Information transmission and detection method and device, electronic equipment and storage medium

CN122845684APending Publication Date: 2026-09-29SHANGHAI LANCUN TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610683938.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-05-18
Publication Date
2026-09-29

AI Technical Summary

Technical Problem

现有技术通常通过压缩编码或调制方式提升频谱效率,但这些方法往往需要对物理层或链路层进行改造,部署成本高,且与上层协议兼容性差

Benefits of technology

上述信息传输和检测方法、装置、电子设备和存储介质,无需修改物理层或链路层,亦无需增加信道带宽,仅利用TCP/IP协议栈中现有协议头字段的冗余空间,即可提升单数据包的有效信息承载量;同时,完全兼容标准协议栈实现,无需部署额外网络基础设施,降低了提升传输效率的实现成本与部署难度。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122845684A_ABST
    Figure CN122845684A_ABST
Patent Text Reader

Abstract

The present disclosure provides an information transmission and detection method, device, electronic equipment and storage medium; wherein the information transmission method comprises: obtaining a bit stream to be sent; distributing the bit stream to a plurality of protocol header fields of a TCP / IP protocol stack to determine the to-be-encoded value corresponding to each protocol header field; wherein the plurality of protocol header fields at least include two or more redundant fields in the IP layer and the TCP layer; imposing a field constraint on the to-be-encoded value corresponding to each protocol header field, so that the encoded protocol header field value conforms to the protocol stack fingerprint characteristics of a target operating system; based on the constraint, encoding the to-be-encoded values of the plurality of protocol header fields to obtain the encoded protocol header field values; and generating at least one data packet based on the encoded protocol header field values, and sending the at least one data packet. The present disclosure can improve the transmission rate of effective information under the premise of being compatible with the existing protocol stack and without the need to modify the network infrastructure.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the field of data transmission technology, and in particular to an information transmission and detection method, apparatus, electronic device, and storage medium. Background Technology

[0002] In digital communication systems, channel bandwidth resources are limited, while the amount of data to be transmitted is constantly increasing. How to improve the transmission rate of effective information without increasing additional bandwidth or changing the transmission medium has long been a research topic in the field of communications. Existing technologies typically improve spectral efficiency through compression coding or modulation, but these methods often require modifications to the physical or data link layers, resulting in high deployment costs and poor compatibility with upper-layer protocols. Therefore, there is a need for an information transmission method that is compatible with existing protocol stacks and requires no modification to the network infrastructure. Summary of the Invention

[0003] In view of this, the purpose of this disclosure is to provide an information transmission and detection method, apparatus, electronic device and storage medium to improve the transmission rate of effective information while being compatible with existing protocol stacks and without modifying network infrastructure.

[0004] In a first aspect, embodiments of this disclosure provide an information transmission method, the method comprising: acquiring a bit stream to be sent; allocating the bit stream to multiple protocol header fields of a TCP / IP protocol stack to determine a value to be encoded corresponding to each protocol header field; wherein the multiple protocol header fields include at least two or more redundant fields from the IP layer and the TCP layer; applying field constraints to the value to be encoded corresponding to each protocol header field to make the encoded protocol header field value conform to the protocol stack fingerprint characteristics of a target operating system; encoding the value to be encoded of the multiple protocol header fields based on the constraints to obtain an encoded protocol header field value; generating at least one data packet based on the encoded protocol header field value, and sending the at least one data packet.

[0005] Secondly, embodiments of this disclosure provide an information detection method, the method comprising: receiving a data stream belonging to the same source device and the same destination device; wherein the data stream contains at least one data packet; extracting joint features of the data packet; wherein the joint features include: value distribution features of a single protocol header field, and statistical correlation features between the values ​​of at least two protocol header fields; inputting the joint features into a pre-trained anomaly detection model to obtain a detection result; wherein the anomaly detection model is trained based on joint features of traffic that does not contain covert channels; and determining whether the data stream contains a covert channel based on the detection result.

[0006] Thirdly, embodiments of this disclosure provide an information transmission apparatus, comprising: an acquisition module for acquiring a bit stream to be sent; an allocation module for allocating the bit stream to multiple protocol header fields of a TCP / IP protocol stack to determine a value to be encoded corresponding to each protocol header field; wherein the multiple protocol header fields include at least two or more redundant fields from the IP layer and the TCP layer; a constraint module for applying field constraints to the value to be encoded corresponding to each protocol header field to ensure that the encoded protocol header field value conforms to the protocol stack fingerprint characteristics of a target operating system; an encoding module for encoding the value to be encoded of the multiple protocol header fields based on the constraints to obtain an encoded protocol header field value; and a sending module for generating at least one data packet based on the encoded protocol header field value and sending the at least one data packet.

[0007] Fourthly, embodiments of this disclosure provide an information detection apparatus, comprising: a receiving module for receiving a data stream belonging to the same source device and the same destination device; wherein the data stream contains at least one data packet; an extraction module for extracting joint features of the data packet; wherein the joint features include: value distribution features of a single protocol header field, and statistical correlation features between the values ​​of at least two protocol header fields; a detection module for inputting the joint features into a pre-trained anomaly detection model to obtain a detection result; wherein the anomaly detection model is trained based on the joint features of traffic that does not contain a covert channel; and a determination module for determining, based on the detection result, whether the data stream contains a covert channel.

[0008] Fifthly, embodiments of this disclosure provide an electronic device, including a processor and a memory, wherein the memory stores machine-executable instructions that can be executed by the processor, and the processor executes the machine-executable instructions to implement the above-described information transmission and detection method.

[0009] In a sixth aspect, embodiments of this disclosure provide a computer-readable storage medium storing computer-executable instructions. When the computer-executable instructions are invoked and executed by a processor, the computer-executable instructions cause the processor to implement the aforementioned information transmission and detection method.

[0010] The embodiments disclosed herein bring the following beneficial effects: The aforementioned information transmission and detection methods, devices, electronic equipment, and storage media do not require modification of the physical layer or link layer, nor do they require increasing channel bandwidth. They can increase the effective information carrying capacity of a single data packet by utilizing the redundant space of the existing protocol header fields in the TCP / IP protocol stack. At the same time, they are fully compatible with standard protocol stack implementations, do not require the deployment of additional network infrastructure, and reduce the implementation cost and deployment difficulty of improving transmission efficiency.

[0011] Other features and advantages of this disclosure will be set forth in the following description and will be apparent in part from the description or may be learned by practicing the disclosure. The objects and other advantages of this disclosure are realized and obtained through the structures particularly pointed out in the description, claims and drawings.

[0012] To make the above-mentioned objects, features and advantages of this disclosure more apparent and understandable, preferred embodiments are described below in detail with reference to the accompanying drawings. Attached Figure Description

[0013] To more clearly illustrate the technical solutions in the specific embodiments of this disclosure or the prior art, the drawings used in the description of the specific embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this disclosure. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.

[0014] Figure 1 This is a flowchart of one embodiment of the information transmission method in this disclosure; Figure 2 This is a flowchart of one embodiment of the information detection method in this disclosure; Figure 3 A schematic diagram of an information transmission device provided in an embodiment of this disclosure; Figure 4 A schematic diagram of an information detection device provided in an embodiment of this disclosure; Figure 5 This is a schematic diagram of an electronic device provided in an embodiment of the present disclosure. Detailed Implementation

[0015] To make the objectives, technical solutions, and advantages of the embodiments of this disclosure clearer, the technical solutions of this disclosure will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this disclosure, and not all embodiments. Based on the embodiments of this disclosure, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this disclosure.

[0016] The terms “first,” “second,” “third,” “fourth,” etc. (if present) in this disclosure, claims, and accompanying drawings are used to distinguish similar objects and are not necessarily used to describe a particular order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms “comprising” or “having,” and any variations thereof, are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0017] For ease of understanding, the specific process of the embodiments of this disclosure is described below. Please refer to [link / reference]. Figure 1 One embodiment of the information transmission and detection method in this disclosure includes: Step S10: Obtain the bit stream to be sent; The bit stream to be sent refers to the raw information data that needs to be transmitted from the sender to the receiver via a covert channel. It can be any binary sequence, such as file content, encrypted data, control commands, authentication information, voice signals, or session keys. The length of the bit stream is unlimited; it can consist of a single bit or hundreds of kilobits or even megabits of data.

[0018] When acquiring the bit stream to be sent, it can be received from an upper-layer application, read from local storage media, or generated by the sender itself. The acquisition operation does not change the semantic content of the bit stream itself; it only serves as input for subsequent encoding processes. This disclosure embodiment applies to the data sender, where the bit stream to be sent can be a data stream containing covert channels / hidden information. Unlike encrypted communication, the covert channel can hide not only the information content but also the communication behavior itself.

