• DocumentCode
    3559057
  • Title

    Detection of Information Flows

  • Author

    He, Ting ; Tong, Lang

  • Author_Institution
    Cornell Univ., Ithaca, NY
  • Volume
    54
  • Issue
    11
  • fYear
    2008
  • Firstpage
    4925
  • Lastpage
    4945
  • Abstract
    The detection of information flows by timing analysis is considered. Given transmission timestamps of monitored nodes, the problem is to decide whether there is an information flow through these nodes by analyzing the transmission patterns. Due to constraints that packets from an information flow need to be delivered within certain delay or the relay nodes have bounded memory, transmission patterns of an information flow are statistically different from those of independent traffic. The main result of this paper is a tight characterization of the maximum amount of chaff noise such that Chernoff-consistent detection is achievable. The direct part of the result is an explicit construction of a detector that has vanishing false alarm and miss probabilities as the sample size increases whenever the noise level is below certain threshold. Conversely, when the noise level is above this threshold, there exist means to hide the information flow such that it is indistinguishable from independent traffic. Explicit characterization of the noise threshold is provided for Poisson transmission schedules. It is also shown that while information flows can be hidden among chaff noise for a small number of hops, the rate of information flow diminishes as the number of hops increases.
  • Keywords
    ad hoc networks; security of data; stochastic processes; telecommunication security; telecommunication traffic; Chernoff-consistent detection; Poisson transmission schedule; information flow detection; intrusion detection; probability; timing analysis; traffic analysis; transmission pattern; wireless ad hoc network; Detectors; Helium; Information analysis; Intrusion detection; Monitoring; Noise level; Pattern analysis; Relays; Telecommunication traffic; Timing; Information flow; intrusion detection and security; network flows; point processes and inference; timing analysis and timing channels;
  • fLanguage
    English
  • Journal_Title
    Information Theory, IEEE Transactions on
  • Publisher
    ieee
  • ISSN
    0018-9448
  • Type

    jour

  • DOI
    10.1109/TIT.2008.929944
  • Filename
    4655453