IEEE Access | |
Efficient Non-Linear Covert Channel Detection in TCP Data Streams | |
Kashif Naseer Qureshi1  Hanaa Nafea2  Qi Shi2  Bob Askwith2  Kashif Kifayat3  | |
[1] Department of Computer Science, Bahria University, Islamabad, Pakistan;Department of Computer Science, Liverpool John Moores University, Liverpool, U.K.;Department of Cyber Security, Air University, Islamabad, Pakistan; | |
关键词: Data leakage; network steganography; covert channel; TCP/IP protocol; | |
DOI : 10.1109/ACCESS.2019.2961609 | |
来源: DOAJ |
【 摘 要 】
Cyber-attacks are causing losses amounted to billions of dollars every year due to data breaches and Vulnerabilities. The existing tools for data leakage prevention and detection are often bypassed by using various different types of sophisticated techniques such as network steganography for stealing the data. This is due to several weaknesses which can be exploited by a threat actor in of existing detection systems. The weaknesses are high time and memory training complexities as well as large training datasets. These challenges become worse when the amount of generated data increasing in every second in many realms. In addition, the number of false positives is high which make them inaccurate. Finally, there is a lack of a framework catering the needs such as raising alerts as well as data monitoring and updating/adapting of a threshold value used for checking the data packets for covert data. In order to overcome these weaknesses, this paper proposes a novel framework that includes elements such as continuous data monitoring, threshold maintenance, and alert notification. This paper also proposes a model based on statistical measures to detects covert data leakages, especially for non-linear chaotic data. The main advantage of proposed model is its capability to provide results with tolerance/threshold values much more efficiently. Experiment are indicated that the proposed framework has low false positives and outperforms over various existing techniques in terms of accuracy and efficiency.
【 授权许可】
Unknown