[0019] In one implementation, after obtaining the bit stream to be sent, the bit stream can be preprocessed. The preprocessing process may include: dividing the bit stream to be sent into multiple data blocks according to a preset block size (e.g., 512 bits), and appending a Cyclic Redundancy Check (CRC) code to the end of each data block for the receiving end to verify data integrity.

[0020] In real-time voice communication scenarios, the transmitting end acquires voice signals through a microphone, performs analog-to-digital conversion and compression encoding (such as the Opus codec) to generate a continuous bitstream, which can be used as the bitstream to be sent. This bitstream can be temporarily stored in a circular buffer, and a fixed-length (e.g., 160-bit) bitstream segment is retrieved from the buffer according to a preset time window (e.g., every 20 milliseconds) as the bitstream to be sent for the current data packet. The bitstream to be sent obtained in this step can be the bitstream to be sent for the current data packet; the specific choice is not limited here.

[0021] Step S20: Assign the bit stream to multiple protocol header fields of the TCP / IP protocol stack to determine the value to be encoded for each protocol header field; wherein, the multiple protocol header fields include at least two or more redundant fields from the IP layer and the TCP layer; In this embodiment, the bitstream is split into multiple parts, and each part is mapped to a specific protocol header field in the TCP / IP protocol stack, thereby determining the binary value (i.e. the value to be encoded) that each protocol header field will carry. Each part can be a substream or a data block, and the specifics are not limited here.

[0022] Protocol header fields are fields that have redundancy between the IP and TCP layers, whose values, when modified, will not affect the normal operation of the protocol and are not easily blocked by intermediate devices. Specifically, protocol header fields may include, but are not limited to: IP Identifier (IPID, 16 bits), IP Time to Live (TTL, 8 bits), IP Differentiated Services / Explicit Congestion Notice (DSCP / ECN, 8 bits), TCP Initial Sequence Number (ISN, 32 bits), the time value (TSval, 32 bits) and echo value (TSecr, 32 bits) in the TCP timestamp option, TCP window size (Window, 16 bits), and TCP Urgent Pointer (Urgent Pointer, 16 bits), etc.

[0023] In one implementation, at least two or more protocol header fields from the IP layer and TCP layer are used (e.g., using both IPID and TCP ISN, or both TTL and TCP Window), that is, the bit stream is distributed to two or more protocol header fields of the TCP / IP protocol stack to achieve co-coding between fields.

[0024] The value to be encoded is a binary value assigned to each protocol header field that has not yet undergone field constraints or other adjustments. This value can be the raw bits directly extracted from the bit stream or redundant bits after forward error correction coding, depending on the relevant configuration.

[0025] The allocation method of bit streams can adopt different strategies according to specific needs. As an example and not a limitation, bit stream allocation strategies can include: fixed allocation strategy, dynamic allocation strategy, reliability-based differentiated allocation strategy, and key-based secure allocation strategy, etc. The above strategies can be used alone or in combination, and there are no specific limitations here. When using a fixed allocation strategy to distribute bitstreams across multiple header fields of the TCP / IP protocol stack, the number of bits allocated to each header field can be pre-defined. The bitstream to be sent is then sequentially divided according to the set length and filled into each header field. For example, IPID is fixed at 16 bits, TTL at 3 bits, ISN at 32 bits, and TSval at 12 bits. When using a dynamic allocation strategy to distribute bitstreams across multiple header fields of the TCP / IP protocol stack, the number of bits allocated to each header field can be dynamically adjusted based on the current network environment (such as packet loss rate and the probability of modification by intermediate devices). For example, when many NAT devices are detected in the network, the allocation to the TCP timestamp field can be reduced (because it is more likely to be reset), while the allocation to the ISN field can be increased (because it is less likely to be modified). When using a reliability-based differentiated allocation strategy to distribute bit streams to multiple header fields of the TCP / IP protocol stack, fields with higher reliability (such as ISN and IPID) can be allocated to more important data bits or unprotected raw information; fields with lower reliability (such as TTL and DSCP) can be allocated to forward error correction codes; the reliability can be preset, and the specifics are not limited here. When using a key-based secure allocation strategy to distribute bit streams to multiple header fields of the TCP / IP protocol stack, the allocation order of the header fields can be pseudo-randomized by using a shared key. This results in different bit-to-field mappings for different sessions or different data packets within the same session, increasing the difficulty of parsing hidden data.

[0026] Step S30: Apply field constraints to the value to be encoded corresponding to each protocol header field so that the encoded protocol header field value conforms to the protocol stack fingerprint characteristics of the target operating system; Field constraints refer to the process of restricting or adjusting the values ​​to be encoded for each protocol header field based on protocol specifications, the implementation characteristics of the target operating system, and the behavioral patterns of network intermediate devices. This constraint ensures that the encoded field values ​​not only meet basic protocol syntax requirements but also conform to the statistical behavioral characteristics of the target operating system, i.e., protocol stack fingerprint characteristics.

[0027] Protocol stack fingerprints refer to the differentiated behavioral patterns exhibited by different operating systems (such as Linux 5.x, Windows 11, macOS Ventura, FreeBSD 14, etc.) in their TCP / IP protocol stack implementations. These behavioral patterns include, but are not limited to: the algorithm for generating the initial sequence number (such as random increment or time-based deterministic growth), the increment rate of the time value in the timestamp option (such as increasing by 1 per millisecond or 5 per 50 milliseconds), the typical initial value of the window size (such as 65535 commonly used in Linux and 8192 commonly used in Windows), the generation mode of the IP identifier (global counter or independent counter per destination address), and the order of TCP options (such as whether the timestamp option is swapped with the window expansion option).

[0028] When applying field constraints, one or more of the following can be applied: monotonicity constraints, range constraints, and flag-bit dependency constraints. Among them, monotonicity constraints can be applied to fields whose values ​​must increase monotonically (such as TSval in TCP timestamps). This constraint is used to constrain the encoded value to increase as the packet sequence number increases. This can be achieved by embedding the bit to be encoded into the low-order part of the field and controlling the high-order part with a real clock or counter. Range constraints can be applied to fields with limited value ranges (such as IP Time to Live (TTL)). They are used to ensure that the encoded value must fall within a preset deviation range of the typical initial value of the target operating system. For example, the typical initial value of Linux is 64, and the allowable deviation is ±3. Therefore, the range of the encoded TTL value is 61-67. Flag dependency constraints can be applied to fields that are ignored by the protocol stack only when a specific flag is not set (such as the TCP urgent pointer). These fields can be freely encoded only when the corresponding flag (URG) is 0. If URG is 1, the urgent pointer has a practical function and is not used for covert communication.

[0029] Step S40: Based on constraints, encode the values ​​to be encoded in multiple protocol header fields to obtain the encoded protocol header field values; In this embodiment, when encoding the values ​​to be encoded for multiple protocol header fields, the field constraints applied to the values ​​to be encoded for each protocol header field in the previous step are followed. The values ​​to be encoded are mapped to target values ​​according to a preset encoding algorithm, which are then used as the encoded protocol header field values. This ensures that the encoded protocol header field values ​​conform to the protocol stack fingerprint characteristics of the target operating system.

[0030] In one implementation, after a TCP session is established, several probe packets without carrying hidden data can be sent first to measure the probability of modification of each protocol header field on the transmission path. Then, based on the probe results, the encoding strategy can be dynamically adjusted to encode the values ​​to be encoded in multiple protocol header fields.

[0031] For example, assuming the probe finds that the IPID field arrives unchanged in all 10 packets, the probability of modification is 0%; the TTL field decreases by 1 for each hop, but in reality, it goes through 3 hops, so the change pattern is certain and recovery can be predicted; 30% of packets have their DSCP field rewritten to 0 by the ISP; and 50% of packets have their TCP timestamp field intercepted or reset by intermediate firewalls.

[0032] When dynamically adjusting the encoding strategy based on the detection results, for IPID and ISN header fields with a modification probability below a certain threshold, high code rate encoding can be used (e.g., directly embedding the original data without redundancy). For TTL fields with predictable changes, incremental encoding with a signed bit can be used (the sender encodes the original hop count, and the receiver infers the path hop count by observing the difference between the actual TTL and the initial TTL, and then restores the original value). For DSCP and timestamps with a modification probability above a certain threshold, only redundant check bits can be embedded or none at all.

[0033] Based on the above, different encoding algorithms are applied to each protocol header field to obtain the encoded value of each protocol header field, i.e., the encoded protocol header field value. This adaptive encoding method maximizes the use of the capacity of reliable fields while avoiding wasting encoding opportunities on unreliable fields.

