高安全级网络中信息隐蔽传输分析及检测
Analysis and Detection of Covert Information Transfers in MLS Network
-
摘要: 针对一种难以用隔离设备消除的、以夹带方式在确定概率分布中隐蔽信息的传输方法,提出了修改的属性偏移检测法和卡方检测法,前者用多个报警值门限来降低多单值检测导致的虚警率,后者选取部分近似均匀概率并进一步合并来提高检测效率.2种方法均不同程度地提高了检出概率.Abstract: Regarding the issue of network covert channels hidden in overt sources with fixed probability distribution,two detection methods are proposed.One is an improved attribute shift test and the other is a modified Pearson chi-square test.In attribute shift test we use k warnings instead of one warning to indicate detection.In chi-square test we incorporate adjacent probability values.The two methods improve detection accuracy in different degrees.Advantages of the detection methods are verified by experiments.