ACM Home Page
Please provide us with feedback. Feedback
Detecting covert timing channels: an entropy-based approach
Full text PdfPdf (256 KB)
Source
Conference on Computer and Communications Security archive
Proceedings of the 14th ACM conference on Computer and communications security table of contents
Alexandria, Virginia, USA
SESSION: Side and covert channels detection table of contents
Pages: 307 - 316  
Year of Publication: 2007
ISBN:978-1-59593-703-2
Authors
Steven Gianvecchio  The College of William and Mary, Williamsburg, VA
Haining Wang  The College of William and Mary, Williamsburg, VA
Sponsors
ACM: Association for Computing Machinery
SIGSAC: ACM Special Interest Group on Security, Audit, and Control
Publisher
ACM  New York, NY, USA
Bibliometrics
Downloads (6 Weeks): 18,   Downloads (12 Months): 178,   Citation Count: 2
Additional Information:

abstract   references   cited by   index terms   collaborative colleagues  

Tools and Actions: Request Permissions Request Permissions    Review this Article  
DOI Bookmark: Use this link to bookmark this Article: http://doi.acm.org/10.1145/1315245.1315284
What is a DOI?

ABSTRACT

The detection of covert timing channels is of increasing interest in light of recent practice on the exploitation of covert timing channels over the Internet. However, due to the high variation in legitimate network traffic, detecting covert timing channels is a challenging task. The existing detection schemes are ineffective to detect most of the covert timing channels known to the security community. In this paper, we introduce a new entropy-based approach to detecting various covert timing channels. Our new approach is based on the observation that the creation of a covert timing channel has certain effects on the entropy of the original process, and hence, a change in the entropy of a process provides a critical clue for covert timing channel detection. Exploiting this observation, we investigate the use of entropy and conditional entropy in detecting covert timing channels. Our experimental results show that our entropy-based approach is sensitive to the current covert timing channels, and is capable of detecting them in an accurate manner.


REFERENCES

Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.

1
 
2
Arimoto, S. An algorithm for computing the capacity of arbitrary discrete memoryless channels. IEEE Transactions on Information Theory Vol. 18, No. 1 (January 1972).
 
3
Berk, V., Giani, A., and Cybenko, G. Covert channel detection using process query systems. In Proceedings of FLOCON 2005 (September 2005).
 
4
Berk, V., Giani, A., and Cybenko, G. Detection of covert channel encoding in network packet delays. Tech. Rep. TR2005-536, Dartmouth College, Computer Science, Hanover, NH., USA, August 2005.
 
5
Blahut, R. E. Computation of channel capacity and rate-distortion functions. IEEE Transactions on Information Theory Vol. 18, No. 4 (July 1972).
 
6
7
 
8
 
9
 
10
Giffin, J., Greenstadt, R., Litwack, P., and Tibbetts, R. Covert messaging through TCP timestamps. In Proceedings of the 2002 International Workshop on Privacy Enhancing Technologies (April 2002).
 
11
Giles, J., and Hajek, B. An information-theoretic and game-theoretic study of timing channels. IEEE Transactions on Information Theory Vol. 48, No. 9 (September 2002).
 
12
Hu, W.-M. Reducing timing channels with fuzzy time. In Proceedings of the 1991 IEEE Symposium on Security and Privacy (May 1991).
13
 
14
 
15
 
16
 
17
 
18
Porta, A., Baselli, G., Liberati, D., Montano, N., Cogliati, C., Gnecchi-Ruscone, T., Malliani, A., and Cerutti, S. Measuring regularity by meansof a corrected conditional entropy in sympathetic outflow. Biological Cybernetics Vol. 78, No. 1 (January 1998).
 
19
Rosipal, R. Kernel-Based Regression and Objective Nonlinear Measures to Assess Brain Functioning. PhD thesis, University of Paisley, Paisley, Scotland, UK, September 2001.
 
20
 
21
Shannon, C. A mathematical theory of communication. Bell System Technical Journal Vol. 27 (July and October 1948).
22
23


Collaborative Colleagues:
Steven Gianvecchio: colleagues
Haining Wang: colleagues