural network model; The coefficients obtained for cubic spline interpolation.
[0106] 2) The sender assigns a probability interval to each coded symbol based on the inverse mapping to determine the transmission time interval distribution of the data packet to be sent: The set of symbolic nodes corresponding to the binary secret information Sort by Uniformly distribute probability intervals , realize each symbol node Corresponding to a probability interval , and using the inverse mapping The transmission time interval distribution of the data packets to be sent in the real network traffic data of the time-series covert channel target group is obtained, and the formula is expressed as:
[0107] in, Indicates that in the probability interval Randomly pick a value from for inverse mapping.
[0108] The sender distributes the transmission time interval As the sending time interval, the information is sent.
[0109] S2-4: The receiver receives the target group's real network traffic data and determines the encoding symbol value through inverse mapping.
[0110] 1) The receiver receives the real network traffic data of the target group and determines the transmission time interval distribution of the data packets. Based on the transmission time interval distribution, the probability value corresponding to the data packet transmission time interval is determined by mapping.
[0111] The arrival time interval of data packets is used as the transmission time interval, and the transmission time interval distribution is mapped from the transmission time interval to the cumulative distribution probability value. , calculate the probability value of the time interval distribution of the target group's real network traffic data, the formula is expressed as:
[0112] in, Indicates the transmission time interval distribution of the target group’s real network traffic data packets, represents the mapping of transmission time interval to cumulative probability value, represents the probability corresponding to the i-th transmission time interval.
[0113] 2) Determine the coded symbol value corresponding to the transmission time interval based on the probability interval assigned to each coded symbol by the sender.
[0114] According to the probability value corresponding to the transmission time interval and the mapping relationship between the coded symbol value and the probability interval in S2-3, the coded symbol corresponding to the transmission time interval is determined. :
[0115] in, Indicates the probability value found The corresponding probability interval , and map to obtain the encoding symbols.
[0116] S2-5 will get the coded symbol The encrypted binary secret information is obtained by using the BP decoding algorithm. The steps include: Since each symbol node is either 0 or 1, in each iteration of the BP decoder, the given received coded symbol is calculated The probability that a variable node is at 0 or 1 given the weight coefficient.
[0117] Defined in BP algorithm In the iteration, from the variable node Passed to the verification node Information and Similarly, in the BP decoder In the iteration, from the check node Return variable node The information is represented as and In the In the iteration, the information The calculation formula is:
[0118] in, Indicates that except for variable nodes In addition, all nodes with check A set of adjacent information nodes; Indicates the encoding symbol of the neighbor variable node, participating in the conditional probability calculation; Represents the weight between the variable node and the check node; Indicates the check constraint value of the check node.
[0119] At the same time, information The calculation is as follows:
[0120] in, Is a variable node All adjacent nodes except the check node The set of check nodes, was selected so that Established. After predefined After iterations, the variable node iteration result is calculated according to the following formula:
[0121] in, was selected so that Established, at this time, if , variable node is determined to be 0; otherwise, it is determined to be 1. Represents the final belief probability of variable node j after the Tth iteration.
[0122] S3 specifically includes the following steps: S3-1: Capture the target group's real network traffic data and statistically analyze the packet transmission time interval to obtain the current network congestion level. .
[0123] Monitor the target group's actual network traffic data transmission time interval and statistically calculate its cumulative distribution function , define the target group's real network traffic data The interval is , then the reference line equation can be obtained , using the cumulative distribution function and the reference line equation to calculate each The corresponding cumulative distribution probability value Function value with reference line The average distance is considered as the degree of network congestion :
[0124] in, For the current network environment the total number of; S3-2: Design of a flow-adaptive covert channel optimization algorithm: Monitor the traffic status of the network in real time, and calculate the network congestion level using step S3-1 after a fixed time interval . And according to the degree of network congestion Calculate the proportion of temporal covert channels in hybrid covert channels , and the corresponding relationship calculation formula is as follows:
[0125] in, The formula is derived heuristically through a large number of experimental results. The calculated ratio Determines the proportion of information sent by the timing covert channel in the hybrid covert channel.
[0126] S3-3: Based on the proportion calculated in step S3-2 , processing the secret information to be sent, so that the single storage covert channel and the single timing covert channel each send a certain proportion of secret information, improving transmission reliability and ensuring concealment. The specific steps of the algorithm are as follows: Define the secret information to be sent as ,in , is the total number of bits of secret information.
[0127] The proportion of temporal covert channels calculated using the traffic adaptive covert channel optimization algorithm mentioned in step S3-2 is , according to the obtained parameters Split the secret information to be sent to obtain the secret information required to be sent by the time-series covert channel Secret information required to be sent through storage-based covert channels ,in Indicates rounding down.
[0128] After the two types of covert channels in the adaptive hybrid covert channel obtain the secret information they need to send, they respectively execute the specific steps of S1 and S2, and the two types of channels successively mix and send the secret information.
[0129] Example 3 The effect of this method is verified by comparative experiments. The experimental results are as follows: Figures 5-10 As shown: Figure 5 This figure shows the effect of the deep neural network model fitting the target group's real network traffic data distribution. As can be seen from the figure, the deep neural network model fits the target group's real network traffic data distribution more closely, and the fitting effect is better than the Weibull function fitting method and the two-state Markov modulation fitting method.
[0130] Figure 6 This is a comparison chart of the bit error rate of secret information transmission under different levels of network congestion. It can be seen from the figure that: 1) The covert channel scheme based on two-state Markov modulation maps the bit values 0 and 1 to two predetermined transmission rate intervals, which will cause bit flipping during network peak hours, increasing the bit error rate.