[0034] After encoding, a preset fingerprint detection engine can be used to perform consistency checks on the encoded protocol header fields. If the check result indicates that the encoded protocol header fields conform to the protocol stack fingerprint characteristics of the target operating system, then proceed to the next step; if they do not conform, adjust the constraint parameters of one or more fields (such as adjusting the TTL deviation value or the low-order embedding position of TSval) and reapply constraints until the preset maximum number of retries is reached.

[0035] Step S50: Based on the encoded protocol header field values, generate at least one data packet and send at least one data packet.

[0036] In this embodiment, when generating at least one data packet, the encoded values ​​of each protocol header field are taken and assembled with other fixed fields necessary for the protocol stack (such as source IP address, destination IP address, source port, destination port, TCP flags, checksum, etc.) to form one or a series of complete data packets conforming to the TCP / IP protocol format. The assembly process described above can follow the encapsulation order of the standard protocol stack: first, construct the IP header and fill in fields such as IP identifier, TTL, and DSCP at the specified offset positions; then, construct the TCP header after the IP header and fill in fields such as sequence number, window size, urgent pointer, and timestamp options at the corresponding positions; finally, append the payload (optional) after the TCP header.

[0037] The information transmission method provided by the above implementation does not require modification of the physical layer or link layer, nor does it require increasing channel bandwidth. It can improve the effective information carrying capacity of a single data packet by utilizing the redundant space of the existing protocol header fields in the TCP / IP protocol stack. At the same time, it is fully compatible with standard protocol stack implementation, does not require the deployment of additional network infrastructure, and reduces the implementation cost and deployment difficulty of improving transmission efficiency.

[0038] Next, the specific methods of information transmission will be explained.

[0039] In one implementation, the bit stream is allocated to multiple protocol header fields of the TCP / IP protocol stack to determine the value to be encoded corresponding to each protocol header field. This includes: determining the effective codecable capacity of each protocol header field in the multiple protocol header fields of the TCP / IP protocol stack; wherein the effective codecable capacity is less than or equal to the nominal bit width of the corresponding protocol header field and satisfies protocol specification constraints; dividing the bit stream to be transmitted into multiple sub-streams according to the effective codecable capacity and the preset reliability level of each protocol header field, and allocating the sub-streams to multiple protocol header fields of the TCP / IP protocol stack to determine the value to be encoded corresponding to each protocol header field; wherein the preset reliability level is determined based on the probability that the protocol header field is modified by an intermediate network device, and the sub-stream length allocated to the protocol header field with a higher preset reliability level is greater than the sub-stream length allocated to the protocol header field with a lower reliability level.

[0040] Effective codeable capacity refers to the number of bits that can actually be used to carry hidden information in the protocol header field, provided that the protocol specification constraints and operating system behavior constraints are met. This capacity is less than or equal to the nominal bit width of the field, which is the length defined by the protocol, such as 16 bits for IPID and 8 bits for TTL.

[0041] Factors affecting effective coded capacity include: protocol semantic constraints (e.g., the IP Time-to-Live (TTL) field is decremented by 1 after each router pass; if the initial value deviates too much from the typical range, packets may be dropped prematurely. Therefore, its effective coded capacity is usually only 3-4 bits, rather than the full 8 bits), typical operating system behavior (e.g., modern operating systems typically use randomized generation algorithms for the initial sequence number (ISN), but its value range is all available, so the effective capacity is close to 32 bits), and the probability of modification by intermediate devices (e.g., the Differentiated Services (DSCP) field is reset to 0 in some networks; if the coded value is modified, information is lost, so its effective capacity needs to take into account the actual transmission success rate).

[0042] A preset reliability level indicates the probability that each protocol header field will remain unchanged throughout the transmission path. This level can be preset based on empirical statistics or real-time detection. Specifically, fields with high reliability levels (such as ISN and IPID) are not modified by intermediate devices in most network environments; fields with medium reliability levels (such as TCP Window and TCPTimestamp) may be fine-tuned by intermediate devices, but the changes are predictable; fields with low reliability levels (such as TTL and DSCP) may change due to route changes or network policies.

[0043] The preset reliability level can be a fixed empirical value or a dynamic value based on real-time probing. For example, after the TCP connection is established, several probe packets without carrying hidden data can be sent to observe the modifications of each field upon arrival at the receiving end. For instance, if the probing finds that the IPID field arrives correctly in all packets, the reliability level can be set to the highest level; if the TTL field decreases by 1 per packet but the change pattern is certain, the reliability level can be set to the medium level; if the DSCP field is reset to 0 in 30% of the packets, the reliability level can be set to the lowest level.

[0044] When dividing the bit stream to be transmitted into multiple sub-streams based on the effective codecable capacity and the preset reliability level of each protocol header field, and assigning the sub-streams to multiple protocol header fields of the TCP / IP protocol stack to determine the value to be encoded for each protocol header field, a weighted fusion calculation can be performed on the effective codecable capacity and preset reliability level of each protocol header field to determine the length of the sub-stream allocated to each protocol header field. Then, the sub-streams allocated to each protocol header field are determined by matching the importance of the information with the preset reliability level. The sub-streams contain the value to be encoded corresponding to the protocol header field.

[0045] In one implementation, field constraints are applied to the value to be encoded corresponding to each protocol header field to ensure that the encoded protocol header field value conforms to the protocol stack fingerprint characteristics of the target operating system. This includes: obtaining pre-stored protocol stack fingerprint parameters of the target operating system, which include: typical values ​​of each protocol header field, statistical dependencies between protocol header fields, and the change pattern of protocol header field values ​​over time or data packet sequence number; applying legal value range constraints and joint value constraints between at least two protocol header fields to the value to be encoded corresponding to each protocol header field based on the protocol stack fingerprint parameters; and applying reasonable value range constraints of the corresponding protocol header field to the value to be encoded according to a preset encoding rule that matches the corresponding protocol header field.

[0046] Typical values ​​for each protocol header field, for example, the default TTL for Linux 5.x is 64, the default TTL for Windows 11 is 128, and the default window size for FreeBSD 14 is 65535. These typical values ​​can be preset / stored, and are not limited here.

[0047] Statistical dependencies between protocol header fields, such as a positive correlation between the increment of the Initial Sequence Number (ISN) and the increment of the TCP timestamp (TSval); consistency between the increment pattern of the IP identifier and the packet sending order (global counter or per-target independent counter); and other statistical dependencies will not be elaborated further.

[0048] The values ​​of protocol header fields vary with time or packet sequence number. For example, the timestamp field usually increases by a fixed step (such as 1, 2 or 10) every millisecond or every packet. The window size increases slowly (congestion avoidance phase) or changes drastically (slow start phase) in the early stages of connection establishment. Other variation patterns will not be elaborated here.

[0049] Based on the typical values ​​of each protocol header field in the protocol stack fingerprint parameters and the variation patterns of protocol header field values ​​over time or packet sequence numbers, a legal value range constraint can be imposed on the value to be encoded corresponding to each protocol header field. This means imposing upper and lower limits on the value of a single protocol header field to ensure that the encoded value falls within the range that the target operating system can accept. For example, the legal range for the IP Time to Live field is [initial typical value]. Preset deviation, initial typical value + preset deviation.

[0050] Based on the statistical dependencies of the protocol stack fingerprint parameters among the protocol header fields, joint value constraints can be imposed on at least two protocol header fields. This means restricting the combinations of values ​​for at least two protocol header fields to maintain statistical correlation between fields. For example, the ratio of the ISN increment to the TSval increment must fall within a normal range (e.g., [0.8, 1.2]); the direction of IPID change must be consistent with the packet transmission order (backwards are prohibited).

[0051] Preset encoding rules are encoding rules that match the protocol semantics of each protocol header field. They are used to indicate the reasonable value range constraints for the corresponding protocol header fields. For example, for fields that the protocol specification requires to have monotonically increasing semantics, the encoded field value is constrained to monotonically increase with the increase of the data packet sequence number or time. For fields that the protocol specification limits to fluctuating within a small range around a certain typical value, the encoded field value is determined with the typical value in the fingerprint parameters as the center and within a preset deviation range. The deviation range corresponds to a preset number of encoded bits. For fields in the protocol specification whose values ​​are ignored by the protocol stack when a certain flag bit is not set, all bits of the field are determined as free encoded values ​​that directly carry the bits allocated to the field. In one implementation, based on constraints, the values ​​to be encoded for multiple protocol header fields are encoded to obtain encoded protocol header field values. This includes: performing pseudo-random permutations on the data to be encoded for the same data packet based on a preset key and the packet sequence number of the data packet to be generated, so as to determine the mapping relationship between each bit value in the bit stream and multiple protocol header fields; the data packet is a specified number of consecutive bit values ​​in the bit stream; and based on constraints, the bit values ​​corresponding to each protocol header field are encoded to obtain encoded protocol header field values.

