• DocumentCode
    3293908
  • Title

    On Tuning the Knobs of Distribution-Based Methods for Detecting VoIP Covert Channels

  • Author

    Arackaparambil, Chrisil ; Yan, Guanhua ; Bratus, Sergey ; Caglayan, Alper

  • Author_Institution
    Dept. of Comput. Sci., Dartmouth Coll., Dartmouth, MA, USA
  • fYear
    2012
  • fDate
    4-7 Jan. 2012
  • Firstpage
    2431
  • Lastpage
    2440
  • Abstract
    We study the parameters (knobs) of distribution-based anomaly detection methods, and how their tuning affects the quality of detection. Specifically, we analyze the popular entropy-based anomaly detection in detecting covert channels in Voice over IP (VoIP) traffic. There has been little effort in prior research to rigorously analyze how the knobs of anomaly detection methodology should be tuned. Such analysis is, however, critical before such methods can be deployed by a practitioner. We develop a probabilistic model to explain the effects of the tuning of the knobs on the rate of false positives and false negatives. We then study the observations produced by our model analytically as well as empirically. We examine the knobs of window length and detection threshold. Our results show how the knobs should be set for achieving high rate of detection, while maintaining a low rate of false positives. We also show how the throughput of the covert channel (the magnitude of the anomaly) affects the rate of detection, thereby allowing a practitioner to be aware of the capabilities of the methodology.
  • Keywords
    IP networks; Internet telephony; entropy; probability; security of data; telecommunication security; telecommunication traffic; VoIP covert channel detection; detection threshold; distribution-based anomaly detection method; entropy-based anomaly detection; knobs tuning; probabilistic model; voice over IP traffic; window length; Analytical models; Entropy; Measurement; Monitoring; Noise; Protocols; Tuning;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    System Science (HICSS), 2012 45th Hawaii International Conference on
  • Conference_Location
    Maui, HI
  • ISSN
    1530-1605
  • Print_ISBN
    978-1-4577-1925-7
  • Electronic_ISBN
    1530-1605
  • Type

    conf

  • DOI
    10.1109/HICSS.2012.456
  • Filename
    6149309