How to Make an Intrusion Detection SystemAware of Steganographic Transmission


연구 분야: Safety



학회: EICC '21: Proceedings of the 2021 European Interdisciplinary Cybersecurity Conference


초록

Information hiding techniques are becoming a major threat in network communication. This paper describes how to modify an intrusion detection system (IDS) to detect certain types of steganography. As a sample IDS we use open-source Zeek software. We show how to adapt it for the purpose of steganalysis. Additionally, we propose a set of validation tests that are suitable for detecting steganography and describe how they were applied to different types of covert channels. We also suggest how to build a steganography detection system by integrating Zeek with a security information and event management system with log and alert support. The scripts are freely available for download.


Author Profile
Tomasz Koziak

Warsaw University of Technology Poland

Poland
Author Profile
Katarzyna Wasielewska

Warsaw University of Technology Poland

Poland
Author Profile
Artur Janicki

Warsaw University of Technology Poland

Poland

📄 논문 정보

발행 연도 2021년
인용수 8
출판 국가 Poland
사이트 ACM
좋아요 수 0

연관 논문 목록 (345건)