[0052] In this embodiment, one or more encoding algorithms can be used for encoding, such as lookup table mapping (e.g., TTL), low-order embedding (e.g., TSval), XOR superposition (e.g., IPID), and probability sampling (e.g., Window). The specific method is not limited here.

[0053] In one implementation, generating and sending at least one data packet based on the encoded protocol header field value includes: performing a protocol stack fingerprint consistency check on the encoded protocol header field value to obtain a check result; if the check result indicates that the encoded protocol header field value conforms to the protocol stack fingerprint characteristics of the target operating system, then encapsulating a specified number of encoded protocol header field values ​​into data packets to obtain at least one data packet of bitstream; during the TCP connection establishment process, embedding session metadata in the synchronization sequence number packet; wherein the session metadata is used by the receiving end to configure the decoder; for the last data packet to be sent after the TCP connection is established, embedding verification information in the last data packet to be sent; wherein the verification information is used by the receiving end to verify the integrity of the session.

[0054] In this embodiment, before sending data packets, a protocol stack fingerprint consistency check is performed on the encoded protocol header field values. If the detection result indicates that the encoded protocol header field values ​​do not conform to the protocol stack fingerprint characteristics of the target operating system, the encoding value of at least one of the multiple protocol header fields is adjusted and the check is repeated until the check passes or the preset number of retries is reached.

[0055] The Synchronize Sequence Numbers (SYN) packet is the first data packet in the TCP three-way handshake, used to initiate a connection request. In this implementation, the session metadata can contain a set of parameters for the entire covert transmission session. These parameters may include, but are not limited to: the total length of the message to be sent (number of bits or packets), the type and parameters of the forward error correction coding (such as code rate, generator polynomial), the interleaving depth, the key version number or initial seed of the pseudo-random permutation, and the session identifier. By parsing the metadata in the SYN packet, the receiving end can correctly configure the decoder before the session begins, without needing to negotiate out-of-band.

[0056] The last data packet to be sent refers to the FIN (Finish) packet at the end of the TCP connection (or the last ACK packet carrying data, depending on the implementation). In this embodiment, verification information is embedded in this packet for the receiving end to verify the integrity of the data received throughout the session. Specifically, the verification information can be a Cyclic Redundancy Check (CDR) code (e.g., CRC-32), a message digest (e.g., a partial hash value of MD5 or SHA-1), or a digital signature of the entire original bitstream.

[0057] Session integrity verification, performed at the end of data transmission, uses a specific verification algorithm to confirm whether the bit stream has been truncated or out of order during cross-packet transmission. In this implementation, a CRC32 or hash checksum can be embedded in the last data packet before the end of the TCP session (such as a packet with the FIN or PSH flags) using redundant fields. Upon receiving this last packet, the receiving end compares it with all received segmented data. If the checksums match, session reassembly is completed, thereby reducing the reassembly risk caused by cross-packet interleaving.

[0058] Please see Figure 2 One embodiment of the information detection method in this disclosure includes: Step S201: Receive a data stream belonging to the same source device and the same destination device; wherein the data stream contains at least one data packet; Step S202: Extract the joint features of the data packet; wherein, the joint features include: the value distribution features of a single protocol header field, and the statistical correlation features between the values ​​of at least two protocol header fields; Step S203: Input the joint features into the pre-trained anomaly detection model to obtain the detection result; wherein, the anomaly detection model is trained based on the joint features of traffic that does not contain covert channels; Step S204: Based on the detection results, determine whether the data stream contains a covert channel.

[0059] This information detection method, by extracting the distribution features of single fields and the statistical correlation features between fields, can discover the disruption of the natural statistical relationship of protocol header fields by multi-field joint encoding. It adopts an anomaly detection model trained only on normal traffic, and can detect unknown or variant covert channels without knowing the specific encoding algorithm of the covert channel in advance, thereby improving the overall security protection capability of the network.

[0060] Corresponding to the information transmission method, the embodiments of this disclosure are applied to the receiving end to receive a data stream transmitted using the above-described information transmission method. The data stream is a sequence of consecutive data packets with the same five-tuple (source IP, source port, destination IP, destination port, and transport protocol) or four-tuple (source IP, destination IP, destination port, and transport layer protocol).

[0061] In this embodiment, the value distribution characteristics of a single protocol header field are one type of feature that can be used to indicate protocol stack fingerprint characteristics, and can be used to detect whether a field is used in a covert channel. Specifically, the value distribution characteristics may include at least one of the following: the entropy of the IP identifier (IPID) value, the mean and variance of the IP time-to-live (TTL) value, and the value range of the TCP window size; no specific limitation is made here.

[0062] In this embodiment, the statistical correlation characteristics between the values ​​of at least two protocol header fields are also a type of feature that can be used to indicate protocol stack fingerprint characteristics. This can be used to capture the cooperative change patterns between fields to detect multi-field joint coding of covert channels. Specifically, the statistical correlation characteristics may include at least one of the following: the correlation coefficient between the Initial Sequence Number (ISN) increment and the TCP timestamp (TSval) increment, the consistency between the IPID sequence change pattern and the packet sending order, and the statistical relationship between the TCP window size and round-trip time (RTT).

[0063] Anomaly detection models are classifiers based on machine learning or deep learning, whose training datasets contain normal traffic without hidden channels. By learning the joint feature distribution of normal traffic, anomaly detection models can identify anomalous traffic that deviates from the normal distribution during the testing phase. Optional model architectures include: autoencoders (for detecting anomalies based on reconstruction error), one-class support vector machines (SVMs), isolation forests, and sequence anomaly detection models based on Transformers. After training, the model takes the joint feature vector of the data stream to be detected as input and outputs the detection result as anomaly score, anomaly probability, or a normal / anomaly classification label.

[0064] The detection result can be a binary classification (normal / abnormal) or a continuous abnormal score. If it is an abnormal score, it is compared with a preset threshold to determine whether the data stream contains a covert channel. If it exceeds the preset threshold, it is determined to be a data stream containing a covert channel; otherwise, it is determined to be normal traffic.

[0065] In one implementation, the value distribution characteristics of a single protocol header field include at least one of the following: a statistical matrix of the corresponding protocol header field value, an autocorrelation coefficient of the corresponding protocol header field value, and an entropy rate of the corresponding protocol header field value; the statistical correlation characteristics between the values ​​of at least two protocol header fields include at least one of the following: a correlation coefficient between the initial sequence number increment and the TCP timestamp increment; a consistency measure between the change pattern of the IP identifier sequence and the packet sending order; a statistical relationship between the TCP window size and the round-trip delay; and a matching degree between the value of the IP time-to-live field and the number of routing hops in the packet transmission path; the joint characteristics also include: cross-session characteristics, which include the consistency of the initial sequence number hopping pattern of the same source address in different sessions and the consistency of the IP identifier increment pattern of the same source address in different sessions.

[0066] The statistical matrix corresponding to the values ​​of the protocol header fields can include mean, variance, skewness, kurtosis, etc. Among them, the mean reflects the central trend of the field values, the variance reflects the dispersion of the values, the skewness measures the asymmetry of the distribution, and the kurtosis measures the thickness of the tail of the distribution. For example, the TTL values ​​of normal traffic are usually concentrated around the default initial value (such as 64±3), with a small variance; if the encoder uses TTL to carry 3 bits of information, its values ​​may be evenly distributed in the interval [61,67], with a larger variance and a smaller kurtosis.

[0067] The autocorrelation coefficient of the corresponding protocol header field values ​​is used to measure the correlation between adjacent values ​​in the protocol header field value sequence. For normal traffic, some fields have strong autocorrelation (e.g., TSval is monotonically increasing, with an autocorrelation coefficient close to 1); however, if the encoded fields adopt a pseudo-random distribution, the autocorrelation coefficient may decrease significantly.

[0068] The entropy rate of a protocol header field measures the randomness or unpredictability of its value sequence. A higher entropy rate indicates that the field values ​​are closer to a uniform or random distribution. In normal traffic, some fields have low entropy rates (e.g., TTL is concentrated in a few values); however, if used to encode information, their entropy rates typically increase (because the encoder will try to utilize all available values).

