计算机科学 ›› 2026, Vol. 53 ›› Issue (6A): 250200069-11.doi: 10.11896/jsjkx.250200069

• 信息安全 • 上一篇    下一篇

基于基线特征的ICMP隐蔽信道恶意流量检测方法

段海影1, 王宝会1, 黄河2   

  1. 1 北京航空航天大学软件学院 北京 100191
    2 航天物联网技术有限公司 北京 100076
  • 出版日期:2026-06-16 发布日期:2026-06-12
  • 通讯作者: 王宝会(wangbh@buaa.edu.cn)
  • 作者简介:(zf2021126@buaa.edu.cn)

Malicious Traffic Detection Method of ICMP Covert Channel Based on Baseline Features

DUAN Haiying1, WANG Baohui1, HUANG He2   

  1. 1 School of Software,Beihang University,Beijing 100191,China
    2 Aerospace Internet of Things Technology Co.,Ltd.,Beijing 100076,China
  • Published:2026-06-16 Online:2026-06-12
  • About author:DUAN Haiying,born in 1995,postgra-duate.Her main research interests include network security and artificial intelligence,etc.
    WANG Baohui,born in 1973,professor,master's supervisor.His main research interests includenetwork security,big data and artificial intelligence.

摘要: ICMP是用来进行网络管理的技术,网络攻击者常将其用于实施远程控制、数据窃取和恶意攻击等非法行为。ICMP是近年来网络攻击中常见的一种隐蔽通信手段,给受害主机带来了严重的安全隐患。针对ICMP隐蔽信道攻击日益严峻的形势以及ICMP数据流特征复杂、难以识别且具有较强隐蔽性的特点,在现有研究中发现采用机器学习进行ICMP隐蔽信道恶意流量检测时存在特征提取不足的问题,且模型的鲁棒性和泛化能力较差。因此,提出了一种基于基线特征的ICMP隐蔽信道恶意流量检测方法,以应对这些挑战。首先,对ICMP良性流量和隐蔽信道流量进行基线分析,提出了5个具有良好区分度的特征:数据报文平均长度、数据报文频率、会话持续时间、请求与回复报文比值以及报文数据信息熵值。然后,结合多种机器学习模型构建二元分类器,用于恶意流量的检测。实验结果表明,所提方法在检测ICMP隐蔽信道恶意流量时,准确率、召回率和F1值分别达到99.53%,99.51%和99.5%,相比现有方法分别提高2.83个百分点、2.97个百分点和2.88个百分点。此外,考虑到基线特征容易被攻击者通过动态调整或混淆技术绕过,增加基于对抗训练与集成学习的ICMP隧道检测方法,通过生成对抗样本增强模型鲁棒性,结合深度注意力网络与传统机器学习模型的优势,有效识别隐蔽隧道流量。主要采用PGD(Projected Gradient Descent)攻击生成对抗样本,引入多头注意力机制提取深层特征,并通过MLP预测结果,最终准确率提升到了99.63%。实验表明,该方法在对抗环境下提升了检测准确率与鲁棒性。此外,该方法具有毫秒级流量解析和检测能力,能够有效适应实际场景中的ICMP隐蔽信道流量检测需求。

关键词: ICMP隐蔽信道, 基线特征, PGD, 注意力机制, 机器学习

Abstract: ICMP is used for network management technology.Network attackers often use it to carry out illegal actions such as remote control,data theft and malicious attacks.It is a common method of hidden communication in network attacks in recent years,which brings serious security risks to the victim host.In view of the increasingly severe situation of ICMP covert channel attacks and the characteristics of ICMP data flow that are complex,difficult to identify and have strong concealment,it is found that there are insufficient feature extraction when using machine learning to detect malicious traffic in ICMP covert channel in existing research,and the robustness and generalization ability of the model are poor.Therefore,a baseline feature-based malicious traffic detection method for ICMP covert channels is proposed to address these challenges.Firstly,the baseline analysis of ICMP benign traffic and covert channel traffic is carried out,and five features with good discrimination are proposed:average data packet length,data packet frequency,session duration,ratio of request to reply packets,and message data information entropy.Then,a binary classifier is constructed by combining multiple machine learning models for malicious traffic detection.The experimental results show that the accuracy,recall and F1 value of the proposed method reach 99.53%,99.51%and 99.5%respectively,which are 2.83 persentage points,2.97 persentage points and 2.88 persentage points higher than those of the existing methods.In addition,considering that the baseline features are easy to be bypass by attackers through dynamic adjustment or obfuscating techniques,this paper adds an ICMP tunnel detection method based on adversarial training and ensemble learning,which enhances the robustness of the model by generating adversarial samples,and combines the advantages of deep attention network and traditional machine learning models to effectively identify covert tunnel traffic.The proposed method mainly uses PGD attack to generate adversarial samples,introduces a multi-head attention mechanism to extract deep features,and predicts the results through MLP.The final accuracy is improved to 99.63%.Experiments show that the proposed method improves the detection accuracy and robustness in the adversarial environment.In addition,the proposed method has millisecond level traffic analysis and detection capabilities,which can effectively adapt to the actual ICMP covert channel traffic detection requirements.

