摘要
网络隐蔽信道利用正常网络协议传递隐蔽信息,能够为木马、间谍软件等恶意通信规避安全检测提供载体。针对现有隐蔽信道数量众多、特征繁杂、检测不便等问题,在分析其通信模型及应用模式的基础上,提出了一种基于实现机制的分类方法,从协议和字段的根本特点出发研究了隐蔽信道的异常特征,分析了现有检测方法及其缺陷,给出了下一步的研究方向。
Network covert channel uses normal network protocols to pass hidden information,which can provide carriers for Trojan,spyware etc.to circumvent security detection.Aiming at the problems that number of convert channels is large,the features are complicated and the detection is inconvenient,we analysed the communication model and application model,proposed a classification method based implementation mechanisms and abnormal features of network covert channel according to the basic features of protocols and fields,analysed existing detection methods and their weaknesses.And the future research direction was given.
出处
《计算机科学》
CSCD
北大核心
2015年第7期216-221,244,共7页
Computer Science
基金
国家973计划项目(2011CB311801)
河南省科技创新人才计划项目(114200510001)资助
关键词
网络隐蔽信道
实现机制
异常特征
检测技术
Network covert channel
Implementation mechanism
Abnormal features
Detection techniques