[0069] Understandably, in a normal TCP protocol stack, the ISN and timestamp are usually driven by the same clock source (although the ISN may be subject to a random factor), and there is a positive correlation between the initial sequence number (ISN) increment and the TCP timestamp (TSval) increment. If the covert channel encoder independently modifies the ISN or TSval without maintaining this correlation, the correlation coefficient between the initial sequence number (ISN) increment and the TCP timestamp (TSval) increment will deviate from the normal range.

[0070] It is understood that the operating system's IPID is typically monotonically increasing (either a global counter or a per-target independent counter), and the direction of IPID change (increase / decrease) should be consistent with the data packet transmission order. If the IPID exhibits random jumps, regressions, or discrepancies with the transmission order, it may indicate encoding behavior. This implementation identifies the presence of such encoding behavior by measuring the consistency between the change pattern of the IP identifier sequence and the data packet transmission order.

[0071] TCP congestion control algorithms can lead to a specific statistical relationship between window size and RTT (e.g., window size is inversely proportional to RTT, or the window size is halved after packet loss). This natural relationship is disrupted if the window size is used to encode information. This implementation identifies this characteristic through the statistical relationship between TCP window size and round-trip time.

[0072] The number of hops can be estimated by subtracting the current TTL from the initial TTL value. If the estimated number of hops differs significantly from the expected number obtained through other methods (such as traceroute or geolocation database), the TTL may have been tampered with for encoding. This implementation identifies this feature by matching the value of the IP Time to Live field with the number of hops in the packet transmission path.

[0073] Cross-session characteristics refer to the statistical characteristics obtained by comparing the protocol stack behavior of the same source device in different TCP sessions. These characteristics include the consistency of the initial sequence number hopping pattern of the same source address in different sessions and the consistency of the IP identifier incrementing pattern of the same source address in different sessions.

[0074] Normal operating system ISN generation algorithms have specific deterministic or pseudo-random characteristics (such as Linux using SipHash encrypted counters). Identifying ISN transition patterns across multiple sessions (such as the difference distribution of ISNs between adjacent sessions) may be considered encoding behavior if it does not conform to the algorithm characteristics of the OS. This implementation identifies this encoding behavior by examining the initial sequence number transition patterns of the same source address in different sessions.

[0075] If the source operating system uses a global IID counter, the IID across sessions should increment continuously (regardless of whether the sessions belong to the same destination address). If the IID is reset, jumps, or rolls back between different sessions, it may be due to encoding interference. This implementation identifies whether encoding interference exists by checking the consistency of the IID increment pattern across different sessions for the same source address.

[0076] In one implementation, the anomaly detection model is a Transformer model based on a self-attention mechanism. The Transformer model uses the joint features of each data packet as an input token for a time step to model the temporal pattern of the data packet sequence. The joint features are input into a pre-trained anomaly detection model to obtain the detection result, including: obtaining the prediction error output by the Transformer model; when the prediction error exceeds a preset threshold, the detection result is determined to indicate the existence of a covert channel.

[0077] The Transformer model can capture long-range dependencies and non-linear interactions between different positions in a data packet sequence. In this implementation, the Transformer model with self-attention mechanism serves as the model architecture for anomaly detection, enabling it to capture the joint features of data packets more accurately.

[0078] In this embodiment, the anomaly detection model may include an input embedding layer, a position encoder, multiple encoder layers, and an output layer. First, the joint feature vector of each data packet is mapped to a high-dimensional space through the input embedding layer. Then, the position encoder adds position encoding (such as sine / cosine encoding or learnable position embedding) to each time step (data packet sequence number). Encoding is performed through the multi-head self-attention sub-layer and feedforward neural network sub-layer (inter-layer residual connection and layer normalization) contained in each of the multiple encoder layers. Finally, the output layer outputs the feature prediction of the next time step or the reconstructed features of the current time step according to the task requirements.

[0079] The anomaly detection model is trained to predict normal traffic. The training process includes: given the joint features of the first k packets, predicting the joint features of the (k+1)th packet (or reconstructing the features of the current packet). The training objective is to minimize the error between the predicted value and the true value (such as mean squared error or cross-entropy).

[0080] In this embodiment, the token is the basic input unit in the Transformer model. This embodiment regards the joint feature vector extracted from each data packet at the extraction time as a token. A data stream containing N data packets is converted into a token sequence of length N, thereby preserving the temporal relationship between data packets and enabling the model to learn the evolution of field values ​​over time in normal traffic.

[0081] In this embodiment, prediction error refers to the difference between the joint feature prediction value of the Transformer model for the current data packet and the actual extracted value. Prediction error can be represented by mean squared error (MSE), cross entropy, or Mahalanobis distance, etc. For data streams containing covert channels, the prediction error will increase significantly because the coding behavior destroys the natural law of field values.

[0082] In one implementation, the preset threshold can be calculated using a validation set (containing only normal traffic). Specifically, it can be the highest quantile of the prediction error on the training set (e.g., the 99th quantile) or the mean plus a certain number of standard deviations. When the prediction error exceeds the threshold, it is determined that the current data stream is abnormal (i.e., contains a covert channel).

[0083] For the corresponding method embodiments described above, see [link to relevant documentation]. Figure 3 The diagram illustrates an information transmission device, comprising: an acquisition module 30 for acquiring a bit stream to be transmitted; an allocation module 32 for allocating the bit stream to multiple protocol header fields of a TCP / IP protocol stack to determine the value to be encoded for each protocol header field; wherein the multiple protocol header fields include at least two or more redundant fields from the IP layer and the TCP layer; a constraint module 34 for applying field constraints to the value to be encoded for each protocol header field to ensure that the encoded protocol header field value conforms to the protocol stack fingerprint characteristics of the target operating system; an encoding module 36 for encoding the value to be encoded for the multiple protocol header fields based on the constraints to obtain the encoded protocol header field value; and a transmission module 38 for generating at least one data packet based on the encoded protocol header field value and transmitting the at least one data packet.

[0084] The aforementioned information transmission device does not require modification of the physical layer or link layer, nor does it require increasing channel bandwidth. It can increase the effective information carrying capacity of a single data packet by utilizing the redundant space of the existing protocol header fields in the TCP / IP protocol stack. At the same time, it is fully compatible with standard protocol stack implementation, requiring no additional network infrastructure deployment, thus reducing the implementation cost and deployment difficulty of improving transmission efficiency.

[0085] Optionally, the allocation module 32 is specifically used to: determine the effective codeable capacity of each protocol header field in the multiple protocol header fields of the TCP / IP protocol stack; wherein the effective codeable capacity is less than or equal to the nominal bit width of the corresponding protocol header field and satisfies the protocol specification constraints; divide the bit stream to be sent into multiple sub-streams according to the effective codeable capacity and the preset reliability level of each protocol header field, and allocate the sub-streams to the multiple protocol header fields of the TCP / IP protocol stack to determine the codeable value corresponding to each protocol header field; wherein the preset reliability level is determined based on the probability that the protocol header field is modified by an intermediate network device, and the sub-stream length allocated to the protocol header field with a higher preset reliability level is greater than the sub-stream length allocated to the protocol header field with a lower reliability level.

[0086] Optionally, the constraint module 34 is specifically used to: obtain pre-stored protocol stack fingerprint parameters of the target operating system, wherein the protocol stack fingerprint parameters include: typical values ​​of each protocol header field, statistical dependencies between protocol header fields, and the change pattern of protocol header field values ​​over time or data packet sequence number; apply legal value range constraints and joint value constraints between at least two protocol header fields to the value to be encoded corresponding to each protocol header field according to the protocol stack fingerprint parameters; and apply reasonable value range constraints of the corresponding protocol header field to the value to be encoded according to a preset encoding rule that matches the corresponding protocol header field.

[0087] Optionally, the encoding module 36 is specifically used to: perform pseudo-random permutation on the data to be encoded of the same data packet based on a preset key and the packet sequence number of the data packet to be generated, so as to determine the mapping relationship between each bit value in the bit stream and the multiple protocol header fields; the data packet is a specified number of consecutive bit values ​​in the bit stream; and based on the constraint, encode the bit value corresponding to each protocol header field to obtain the encoded protocol header field value.

[0088] Optionally, the sending module 38 is specifically used for: performing a protocol stack fingerprint consistency check on the encoded protocol header field value to obtain a check result; if the detection result indicates that the encoded protocol header field value conforms to the protocol stack fingerprint characteristics of the target operating system, then encapsulating a specified number of encoded protocol header field values ​​into data packets to obtain at least one data packet of the bit stream; embedding session metadata in the synchronization sequence number packet during the TCP connection establishment process; wherein the session metadata is used by the receiving end to configure the decoder; and embedding verification information in the last data packet to be sent after the TCP connection is established; wherein the verification information is used by the receiving end to verify the integrity of the session.

