Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

7 results about "Covert channel" patented technology

In computer security, a covert channel is a type of attack that creates a capability to transfer information objects between processes that are not supposed to be allowed to communicate by the computer security policy. The term, originated in 1973 by Lampson, is defined as channels "not intended for information transfer at all, such as the service program's effect on system load," to distinguish it from legitimate channels that are subjected to access controls by COMPUSEC.

Self-adaptive hybrid covert channel construction method based on dynamic flow perception

The invention provides a self-adaptive hybrid covert channel construction method based on dynamic flow perception, and belongs to the technical field of covert communication and network security. The method comprises the following steps: constructing a hybrid covert channel comprising a time sequence type covert channel and a storage type covert channel to transmit secret information; monitoring the flow condition of the network in real time and calculating the network congestion degree; determining the proportion of a time sequence type covert channel and a storage type covert channel in the mixed type covert channel based on the network congestion degree; segmenting the to-be-sent secret information according to the belonging proportion to obtain to-be-sent information of a time sequence type covert channel and to-be-sent information of a storage type covert channel; the time sequence type hidden channel to-be-sent information is sent through the time sequence type hidden channel; and sending the to-be-sent information of the storage type covert channel through the storage type covert channel. The method can adapt to changes of different network loads and crowdedness degrees, the reliability and concealment of data concealed transmission are guaranteed, and the requirements of two communication parties for safe communication are met.
Owner:NORTHEASTERN UNIV CHINA

Covert channel identification method, device, computer equipment and storage medium

This application discloses a covert channel identification method, apparatus, computer device, and storage medium. The method includes obtaining a DNS tunnel domain name to be detected, extracting target domain name features of the DNS tunnel domain name using a DFA algorithm, performing feature enhancement processing on the target domain name features using a convolutional neural network algorithm and a long short-term memory algorithm, respectively, to obtain local enhancement features corresponding to the convolutional neural network algorithm and global enhancement features corresponding to the long short-term memory algorithm; and determining whether the DNS tunnel domain name is a DNS covert tunnel domain name of a covert channel based on the fused features of the local and global enhancement features. This method can effectively improve recognition accuracy, reduce the possibility of misjudgment, and thus improve the efficiency of covert channel identification.
Owner:CHINA MOBILE INFORMATION TECHNOLOGY CO LTD +1

Industrial control protocol covert channel detection method and system

The application provides an industrial control protocol covert channel detection method and system, the method comprises the following steps: obtaining multi-source industrial control network communication data, obtaining conversation flow, command flow and field level change sequence through protocol identification and hierarchical analysis; dividing three behavior windows of fixed time length, conversation length and logical transaction, extracting communication events to form multi-granularity behavior sequence; calculating information entropy, transition entropy or structure entropy and normalizing to construct dynamic baseline entropy image; detecting entropy variation drift based on adaptive sliding threshold, marking abnormal interval; performing multi-dimensional feature clustering on entropy variation events and combining logical verification to output suspected covert channel instances; generating a traceability report and feeding back optimized detection model parameters. Through multi-scale entropy analysis and closed-loop optimization, the application realizes high-precision, low-false alarm and adaptive detection of the covert channel.
Owner:GUANGZHOU ELECTRIC POWER COMM NETWORK LTD

Detecting covert channels in role based cloud access control policies using large language model (LLM)

Literature on access control policies in cloud computing has focused on the design of secure models of access or on the syntactic and semantic analysis of policies but not into aspect of covert channel. A method and system for detecting covert channels in role based cloud access control policies using Large Language Model (LLM) is disclosed. A set of access control policies and an access specification is analyzed by the LLM for presence of violation indicating an implicit path between an entity (principal) and a restricted resource. Further, the LLM is prompted to generate a script Python program, which in turn generates a graph to visually depict paths leading from principal to one or more resources in the cloud environment, wherein any implicit access to the restricted resource if detected is highlighted by introducing a path from the principal to the restricted resources with label as covert channel. The covert channel so depicted provides information on possible theft threats.
Owner:TATA CONSULTANCY SERVICES LTD

DNS covert channel detection method based on Transform

The invention belongs to the technical field of network security, and relates to a DNS covert channel detection method based on Transform. Comprising the following steps: S1, acquiring a DNS query data packet in network traffic by using a network data packet capturing tool; s2, extracting a multi-dimensional feature set from the DNS query data packet; s3, carrying out preprocessing on the multi-dimensional feature set; s4, constructing a detection model based on multi-dimensional feature fusion and a self-adaptive Transform; s5, training the detection model by using the labeled DNS covert channel sample data set; and S6, processing DNS query data to be detected according to the steps S1-S3, inputting the DNS query data to be detected into the trained Transform detection model, and outputting a detection result. By adopting the technical scheme of the invention, the detection accuracy is obviously improved, the false alarm rate is greatly reduced, and the complex code detection capability is stronger.
Owner:CHANGSHA UNIVERSITY OF SCIENCE AND TECHNOLOGY

A secure communication method for heterogeneous Internet of Things

This invention relates to a secure communication method for heterogeneous Internet of Things (IoT), comprising: a control terminal establishing a covert channel according to a communication protocol with a controlled terminal; sending an encryption method and a random key to the controlled terminal via the covert channel; establishing a secure channel with the control terminal; encrypting user-input control commands to obtain ciphertext; transmitting the ciphertext to the controlled terminal via the established secure channel; decrypting the ciphertext using the acquired encryption method and random key to obtain a decryption command; converting the decryption command according to a protocol and forwarding it to a specified destination address via a corresponding port; the device at the destination address executing the corresponding operation according to the decryption command and returning the corresponding requested resource; encrypting the requested resource using the acquired encryption method and random key to obtain an encrypted request resource; converting the encrypted request resource according to a protocol and forwarding it to the control terminal via a corresponding port; the control terminal receiving the encrypted request resource returned by the controlled terminal; decrypting the encrypted request resource using the selected encryption method and random key to obtain the decrypted request resource; and printing the decrypted request resource on a command-line interface for display to the user. This invention improves the concealment of network communication.
Owner:CHONGQING UNIV OF POSTS & TELECOMM

APT covert channel identification method and system for multimodal anomaly detection

The present invention relates to the technical field of APT covert channel identification methods, and provides an APT covert channel identification method and system for multimodal anomaly detection, which aims to solve the problem of detecting covert channels in advanced persistent threat (APT) attacks. Through multimodal anomaly detection, the method can identify and analyze APT attacks in complex network environments, especially those using covert channels. The present invention provides an APT covert channel identification method for multimodal anomaly detection, which includes obtaining multimodal data, normal behavior modeling, joint representation learning, enhancing anomaly sensitivity, capturing time series anomaly patterns, optimizing anomaly features, updating anomaly detection models, APT covert channel identification, and generating detection reports. The present invention is used to improve the detection accuracy of APT covert channels, reduce false alarm rates, increase detection delays, enhance the adaptability of models, and reduce computing resource consumption, thereby providing enterprises with powerful network security protection measures.
Owner:UNIV OF ELECTRONICS SCI & TECH OF CHINA