Visible to the public Towards Distributed Network Covert Channels Detection Using Data Mining-Based Approach

TitleTowards Distributed Network Covert Channels Detection Using Data Mining-Based Approach
Publication TypeConference Paper
Year of Publication2018
AuthorsCabaj, Krzysztof, Mazurczyk, Wojciech, Nowakowski, Piotr, \textbackslash.Zórawski, Piotr
Conference NameProceedings of the 13th International Conference on Availability, Reliability and Security
Date PublishedAugust 2018
PublisherACM
Conference LocationNew York, NY, USA
ISBN Number978-1-4503-6448-5
Keywordscompositionality, covert channels, data hiding, data mining, Information hiding, resilience, Scalability
Abstract

Currently, due to improvements in defensive systems network covert channels are increasingly drawing attention of cybercriminals and malware developers as they can provide stealthiness of the malicious communication and thus to bypass existing security solutions. On the other hand, the utilized data hiding methods are getting increasingly sophisticated as the attackers, in order to stay under the radar, distribute the covert data among many connections, protocols, etc. That is why, the detection of such threats becomes a pressing issue. In this paper we make an initial step in this direction by presenting a data mining-based detection of such advanced threats which relies on pattern discovery technique. The obtained, initial experimental results indicate that such solution has potential and should be further investigated.

URLhttps://dl.acm.org/doi/10.1145/3230833.3233264
DOI10.1145/3230833.3233264
Citation Keycabaj_towards_2018