[0089] For the corresponding method embodiments described above, see [link to relevant documentation]. Figure 4 The diagram illustrates an information detection device, comprising: a receiving module 40 for receiving a data stream belonging to the same source device and the same destination device; wherein the data stream contains at least one data packet; an extraction module 42 for extracting joint features of the data packet; wherein the joint features include: value distribution features of a single protocol header field, and statistical correlation features between the values ​​of at least two protocol header fields; a detection module 44 for inputting the joint features into a pre-trained anomaly detection model to obtain a detection result; wherein the anomaly detection model is trained based on the joint features of traffic that does not contain a covert channel; and a determination module 46 for determining, based on the detection result, whether the data stream contains a covert channel.

[0090] The aforementioned information detection device, by extracting the distribution features of single fields and the statistical correlation features between fields, can detect the disruption of the natural statistical relationship of protocol header fields by multi-field joint encoding. It adopts an anomaly detection model trained only on normal traffic, and can detect unknown or variant covert channels without knowing the specific encoding algorithm of the covert channel in advance, thereby improving the overall security protection capability of the network.

[0091] Optionally, the value distribution characteristics of a single protocol header field include at least one of the following: a statistical matrix of the corresponding protocol header field value, an autocorrelation coefficient of the corresponding protocol header field value, and an entropy rate of the corresponding protocol header field value; the statistical correlation characteristics between the values ​​of at least two protocol header fields include at least one of the following: a correlation coefficient between the initial sequence number increment and the TCP timestamp increment; a consistency measure between the change pattern of the IP identifier sequence and the packet sending order; a statistical relationship between the TCP window size and the round-trip delay; and a matching degree between the value of the IP time-to-live field and the number of routing hops in the packet transmission path; the joint features also include cross-session features, which include the consistency of the initial sequence number hopping pattern of the same source address in different sessions and the IP identifier increment pattern of the same source address in different sessions.

[0092] Optionally, the anomaly detection model is a Transformer model based on a self-attention mechanism. The Transformer model uses the joint features of each data packet as an input token for a time step to model the temporal pattern of the data packet sequence. The detection module 44 is specifically used to: obtain the prediction error output by the Transformer model, and when the prediction error exceeds a preset threshold, determine that the detection result indicates the existence of a covert channel.

[0093] This embodiment also provides an electronic device, including a processor and a memory. The memory stores machine-executable instructions that can be executed by the processor. The processor executes the machine-executable instructions to implement the aforementioned information transmission and detection method. This electronic device can be a server or a terminal device.

[0094] See Figure 5 As shown, the electronic device includes a processor 100 and a memory 101. The memory 101 stores machine-executable instructions that can be executed by the processor 100. The processor 100 executes the machine-executable instructions to implement the above-mentioned information transmission and detection methods.

[0095] Furthermore, Figure 5 The electronic device shown also includes a bus 102 and a communication interface 103, with the processor 100, the communication interface 103 and the memory 101 connected via the bus 102.

[0096] The memory 101 may include high-speed random access memory (RAM) and may also include non-volatile memory, such as at least one disk storage device. Communication between this system network element and at least one other network element is achieved through at least one communication interface 103 (which can be wired or wireless), such as the Internet, wide area network, local area network, metropolitan area network, etc. The bus 102 may be an ISA bus, PCI bus, or EISA bus, etc. The bus can be divided into address bus, data bus, control bus, etc. For ease of representation, Figure 5 The symbol is represented by a single double-headed arrow, but this does not mean that there is only one bus or one type of bus.

[0097] The processor 100 may be an integrated circuit chip with signal processing capabilities. In implementation, each step of the above method can be completed by the integrated logic circuitry in the hardware of the processor 100 or by instructions in software form. The processor 100 may be a general-purpose processor, including a Central Processing Unit (CPU), a Network Processor (NP), etc.; it may also be a Digital Signal Processor (DSP), an Application Specific Integrated Circuit (ASIC), a Field-Programmable Gate Array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. It can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this disclosure. The general-purpose processor may be a microprocessor or any conventional processor. The steps of the methods disclosed in the embodiments of this disclosure can be directly manifested as execution by a hardware decoding processor, or execution by a combination of hardware and software modules in the decoding processor. The software module can reside in a readily available storage medium in the art, such as random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, or registers. This storage medium is located in memory 101. The processor 100 reads information from memory 101 and, in conjunction with its hardware, completes the steps of the method described in the foregoing embodiments, for example: The information transmission method includes: acquiring a bit stream to be sent; allocating the bit stream to multiple protocol header fields of the TCP / IP protocol stack to determine the value to be encoded for each protocol header field; wherein the multiple protocol header fields include at least two or more redundant fields from the IP layer and the TCP layer; applying field constraints to the value to be encoded for each protocol header field so that the encoded protocol header field value conforms to the protocol stack fingerprint characteristics of the target operating system; encoding the values ​​to be encoded for the multiple protocol header fields based on the constraints to obtain encoded protocol header field values; generating at least one data packet based on the encoded protocol header field values, and sending at least one data packet.

[0098] This information transmission method does not require modification of the physical layer or link layer, nor does it require increasing channel bandwidth. It can increase the effective information carrying capacity of a single data packet by utilizing the redundant space of the existing protocol header fields in the TCP / IP protocol stack. At the same time, it is fully compatible with standard protocol stack implementations, requiring no additional network infrastructure deployment, thus reducing the implementation cost and deployment difficulty of improving transmission efficiency.

[0099] Optionally, the bit stream is allocated to multiple protocol header fields of the TCP / IP protocol stack to determine the value to be encoded corresponding to each protocol header field. This includes: determining the effective codecable capacity of each protocol header field in the TCP / IP protocol stack; wherein the effective codecable capacity is less than or equal to the nominal bit width of the corresponding protocol header field and satisfies protocol specification constraints; based on the effective codecable capacity and the preset reliability level of each protocol header field, the bit stream to be transmitted is divided into multiple sub-streams, and the sub-streams are allocated to multiple protocol header fields of the TCP / IP protocol stack to determine the value to be encoded corresponding to each protocol header field; wherein the preset reliability level is determined based on the probability that the protocol header field is modified by an intermediate network device, and the sub-stream length allocated to a protocol header field with a higher preset reliability level is greater than the sub-stream length allocated to a protocol header field with a lower reliability level.

[0100] Optionally, field constraints are applied to the values ​​to be encoded corresponding to each protocol header field to ensure that the encoded protocol header field values ​​conform to the protocol stack fingerprint characteristics of the target operating system. This includes: obtaining pre-stored protocol stack fingerprint parameters of the target operating system, which include: typical values ​​of each protocol header field, statistical dependencies between protocol header fields, and the changing patterns of protocol header field values ​​over time or packet sequence numbers; applying legal value range constraints and joint value constraints between at least two protocol header fields to the values ​​to be encoded corresponding to each protocol header field based on the protocol stack fingerprint parameters; and applying reasonable value range constraints of the corresponding protocol header field to the values ​​to be encoded for each protocol header field according to a preset encoding rule that matches the corresponding protocol header field.

[0101] Optionally, based on constraints, the values ​​to be encoded for multiple protocol header fields are encoded to obtain encoded protocol header field values. This includes: performing pseudo-random permutations on the data to be encoded for the same data packet based on a preset key and the packet sequence number of the data packet to be generated, in order to determine the mapping relationship between each bit value in the bit stream and multiple protocol header fields; the data packet is a specified number of consecutive bit values ​​in the bit stream; and based on constraints, the bit values ​​corresponding to each protocol header field are encoded to obtain encoded protocol header field values.

[0102] Optionally, based on the encoded protocol header field values, at least one data packet is generated and sent, including: performing a protocol stack fingerprint consistency check on the encoded protocol header field values ​​and obtaining the check result; if the check result indicates that the encoded protocol header field values ​​conform to the protocol stack fingerprint characteristics of the target operating system, then encapsulating a specified number of encoded protocol header field values ​​into data packets to obtain at least one data packet of the bit stream; during the TCP connection establishment process, embedding session metadata in the synchronization sequence number packet; wherein, the session metadata is used by the receiving end to configure the decoder; for the last data packet to be sent after the TCP connection is established, embedding verification information in the last data packet to be sent; wherein, the verification information is used by the receiving end to verify the integrity of the session.

[0103] The information detection method includes: receiving a data stream belonging to the same source device and the same destination device; wherein the data stream contains at least one data packet; extracting joint features of the data packets; wherein the joint features include: value distribution features of a single protocol header field, and statistical correlation features between the values ​​of at least two protocol header fields; inputting the joint features into a pre-trained anomaly detection model to obtain a detection result; wherein the anomaly detection model is trained based on the joint features of traffic that does not contain a covert channel; and determining whether the data stream contains a covert channel based on the detection result.