[0131] 2) The covert channel scheme based on Weibull function fitting has insufficient coding redundancy and the long-tail characteristic of Weibull distribution, which leads to an increase in bit error rate.
[0132] 3) The time-series covert channel based on deep neural network model fitting has a lower bit error rate than the above two methods when the network is not congested, but as the network congestion increases, the transmission reliability gradually decreases; 4) The adaptive hybrid covert channel based on dynamic perception combines the advantages of timing-based covert channels and storage-based covert channels, and the bit error rate is kept stable at a low level.
[0133] Because of the interference such as delay and noise during the channel transmission process, when the receiver receives the data packet, the calculation of its transmission time interval will produce corresponding errors. Figure 7 This is a comparison chart of the bit error rate of secret information transmission under different channel interference. It can be seen from the figure: 1) The timing covert channel method based on deep neural network model fitting shows a gradually decreasing bit error rate when the TISNR (Time-Interval Signal-to-Noise Ratio) is between 35dB and 50dB, and outperforms the comparison scheme. When the TISNR is between 30dB and 35dB, the bit error rate of secret information transmission fluctuates slightly.
[0134] 2) The adaptive hybrid covert channel based on dynamic traffic perception solves the problem of bit error rate fluctuation when the TISNR interference intensity increases, and improves the ability of the covert channel to transmit secret information in unstable communication channels.
[0135] Figure 8 A comparison chart of Kolmogorov-Smirnov test values under different covert channels. Figure 9 The figure shows the comparison of Kullback-Leibler Divergence test under different covert channels. The test results of this method are better than those of the comparison scheme.
[0136] Figure 10 This figure compares the effectiveness of this method in detecting covert channels in an SVM detection system. As can be seen from the figure, the hybrid covert channel constructed by this method has significantly lower accuracy, precision, recall, and F1 score than the other covert channels using a single temporal covert channel classifier, demonstrating the strong concealment advantage of the covert channel constructed by this method.
[0137] This method has strong adaptability and concealment, and can achieve reliable and concealed information transmission in a dynamically changing network environment. It has certain reference value for research on improving the security of network communications.
[0138] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the above embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the above embodiments, or replace some or all of the technical features therein with equivalents. However, these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present invention.
Claims
1. An adaptive hybrid covert channel construction method based on dynamic traffic perception, characterized in that: include: Construct a hybrid covert channel including a timing covert channel and a storage covert channel; Real-time monitoring of network traffic conditions and calculation of network congestion levels; Determining the proportion of the timing-type covert channel and the storage-type covert channel in the hybrid covert channel based on the degree of network congestion; dividing the secret information to be sent according to the proportion to obtain the information to be sent by the timing-type covert channel and the information to be sent by the storage-type covert channel; The information to be sent through the timing type covert channel is sent through the timing type covert channel, and the information to be sent through the storage type covert channel is sent through the storage type covert channel.
2. The method according to claim 1, characterized in that The network congestion level is defined by the target group's actual network traffic data transmission time interval, including: in, Indicates the degree of network congestion; Indicates the target group's actual network traffic data transmission time interval The cumulative distribution function of Indicates the target group's actual network traffic data transmission time interval The reference line function value of It is the total number of real network traffic data transmission intervals of the target group in the current network environment.
3. The method according to claim 1, characterized in that The proportion of sequential covert channels in the hybrid covert channels includes: in, It is a preset constant obtained by least squares fitting based on a large number of experimental results. e is the base of the natural logarithm, and K represents the degree of network congestion.
4. The method according to claim 1, wherein The information to be sent through the time-series covert channel is , where R represents the proportion of sequential covert channels in hybrid covert channels, and n represents the total number of bits of secret information converted into binary bit strings; The information to be sent through the storage-type covert channel: ,in Indicates rounding down.
5. The method according to claim 1, wherein The storage-type covert channel includes: determining a field carrier of the binary secret information, and dividing the binary secret information into a predetermined length according to the field carrier as a target bit string; Determine the basic structure of the data packet and the fields for storing secret information; The secret information target bit string is embedded into a preset field of the data packet.
6. The method according to claim 1, characterized in that The time-series covert channel includes: Determine the transmission time interval of data packets in the target group's real network traffic data and calculate the corresponding cumulative probability distribution; Based on the transmission time intervals of data packets in the target group's real network traffic data and the corresponding cumulative probability distribution, a deep neural network model is used to output a mapping from transmission time intervals to cumulative distribution probability values and an inverse mapping from cumulative distribution probability values to transmission time intervals. Encoding the coded symbol values of the binary secret information using a simulated fountain code technique, and assigning a probability interval to each coded symbol value to obtain a mapping relationship between the coded symbol value and the probability; the sender determines the transmission time interval distribution of the data packet to be sent based on the inverse mapping and the random probability value within the probability interval, and sends the data packet using the transmission time interval as the sending time interval; The receiver receives the real network traffic data of the target group and determines the arrival time interval distribution of the data packets as the transmission time interval distribution; and determines the probability value corresponding to the transmission time interval based on the transmission time interval distribution through the mapping; The coding symbol value corresponding to the transmission time interval is determined by combining the mapping relationship between the coding symbol value and the probability and the probability value corresponding to the transmission time interval.
7. The method according to claim 5, characterized in that The field carrier of the binary secret information includes: a traffic category field, a hop limit field, a flow label field, an option field of a hop-by-hop option extension header, and a reserved field of a fragment extension header.
8. The method according to claim 6, characterized in that The deep neural network comprises: The output value is limited to between 0 and 1 through the Sigmoid activation function.
9. The method according to claim 6, characterized in that The cumulative distribution probability value of the transmission time interval is calculated using the cubic spline interpolation method, and the inverse mapping from the cumulative distribution probability value to the transmission time interval is obtained.