Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

4 results about "Covert channel" patented technology

In computer security, a covert channel is a type of attack that creates a capability to transfer information objects between processes that are not supposed to be allowed to communicate by the computer security policy. The term, originated in 1973 by Lampson, is defined as channels "not intended for information transfer at all, such as the service program's effect on system load," to distinguish it from legitimate channels that are subjected to access controls by COMPUSEC.

Industrial control protocol covert channel detection method and system

The application provides an industrial control protocol covert channel detection method and system, the method comprises the following steps: obtaining multi-source industrial control network communication data, obtaining conversation flow, command flow and field level change sequence through protocol identification and hierarchical analysis; dividing three behavior windows of fixed time length, conversation length and logical transaction, extracting communication events to form multi-granularity behavior sequence; calculating information entropy, transition entropy or structure entropy and normalizing to construct dynamic baseline entropy image; detecting entropy variation drift based on adaptive sliding threshold, marking abnormal interval; performing multi-dimensional feature clustering on entropy variation events and combining logical verification to output suspected covert channel instances; generating a traceability report and feeding back optimized detection model parameters. Through multi-scale entropy analysis and closed-loop optimization, the application realizes high-precision, low-false alarm and adaptive detection of the covert channel.
Owner:GUANGZHOU ELECTRIC POWER COMM NETWORK LTD

Detecting covert channels in role based cloud access control policies using large language model (LLM)

Literature on access control policies in cloud computing has focused on the design of secure models of access or on the syntactic and semantic analysis of policies but not into aspect of covert channel. A method and system for detecting covert channels in role based cloud access control policies using Large Language Model (LLM) is disclosed. A set of access control policies and an access specification is analyzed by the LLM for presence of violation indicating an implicit path between an entity (principal) and a restricted resource. Further, the LLM is prompted to generate a script Python program, which in turn generates a graph to visually depict paths leading from principal to one or more resources in the cloud environment, wherein any implicit access to the restricted resource if detected is highlighted by introducing a path from the principal to the restricted resources with label as covert channel. The covert channel so depicted provides information on possible theft threats.
Owner:TATA CONSULTANCY SERVICES LTD

DNS covert channel detection method based on Transform

The invention belongs to the technical field of network security, and relates to a DNS covert channel detection method based on Transform. Comprising the following steps: S1, acquiring a DNS query data packet in network traffic by using a network data packet capturing tool; s2, extracting a multi-dimensional feature set from the DNS query data packet; s3, carrying out preprocessing on the multi-dimensional feature set; s4, constructing a detection model based on multi-dimensional feature fusion and a self-adaptive Transform; s5, training the detection model by using the labeled DNS covert channel sample data set; and S6, processing DNS query data to be detected according to the steps S1-S3, inputting the DNS query data to be detected into the trained Transform detection model, and outputting a detection result. By adopting the technical scheme of the invention, the detection accuracy is obviously improved, the false alarm rate is greatly reduced, and the complex code detection capability is stronger.
Owner:CHANGSHA UNIVERSITY OF SCIENCE AND TECHNOLOGY

A secure communication method for heterogeneous Internet of Things

This invention relates to a secure communication method for heterogeneous Internet of Things (IoT), comprising: a control terminal establishing a covert channel according to a communication protocol with a controlled terminal; sending an encryption method and a random key to the controlled terminal via the covert channel; establishing a secure channel with the control terminal; encrypting user-input control commands to obtain ciphertext; transmitting the ciphertext to the controlled terminal via the established secure channel; decrypting the ciphertext using the acquired encryption method and random key to obtain a decryption command; converting the decryption command according to a protocol and forwarding it to a specified destination address via a corresponding port; the device at the destination address executing the corresponding operation according to the decryption command and returning the corresponding requested resource; encrypting the requested resource using the acquired encryption method and random key to obtain an encrypted request resource; converting the encrypted request resource according to a protocol and forwarding it to the control terminal via a corresponding port; the control terminal receiving the encrypted request resource returned by the controlled terminal; decrypting the encrypted request resource using the selected encryption method and random key to obtain the decrypted request resource; and printing the decrypted request resource on a command-line interface for display to the user. This invention improves the concealment of network communication.
Owner:CHONGQING UNIV OF POSTS & TELECOMM