应用科学学报 ›› 2013, Vol. 31 ›› Issue (3): 278-284.doi: 10.3969/j.issn.0255-8297.2013.03.010

• 信号与信息处理 • 上一篇    下一篇

基于水印信息重排序的多流攻击反制方法

王振兴1, 张连成1, 郭毅1, 李硕2   

  1. 1. 解放军信息工程大学网络空间安全学院,郑州450001
    2. 北京302医院,北京100039
  • 收稿日期:2011-11-20 修回日期:2012-03-06 出版日期:2013-05-28 发布日期:2012-03-06
  • 作者简介:王振兴,教授,博导,研究方向:流量分析、网络与信息安全,E-mail:wzx05@sina.com
  • 基金资助:

    国家“973”重点基础研究发展计划基金(No.2007CB307102); 国家“863” 高技术研究发展计划基金(No.2007AA01Z2A1,
    No. 2012AA012902)资助

Multi-flow Attack Resistance Based on Reordering of Watermark Bits

WANG Zhen-xing1, ZHANG Lian-cheng1, GUO Yi1, LI Shuo2   

  1. 1. College of Cyberspace Security, PLA Information Engineering University, Zhengzhou 450001, China
    2. Beijing 302 Hospital, Beijing 100039, China
  • Received:2011-11-20 Revised:2012-03-06 Online:2013-05-28 Published:2012-03-06

摘要: 网络流水印是一种网络攻击源主动追踪技术,但根据其流间依赖关系实施的多流攻击对流水印可用性构成严重威胁. 提出基于水印信息重排序的多流攻击反制方法,对于不同的目标数据流,采用不同的随机种子来随机选择水印信息的不同排列进行嵌入,有效消除了已标记数据流之间的依赖关系. 分析与实验结果表明,该方法可抵御多流攻击. 与嵌入位置随机化方法相比,误报率低,而且对水印检测器性能影响小,是一种抵御多流攻击的有效方法.

关键词: 网络流水印, 多流攻击, 水印信息重排序, 嵌入位置随机化

Abstract: Network flow watermarking is a technique for active tracing of network attacks. Multi-flow attack makes use of dependences among different watermarked network flows, and thus poses a great challenge to the applicability of flow watermarking. This paper proposes a multi-flow attack resistance method based on reordering of watermark bits that combats the multi-flow attack. The method randomizes the bit order of the watermark message across multiple flows based on different random seeds, therefore effectively removing cross-correlations among watermarked flows. Theoretical analysis and experimental evaluation show that the proposed method is robust against multi-flow attack. Compared with insertion position randomization, the method is more effective in resisting multi-flow attack. It neither increase false positive rate, nor requires high computation cost.

Key words: network flow watermarking, multi-flow attack, watermark bit reordering, insertion position randomization

中图分类号: