计算机与现代化

• 信息安全 • 上一篇    下一篇

基于One-class SVM的网络时间隐蔽信道检测方法

  

  1. (南京理工大学计算机科学与工程学院,江苏 南京 210094)
  • 收稿日期:2016-11-01 出版日期:2017-06-23 发布日期:2017-06-23
  • 作者简介:刘义(1990-),男,江苏宿迁人,南京理工大学计算机科学与工程学院硕士研究生,研究方向:计算机网络和安全; 兰少华(1958-),男,江苏南京人,教授,硕士生导师,博士,研究方向:计算机网络及应用,网络安全,分布式人工智能。
  • 基金资助:
    国家自然科学基金资助项目(61170250, 61103201)

Approach for Detecting Covert Timing Channels Based on One-class SVM

  1. (School of Computer Science and Engineering, Nanjing University of Science and Technology, Nanjing 210094, China)
  • Received:2016-11-01 Online:2017-06-23 Published:2017-06-23

摘要: 网络时间隐蔽信道的检测是网络隐蔽信道研究中的热点和难点。当前的网络时间隐蔽信道的检测方法更多是针对某个或者某些特定的网络时间隐蔽信道,不具备通用性。本文利用机器学习中的SVM思想,提出一种基于One-class SVM的通用检测方法。把时间隐蔽信道的检测看作是一种单值分类问题,利用正常信道数据集进行训练,构建分类模型。实验表明该检测方法在保证较高检测率的同时,又具备较好的通用性,可以比较有效地检测出多种网络时间隐蔽信道。

关键词: 时间隐蔽信道, 单类支持向量机, 网络安全

Abstract: The detection of covert timing channel is the focus and the difficulty of the research on covert channel. Current detections of covert timing channels are more directed against some particular covert timing channels, not all applicable. In this paper, a detection approach based on one-class SVM was introduced. Detection of covert channels is seen as a one-calss calssification problem. The model-building part of the algorithm works trained by the common channel set and generates the classification model. Experimental results show that the detection method can not only ensure a higher detection rate and better versatility, but also effectively detect covert timing channels.

Key words: covert timing channel, one-class SVM, network security

中图分类号: