DocumentCode :
3293908
Title :
On Tuning the Knobs of Distribution-Based Methods for Detecting VoIP Covert Channels
Author :
Arackaparambil, Chrisil ; Yan, Guanhua ; Bratus, Sergey ; Caglayan, Alper
Author_Institution :
Dept. of Comput. Sci., Dartmouth Coll., Dartmouth, MA, USA
fYear :
2012
fDate :
4-7 Jan. 2012
Firstpage :
2431
Lastpage :
2440
Abstract :
We study the parameters (knobs) of distribution-based anomaly detection methods, and how their tuning affects the quality of detection. Specifically, we analyze the popular entropy-based anomaly detection in detecting covert channels in Voice over IP (VoIP) traffic. There has been little effort in prior research to rigorously analyze how the knobs of anomaly detection methodology should be tuned. Such analysis is, however, critical before such methods can be deployed by a practitioner. We develop a probabilistic model to explain the effects of the tuning of the knobs on the rate of false positives and false negatives. We then study the observations produced by our model analytically as well as empirically. We examine the knobs of window length and detection threshold. Our results show how the knobs should be set for achieving high rate of detection, while maintaining a low rate of false positives. We also show how the throughput of the covert channel (the magnitude of the anomaly) affects the rate of detection, thereby allowing a practitioner to be aware of the capabilities of the methodology.
Keywords :
IP networks; Internet telephony; entropy; probability; security of data; telecommunication security; telecommunication traffic; VoIP covert channel detection; detection threshold; distribution-based anomaly detection method; entropy-based anomaly detection; knobs tuning; probabilistic model; voice over IP traffic; window length; Analytical models; Entropy; Measurement; Monitoring; Noise; Protocols; Tuning;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
System Science (HICSS), 2012 45th Hawaii International Conference on
Conference_Location :
Maui, HI
ISSN :
1530-1605
Print_ISBN :
978-1-4577-1925-7
Electronic_ISBN :
1530-1605
Type :
conf
DOI :
10.1109/HICSS.2012.456
Filename :
6149309
Link To Document :
بازگشت