[0104] This information detection method, by extracting the distribution features of single fields and the statistical correlation features between fields, can discover the disruption of the natural statistical relationship of protocol header fields by multi-field joint encoding. It adopts an anomaly detection model trained only on normal traffic, and can detect unknown or variant covert channels without knowing the specific encoding algorithm of the covert channel in advance, thereby improving the overall security protection capability of the network.

[0105] Optionally, the value distribution characteristics of a single protocol header field include at least one of the following: a statistical matrix of the corresponding protocol header field value, an autocorrelation coefficient of the corresponding protocol header field value, and an entropy rate of the corresponding protocol header field value; the statistical correlation characteristics between the values ​​of at least two protocol header fields include at least one of the following: the correlation coefficient between the initial sequence number increment and the TCP timestamp increment; the consistency measure between the IP identifier sequence change pattern and the packet sending order; the statistical relationship between the TCP window size and the round-trip delay; the matching degree between the value of the IP time-to-live field and the number of routing hops in the packet transmission path; the joint features also include: cross-session features, which include: the consistency of the initial sequence number hopping pattern of the same source address in different sessions, and the consistency of the IP identifier increment pattern of the same source address in different sessions.

[0106] Optionally, the anomaly detection model is a Transformer model based on a self-attention mechanism. The Transformer model uses the joint features of each data packet as an input token for a time step to model the temporal pattern of the data packet sequence. The joint features are input into the pre-trained anomaly detection model to obtain the detection result, including: obtaining the prediction error output by the Transformer model. When the prediction error exceeds a preset threshold, the detection result is determined to indicate the existence of a covert channel.

[0107] This embodiment also provides a computer-readable storage medium storing computer-executable instructions. When these computer-executable instructions are invoked and executed by a processor, they cause the processor to implement the aforementioned information transmission and detection methods, for example: The information transmission method includes: acquiring a bit stream to be sent; allocating the bit stream to multiple protocol header fields of the TCP / IP protocol stack to determine the value to be encoded for each protocol header field; wherein the multiple protocol header fields include at least two or more redundant fields from the IP layer and the TCP layer; applying field constraints to the value to be encoded for each protocol header field so that the encoded protocol header field value conforms to the protocol stack fingerprint characteristics of the target operating system; encoding the values ​​to be encoded for the multiple protocol header fields based on the constraints to obtain encoded protocol header field values; generating at least one data packet based on the encoded protocol header field values, and sending at least one data packet.

[0108] This information transmission method does not require modification of the physical layer or link layer, nor does it require increasing channel bandwidth. It can increase the effective information carrying capacity of a single data packet by utilizing the redundant space of the existing protocol header fields in the TCP / IP protocol stack. At the same time, it is fully compatible with standard protocol stack implementations, requiring no additional network infrastructure deployment, thus reducing the implementation cost and deployment difficulty of improving transmission efficiency.

[0109] Optionally, the bit stream is allocated to multiple protocol header fields of the TCP / IP protocol stack to determine the value to be encoded corresponding to each protocol header field. This includes: determining the effective codecable capacity of each protocol header field in the TCP / IP protocol stack; wherein the effective codecable capacity is less than or equal to the nominal bit width of the corresponding protocol header field and satisfies protocol specification constraints; based on the effective codecable capacity and the preset reliability level of each protocol header field, the bit stream to be transmitted is divided into multiple sub-streams, and the sub-streams are allocated to multiple protocol header fields of the TCP / IP protocol stack to determine the value to be encoded corresponding to each protocol header field; wherein the preset reliability level is determined based on the probability that the protocol header field is modified by an intermediate network device, and the sub-stream length allocated to a protocol header field with a higher preset reliability level is greater than the sub-stream length allocated to a protocol header field with a lower reliability level.

[0110] Optionally, field constraints are applied to the values ​​to be encoded corresponding to each protocol header field to ensure that the encoded protocol header field values ​​conform to the protocol stack fingerprint characteristics of the target operating system. This includes: obtaining pre-stored protocol stack fingerprint parameters of the target operating system, which include: typical values ​​of each protocol header field, statistical dependencies between protocol header fields, and the changing patterns of protocol header field values ​​over time or packet sequence numbers; applying legal value range constraints and joint value constraints between at least two protocol header fields to the values ​​to be encoded corresponding to each protocol header field based on the protocol stack fingerprint parameters; and applying reasonable value range constraints of the corresponding protocol header field to the values ​​to be encoded for each protocol header field according to a preset encoding rule that matches the corresponding protocol header field.

[0111] Optionally, based on constraints, the values ​​to be encoded for multiple protocol header fields are encoded to obtain encoded protocol header field values. This includes: performing pseudo-random permutations on the data to be encoded for the same data packet based on a preset key and the packet sequence number of the data packet to be generated, in order to determine the mapping relationship between each bit value in the bit stream and multiple protocol header fields; the data packet is a specified number of consecutive bit values ​​in the bit stream; and based on constraints, the bit values ​​corresponding to each protocol header field are encoded to obtain encoded protocol header field values.

[0112] Optionally, based on the encoded protocol header field values, at least one data packet is generated and sent, including: performing a protocol stack fingerprint consistency check on the encoded protocol header field values ​​and obtaining the check result; if the check result indicates that the encoded protocol header field values ​​conform to the protocol stack fingerprint characteristics of the target operating system, then encapsulating a specified number of encoded protocol header field values ​​into data packets to obtain at least one data packet of the bit stream; during the TCP connection establishment process, embedding session metadata in the synchronization sequence number packet; wherein, the session metadata is used by the receiving end to configure the decoder; for the last data packet to be sent after the TCP connection is established, embedding verification information in the last data packet to be sent; wherein, the verification information is used by the receiving end to verify the integrity of the session.

[0113] The information detection method includes: receiving a data stream belonging to the same source device and the same destination device; wherein the data stream contains at least one data packet; extracting joint features of the data packets; wherein the joint features include: value distribution features of a single protocol header field, and statistical correlation features between the values ​​of at least two protocol header fields; inputting the joint features into a pre-trained anomaly detection model to obtain a detection result; wherein the anomaly detection model is trained based on the joint features of traffic that does not contain a covert channel; and determining whether the data stream contains a covert channel based on the detection result.

[0114] This information detection method, by extracting the distribution features of single fields and the statistical correlation features between fields, can discover the disruption of the natural statistical relationship of protocol header fields by multi-field joint encoding. It adopts an anomaly detection model trained only on normal traffic, and can detect unknown or variant covert channels without knowing the specific encoding algorithm of the covert channel in advance, thereby improving the overall security protection capability of the network.

[0115] Optionally, the value distribution characteristics of a single protocol header field include at least one of the following: a statistical matrix of the corresponding protocol header field value, an autocorrelation coefficient of the corresponding protocol header field value, and an entropy rate of the corresponding protocol header field value; the statistical correlation characteristics between the values ​​of at least two protocol header fields include at least one of the following: the correlation coefficient between the initial sequence number increment and the TCP timestamp increment; the consistency measure between the IP identifier sequence change pattern and the packet sending order; the statistical relationship between the TCP window size and the round-trip delay; the matching degree between the value of the IP time-to-live field and the number of routing hops in the packet transmission path; the joint features also include: cross-session features, which include: the consistency of the initial sequence number hopping pattern of the same source address in different sessions, and the consistency of the IP identifier increment pattern of the same source address in different sessions.

[0116] Optionally, the anomaly detection model is a Transformer model based on a self-attention mechanism. The Transformer model uses the joint features of each data packet as an input token for a time step to model the temporal pattern of the data packet sequence. The joint features are input into the pre-trained anomaly detection model to obtain the detection result, including: obtaining the prediction error output by the Transformer model. When the prediction error exceeds a preset threshold, the detection result is determined to indicate the existence of a covert channel.

[0117] The computer program products of the information transmission and detection methods, apparatus, electronic devices and storage media provided in the embodiments of this disclosure include a computer-readable storage medium storing program code. The instructions included in the program code can be used to execute the methods described in the preceding method embodiments. For specific implementation, please refer to the method embodiments, which will not be repeated here.

[0118] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working process of the system and apparatus described above can be referred to the corresponding process in the foregoing method embodiments, and will not be repeated here.

[0119] Furthermore, in the description of the embodiments of this disclosure, unless otherwise expressly specified and limited, the terms "installation," "connection," and "linking" should be interpreted broadly. For example, they can refer to a fixed connection, a detachable connection, or an integral connection; they can refer to a mechanical connection or an electrical connection; they can refer to a direct connection or an indirect connection through an intermediate medium; and they can refer to the internal connection of two components. Those skilled in the art can understand the specific meaning of the above terms in this disclosure based on the specific circumstances.