Key words: ICMP covert channel, Baseline features, PGD, Attention mechanism, Machine learning

中图分类号: 

  • TP393
[1] LI Y,GUO H,HOU J,et al.A Survey of Encrypted Malicious Traffic Detection[C]//2021 International Conference on Communications,Computing,Cybersecurity,and Informatics(CCCI).IEEE,2021:1-7.
[2] LI Z,SI C,CHENG Z,et al.MLMTD:A Multi-Layer Malicious Traffic Detection Model Based on Multi-Branch Octave Convolution and Attention Mechanism[C]//ICASSP 2024 IEEE International Conference on Acoustics,Speech and Signal Processing(ICASSP).IEEE,2024:4880-4884.
[3] GU G M,CHEN W H,HUANG W D.A Covert Tunnel and Encrypted Malicious Traffic Detection Method Based on Multi-Model Fusion[J].Netinfo Security,2024,24(5):694-708.
[4] DONG S,XIA Y,PENG T.Network abnormal traffic detection model based on semi-supervised deep reinforcement learning[J].IEEE Transactions on Network and Service Management,2021,18(4):4197-4212.
[5] SUI Z,SHU H,KANG F,et al.A Comprehensive Review of Tunnel Detection on Multilayer Protocols:From Traditional to Machine Learning Approaches.Applied Sciences.2023,13(3):1974.
[6] LI R,ZHANG LQ,LI H F,et al.Survey of Entropy-Based Network Traffic Anomaly Detection Methods[J].Computer Systems and Applications,2017,26(6):36-39.
[7] LU G,GUO R H, ZHOU Y,et al.Review of Malicious Traffic Feature Extraction[J].Netinfo Security,2018,18(9):1-9.
[8] LIU Y,GOU X.Research on Application of Feature Analysis Method in DNS Tunnel Detection[C]//Journal of Physics:Conference Series.IQP Publishing,2020.
[9] WU K,ZHANG Y Z,YIN T.FTPB:A Three-stage DNS Tunnel Detection Method Based on Character Feature Extraction[C]//19th International Conference on Trust,Security and Privacy in Computing and Communications(TrustCom).IEEE,2020:250-258.
[10] PETERIE S L,IVANOV J,KNIPPEL E,et al.Shallow tunnel detection using converted surface waves[J].Geophysics,2021,86(3):WB59-WB68.
[11] WANG F,HUANG L,CHEN Z,et al.A novel web tunnel detection method based on protocol behaviors[C]//International Conference on Security and Privacy in Communication Systems.Cham:Springer,2013:234-251.
[12] TU T,YIN W,ZHANG H,et al.Icmptend:internet controlmessage protocol covert tunnel attack intent detector[J].Computer,Materials & Continua,2022,71(2):2315-2331.
[13] WANG Z Y,CHEN S P.Self-Supervised Network Intrusion Detection Model Based on Graph Contrastive Learning[J].Electronic Science and Technology,2025,38(3):22-31.
[14] YANG P,LI Y,ZANG Y.Detecting DNS covert channels using stacking model[J].China Communications,2020,17(10):183-194.
[15] LI X D,ZHANG Y M,LI Y Q,et al.DNS Covert Channel Detection Algorithm Based on Multi-channel Convolution Neural Network and Attention Mechanism[J].Science Technology and Engineering,2024,24(35):15137-15144.
[16] WAN X,PENG Y,HAO R,et al.Capturing Spatial-Temporal Correlations with Attention Based Graph Convolutional Networks for Network Traffic Prediction[C]//2023 15th International Conference on Communication Software and Networks(ICCSN).IEEE,2023:95-99.
[17] LIN X,XIONG G,GOU G,et al.Et-bert:A contextualized datagram representation with pre-training transformers for encrypted traffic classification[C]//Proceedings of the ACM Web Conference 2022.2022:633-642.
[18] ROESCH M.Snort:Lightweight intrusion detection for net-works[C]//13th LISA Conference.1999:229-238.
[19] Ad-Aware offical website [EB/OL].https://www.adaware.com/.
[20] LIN H,LIU G,YAN Z.Detection of application-layer tunnelswith rules and machine learning[C]//International Conference on Security,Privacy and Anonymity in Computation,Communication and Storage.Cham:Springer,2019:441-455.
[21] LIU J,LI S,ZHANG Y,et al.Detecting DNS tunnel through binary-classification based on behavior features[C]//Trustcom/BigDataSE/ICESS.IEEE,2017:339-346.
[22] LI Y X,ZHOU A M,ZHENG R F,et al.Detection of Network Storage Covert Channel over ICMP Protocol Based on SVM[J].Journal of Information Security Research,2022,6(2):122-130.
[23] XU X D,WANG C A,ZHU S R.Covert channel detection in ICMP payload based on information entropy SVM[J].Journal of Computer Applications,2009,29(7):1796-1798.
[24] SAYADI S,ABBES T,BOUHOULA A.Detection of coverttunnels over ICMP protocol[C]//14th International Conference on Computer Systems and Applications.IEEE,2017:1247-1252.
[25] HAN X,XU L,REN M,et al.A naive bayesian network intrusion detection algorithm based on principal component analysis[C]//7th International Conference on Information Technology in Medicine and Education.IEEE,2015:325-328.
[26] ALMUSAWI A,ARNINTOOSI H.DNS Tunneling detectionmethod based on multilabel support vector machine[J/OL].https://doi.org/10.1155/2018/6137098.
[27] PALAU F,CATANIA C,GUERRA J,et al.DNS tunneling:a deep learning based lexicographical detection approach[J].arXiv:2006.06122,2020.
[28] WANG Y,AN J,HUANG W.Using CNN-based representation learning method for malicious traffic identification[C]//17th International Conference on Computer and Information Science.IEEE,2018:400-404.
[29] Icmptunnel offical website [EB/OL].https://github.com/Dha-valKapillicmp.
[30] LI Q,WANG B,WEN X,et al.Malicious traffic predictionmodel for ResNet based on Maple-IDS dataset[J].Network Daily News,2025(May):23-24.
Viewed
Full text


Abstract

Cited

  Shared   
  Discussed   
No Suggested Reading articles found!