As an effective anti-censorship mechanism, network covert channels can provide data privacy protection and ensure communication security. However, the covertness of existing network covert channels primarily depends on the secrecy of their covert algorithms. With the increasing depth of research in this field, the difficulty of breaking such algorithms has gradually decreased. Once the algorithm is exposed, the network covert channel can be easily detected by adversaries. To address this issue, this paper proposes a covert carrier filtering strategy based on the hash. In this strategy, a key-dependent filtering rule is introduced during the construction of the network covert channel, enabling the communicating parties to randomly and dynamically filter a sparse subset from the carrier set as the covert carrier set. This strategy not only enhances the randomness of carrier selection but also tightly couples the covertness of the network covert channel with the security of the key. We employ machine learning-based traffic analysis methods to experimentally validate the strategy in two types of network covert channels: network storage and timing covert channels. The experimental results demonstrate that the proposed strategy significantly improves the detection resistance of network covert channels. When the filter key size exceeds six bits, the impact on the detection effect of the classifier becomes quite significant. Furthermore, the processing delay for a single packet is less than 8 $μs$, indicating the feasibility of deploying the proposed strategy in high-speed network environments.
翻译:作为一种有效的反 censorship 机制,网络隐蔽信道能够提供数据隐私保护并确保通信安全。然而,现有网络隐蔽信道的隐蔽性主要依赖于其隐蔽算法的保密性。随着该领域研究的深入,此类算法被攻破的难度逐渐降低。一旦算法泄露,网络隐蔽信道极易被对手检测。针对此问题,本文提出一种基于散列的隐写载体过滤策略。该策略在网络隐蔽信道构建过程中引入密钥相关的过滤规则,使通信双方能够从载体集中随机、动态地筛选出稀疏子集作为隐写载体集。该策略不仅增强了载体选择的随机性,还将网络隐蔽信道的隐蔽性与密钥的安全性紧密耦合。我们采用基于机器学习的流量分析方法,在两种网络隐蔽信道——网络存储与时延隐蔽信道——中对该策略进行实验验证。实验结果表明,所提策略显著提升了网络隐蔽信道的抗检测能力。当过滤密钥长度超过六位时,对分类器检测效果的影响已相当显著。此外,单个数据包的处理延迟小于 8 $μs$,证实了该策略在高速网络环境中部署的可行性。