[0120] If the aforementioned functions are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this disclosure, in essence, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this disclosure. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0121] In the description of this disclosure, it should be noted that the terms "center," "upper," "lower," "left," "right," "vertical," "horizontal," "inner," and "outer," etc., indicate the orientation or positional relationship based on the orientation or positional relationship shown in the accompanying drawings, and are only for the convenience of describing this disclosure and simplifying the description, and do not indicate or imply that the device or element referred to must have a specific orientation, or be constructed and operated in a specific orientation, and therefore should not be construed as a limitation of this disclosure. Furthermore, the terms "first," "second," and "third" are used for descriptive purposes only and should not be construed as indicating or implying relative importance.

[0122] Finally, it should be noted that the above embodiments are merely specific implementations of this disclosure, used to illustrate the technical solutions of this disclosure, and not to limit it. The protection scope of this disclosure is not limited thereto. Although this disclosure has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that any person skilled in the art can still modify or easily conceive of changes to the technical solutions described in the foregoing embodiments, or make equivalent substitutions for some of the technical features, within the scope of the technology disclosed in this disclosure. Such modifications, changes, or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this disclosure, and should all be covered within the protection scope of this disclosure. Therefore, the protection scope of this disclosure should be determined by the protection scope of the claims.

Claims

1. An information transmission method, characterized in that, The method includes: Obtain the bit stream to be sent; The bit stream is assigned to multiple protocol header fields of the TCP / IP protocol stack to determine the value to be encoded for each protocol header field; wherein, the multiple protocol header fields include at least two or more redundant fields from the IP layer and the TCP layer; Apply field constraints to the value to be encoded for each protocol header field so that the encoded protocol header field value conforms to the protocol stack fingerprint characteristics of the target operating system; Based on the constraints, the values ​​to be encoded in the plurality of protocol header fields are encoded to obtain the encoded protocol header field values; Based on the encoded protocol header field values, at least one data packet is generated and sent.

2. The method according to claim 1, characterized in that, The bitstream is assigned to multiple header fields of the TCP / IP protocol stack to determine the value to be encoded for each header field, including: Determine the effective codeable capacity of each protocol header field in the TCP / IP protocol stack; wherein the effective codeable capacity is less than or equal to the nominal bit width of the corresponding protocol header field and satisfies the protocol specification constraints; Based on the effective codeable capacity and the preset reliability level of each protocol header field, the bit stream to be transmitted is divided into multiple sub-streams, and the sub-streams are assigned to multiple protocol header fields of the TCP / IP protocol stack to determine the value to be encoded for each protocol header field; wherein, the preset reliability level is determined based on the probability that the protocol header field is modified by an intermediate network device, and the sub-stream length assigned to the protocol header field with a higher preset reliability level is greater than the sub-stream length assigned to the protocol header field with a lower reliability level.

3. The method according to claim 1, characterized in that, Apply field constraints to the value to be encoded for each protocol header field to ensure that the encoded protocol header field value conforms to the protocol stack fingerprint characteristics of the target operating system, including: Obtain the pre-stored protocol stack fingerprint parameters of the target operating system. The protocol stack fingerprint parameters include: typical values ​​of each protocol header field, statistical dependencies between protocol header fields, and the change pattern of protocol header field values ​​over time or data packet sequence number. Based on the protocol stack fingerprint parameters, apply a legal value range constraint and a joint value constraint between at least two protocol header fields to the value to be encoded. For each value to be encoded corresponding to a protocol header field, a reasonable range of values ​​for the corresponding protocol header field is constrained for the corresponding value to be encoded according to a preset encoding rule that matches the corresponding protocol header field.

4. The method according to claim 1, characterized in that, Based on the constraints, the values ​​to be encoded in the plurality of protocol header fields are encoded to obtain encoded protocol header field values, including: Based on a preset key and the packet sequence number of the data packet to be generated, pseudo-random permutation is performed on the data to be encoded in the same data packet to determine the mapping relationship between each bit value in the bit stream and the multiple protocol header fields; the data packet is a specified number of consecutive bit values ​​in the bit stream; Based on the constraints, the bit values ​​corresponding to each protocol header field are encoded to obtain the encoded protocol header field values.

5. The method according to claim 1, characterized in that, Based on the encoded protocol header field values, generate at least one data packet and send the at least one data packet, including: Perform a protocol stack fingerprint consistency check on the encoded protocol header field values ​​and obtain the check results; If the detection result indicates that the encoded protocol header field value conforms to the protocol stack fingerprint characteristics of the target operating system, then a specified number of encoded protocol header field values ​​are encapsulated into data packets to obtain at least one data packet of the bit stream. During the TCP connection establishment process, session metadata is embedded in the synchronization sequence number packet; wherein, the session metadata is used by the receiving end to configure the decoder; For the last data packet to be sent after the TCP connection is established, verification information is embedded in the last data packet to be sent; wherein, the verification information is used by the receiving end to verify the integrity of the session.

6. An information detection method, characterized in that, The method includes: Receive a data stream belonging to the same source device and the same destination device; wherein the data stream contains at least one data packet; Extract the joint features of the data packet; wherein the joint features include: the value distribution features of a single protocol header field, and the statistical correlation features between the values ​​of at least two protocol header fields; The joint features are input into a pre-trained anomaly detection model to obtain the detection result; wherein, the anomaly detection model is trained based on the joint features of traffic that does not include covert channels; Based on the detection results, it is determined whether the data stream contains a covert channel.

7. The method according to claim 6, characterized in that, The value distribution characteristics of a single protocol header field include at least one of the following: a statistical matrix of the corresponding protocol header field value, an autocorrelation coefficient of the corresponding protocol header field value, and an entropy rate of the corresponding protocol header field value; The statistical correlation characteristics between the values ​​of the at least two protocol header fields include at least one of the following: The correlation coefficient between the initial sequence number increment and the TCP timestamp increment; A measure of consistency between the variation pattern of IP identifier sequences and the order in which data packets are sent; Statistical relationship between TCP window size and round-trip latency; The degree of matching between the value of the IP Time to Live field and the number of hops in the packet transmission path; The joint features also include cross-session features, which include the consistency of the initial sequence number hopping pattern of the same source address in different sessions and the consistency of the IP identifier incrementing pattern of the same source address in different sessions.

8. The method according to claim 6, characterized in that, The anomaly detection model is a Transformer model based on a self-attention mechanism. The Transformer model uses the joint features of each data packet as an input token for a time step to model the temporal pattern of the data packet sequence. The step of inputting the joint features into a pre-trained anomaly detection model to obtain detection results includes: The prediction error output by the Transformer model is obtained. When the prediction error exceeds a preset threshold, the detection result is determined to indicate the existence of a hidden channel.

9. An information transmission device, characterized in that, The device includes: The acquisition module is used to acquire the bit stream to be sent; The allocation module is used to allocate the bit stream to multiple protocol header fields of the TCP / IP protocol stack to determine the value to be encoded corresponding to each protocol header field; wherein, the multiple protocol header fields include at least two or more redundant fields from the IP layer and the TCP layer; The constraint module is used to apply field constraints to the values ​​to be encoded corresponding to each protocol header field, so that the encoded protocol header field values ​​conform to the protocol stack fingerprint characteristics of the target operating system. An encoding module is used to encode the values ​​to be encoded of the plurality of protocol header fields based on the constraints, so as to obtain the encoded protocol header field values; The sending module is used to generate at least one data packet based on the encoded protocol header field value, and to send the at least one data packet.

10. An information detection device, characterized in that, The device includes: A receiving module is configured to receive a data stream belonging to the same source device and the same destination device; wherein the data stream contains at least one data packet; An extraction module is used to extract joint features of the data packet; wherein the joint features include: value distribution features of a single protocol header field, and statistical correlation features between the values ​​of at least two protocol header fields; The detection module is used to input the joint features into a pre-trained anomaly detection model to obtain the detection result; wherein, the anomaly detection model is trained based on the joint features of traffic that does not contain covert channels; The determination module is used to determine, based on the detection results, whether the data stream is a data stream containing a covert channel.

11. An electronic device, characterized in that, It includes a processor and a memory, the memory storing machine-executable instructions that can be executed by the processor, the processor executing the machine-executable instructions to implement the information transmission method or information detection method according to any one of claims 1-8.

12. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions, which, when invoked and executed by a processor, cause the processor to implement the information transmission method or information detection method according to any one of claims 1-8.