<div class="csl-bib-body">
<div class="csl-entry">Iglesias Vazquez, F., Annessi, R., & Zseby, T. (2017). Analytic Study of Features for the Detection of Covert Timing Channels in Network Traffic. <i>Journal of Cyber Security and Mobility</i>, <i>6</i>(3), 245–270. https://doi.org/10.13052/2245-1439.632</div>
</div>
-
dc.identifier.issn
2245-1439
-
dc.identifier.uri
http://hdl.handle.net/20.500.12708/147429
-
dc.description.abstract
Covert timing channels are security threats that have concerned the expert community from the beginnings of secure computer networks. In this paper we explore the nature of covert timing channels by studying the behavior of a selection of features used for their detection. Insights are obtained from experimental studies based on ten covert timing channels techniques published in the literature, which include popular and novel approaches. The study digs into the shapes of flows containing covert timing channels from a statistical perspective as well as using supervised and unsupervised machine learning algorithms. Our experiments reveal which features are recommended for building detection methods and draw meaningful representations to understand the problem space. Covert timing channels show high histogram-distance based outlierness, but insufficient to clearly discriminate them from normal traffic. On the other hand, traffic features do show dependencies that allow separating subspaces and facilitate the identification of covert timing channels. The conducted study shows the detection difficulties due to the high shape variability of normal traffic and suggests the implementation of semi-supervised techniques to develop accurate and reliable detectors.
en
dc.language.iso
en
-
dc.relation.ispartof
Journal of Cyber Security and Mobility
-
dc.subject
Hardware and Architecture
-
dc.subject
classification
-
dc.subject
Computer Networks and Communications
-
dc.subject
network traffic analysis
-
dc.subject
covert timing channels
-
dc.subject
anomaly detection
-
dc.title
Analytic Study of Features for the Detection of Covert Timing Channels in Network Traffic
-
dc.type
Artikel
de
dc.type
Article
en
dc.description.startpage
245
-
dc.description.endpage
270
-
dc.type.category
Original Research Article
-
tuw.container.volume
6
-
tuw.container.issue
3
-
tuw.journal.peerreviewed
true
-
tuw.peerreviewed
true
-
tuw.researchTopic.id
I7
-
tuw.researchTopic.id
I1
-
tuw.researchTopic.name
Telecommunication
-
tuw.researchTopic.name
Logic and Computation
-
tuw.researchTopic.value
50
-
tuw.researchTopic.value
50
-
dcterms.isPartOf.title
Journal of Cyber Security and Mobility
-
tuw.publication.orgunit
E389-01 - Forschungsbereich Networks
-
tuw.publisher.doi
10.13052/2245-1439.632
-
dc.description.numberOfPages
26
-
wb.sciencebranch
Elektrotechnik, Elektronik, Informationstechnik
-
wb.sciencebranch.oefos
2020
-
wb.facultyfocus
Telekommunikation
de
wb.facultyfocus
Telecommunications
en
wb.facultyfocus.faculty
E350
-
item.grantfulltext
none
-
item.openairecristype
http://purl.org/coar/resource_type/c_2df8fbb1
-
item.openairetype
research article
-
item.languageiso639-1
en
-
item.cerifentitytype
Publications
-
item.fulltext
no Fulltext
-
crisitem.author.dept
E389-01 - Forschungsbereich Networks
-
crisitem.author.dept
E389 - Institute of Telecommunications
-
crisitem.author.dept
E389-01 - Forschungsbereich Networks
-
crisitem.author.orcid
0000-0001-6081-969X
-
crisitem.author.orcid
0000-0002-5391-467X
-
crisitem.author.parentorg
E389 - Institute of Telecommunications
-
crisitem.author.parentorg
E350 - Fakultät für Elektrotechnik und Informationstechnik