计算机科学 ›› 2026, Vol. 53 ›› Issue (6A): 250200069-11.doi: 10.11896/jsjkx.250200069
段海影1, 王宝会1, 黄河2
DUAN Haiying1, WANG Baohui1, HUANG He2
摘要: ICMP是用来进行网络管理的技术,网络攻击者常将其用于实施远程控制、数据窃取和恶意攻击等非法行为。ICMP是近年来网络攻击中常见的一种隐蔽通信手段,给受害主机带来了严重的安全隐患。针对ICMP隐蔽信道攻击日益严峻的形势以及ICMP数据流特征复杂、难以识别且具有较强隐蔽性的特点,在现有研究中发现采用机器学习进行ICMP隐蔽信道恶意流量检测时存在特征提取不足的问题,且模型的鲁棒性和泛化能力较差。因此,提出了一种基于基线特征的ICMP隐蔽信道恶意流量检测方法,以应对这些挑战。首先,对ICMP良性流量和隐蔽信道流量进行基线分析,提出了5个具有良好区分度的特征:数据报文平均长度、数据报文频率、会话持续时间、请求与回复报文比值以及报文数据信息熵值。然后,结合多种机器学习模型构建二元分类器,用于恶意流量的检测。实验结果表明,所提方法在检测ICMP隐蔽信道恶意流量时,准确率、召回率和F1值分别达到99.53%,99.51%和99.5%,相比现有方法分别提高2.83个百分点、2.97个百分点和2.88个百分点。此外,考虑到基线特征容易被攻击者通过动态调整或混淆技术绕过,增加基于对抗训练与集成学习的ICMP隧道检测方法,通过生成对抗样本增强模型鲁棒性,结合深度注意力网络与传统机器学习模型的优势,有效识别隐蔽隧道流量。主要采用PGD(Projected Gradient Descent)攻击生成对抗样本,引入多头注意力机制提取深层特征,并通过MLP预测结果,最终准确率提升到了99.63%。实验表明,该方法在对抗环境下提升了检测准确率与鲁棒性。此外,该方法具有毫秒级流量解析和检测能力,能够有效适应实际场景中的ICMP隐蔽信道流量检测需求。
中图分类号:
| [1] LI Y,GUO H,HOU J,et al.A Survey of Encrypted Malicious Traffic Detection[C]//2021 International Conference on Communications,Computing,Cybersecurity,and Informatics(CCCI).IEEE,2021:1-7. [2] LI Z,SI C,CHENG Z,et al.MLMTD:A Multi-Layer Malicious Traffic Detection Model Based on Multi-Branch Octave Convolution and Attention Mechanism[C]//ICASSP 2024 IEEE International Conference on Acoustics,Speech and Signal Processing(ICASSP).IEEE,2024:4880-4884. [3] GU G M,CHEN W H,HUANG W D.A Covert Tunnel and Encrypted Malicious Traffic Detection Method Based on Multi-Model Fusion[J].Netinfo Security,2024,24(5):694-708. [4] DONG S,XIA Y,PENG T.Network abnormal traffic detection model based on semi-supervised deep reinforcement learning[J].IEEE Transactions on Network and Service Management,2021,18(4):4197-4212. [5] SUI Z,SHU H,KANG F,et al.A Comprehensive Review of Tunnel Detection on Multilayer Protocols:From Traditional to Machine Learning Approaches.Applied Sciences.2023,13(3):1974. [6] LI R,ZHANG LQ,LI H F,et al.Survey of Entropy-Based Network Traffic Anomaly Detection Methods[J].Computer Systems and Applications,2017,26(6):36-39. [7] LU G,GUO R H, ZHOU Y,et al.Review of Malicious Traffic Feature Extraction[J].Netinfo Security,2018,18(9):1-9. [8] LIU Y,GOU X.Research on Application of Feature Analysis Method in DNS Tunnel Detection[C]//Journal of Physics:Conference Series.IQP Publishing,2020. [9] WU K,ZHANG Y Z,YIN T.FTPB:A Three-stage DNS Tunnel Detection Method Based on Character Feature Extraction[C]//19th International Conference on Trust,Security and Privacy in Computing and Communications(TrustCom).IEEE,2020:250-258. [10] PETERIE S L,IVANOV J,KNIPPEL E,et al.Shallow tunnel detection using converted surface waves[J].Geophysics,2021,86(3):WB59-WB68. [11] WANG F,HUANG L,CHEN Z,et al.A novel web tunnel detection method based on protocol behaviors[C]//International Conference on Security and Privacy in Communication Systems.Cham:Springer,2013:234-251. [12] TU T,YIN W,ZHANG H,et al.Icmptend:internet controlmessage protocol covert tunnel attack intent detector[J].Computer,Materials & Continua,2022,71(2):2315-2331. [13] WANG Z Y,CHEN S P.Self-Supervised Network Intrusion Detection Model Based on Graph Contrastive Learning[J].Electronic Science and Technology,2025,38(3):22-31. [14] YANG P,LI Y,ZANG Y.Detecting DNS covert channels using stacking model[J].China Communications,2020,17(10):183-194. [15] LI X D,ZHANG Y M,LI Y Q,et al.DNS Covert Channel Detection Algorithm Based on Multi-channel Convolution Neural Network and Attention Mechanism[J].Science Technology and Engineering,2024,24(35):15137-15144. [16] WAN X,PENG Y,HAO R,et al.Capturing Spatial-Temporal Correlations with Attention Based Graph Convolutional Networks for Network Traffic Prediction[C]//2023 15th International Conference on Communication Software and Networks(ICCSN).IEEE,2023:95-99. [17] LIN X,XIONG G,GOU G,et al.Et-bert:A contextualized datagram representation with pre-training transformers for encrypted traffic classification[C]//Proceedings of the ACM Web Conference 2022.2022:633-642. [18] ROESCH M.Snort:Lightweight intrusion detection for net-works[C]//13th LISA Conference.1999:229-238. [19] Ad-Aware offical website [EB/OL].https://www.adaware.com/. [20] LIN H,LIU G,YAN Z.Detection of application-layer tunnelswith rules and machine learning[C]//International Conference on Security,Privacy and Anonymity in Computation,Communication and Storage.Cham:Springer,2019:441-455. [21] LIU J,LI S,ZHANG Y,et al.Detecting DNS tunnel through binary-classification based on behavior features[C]//Trustcom/BigDataSE/ICESS.IEEE,2017:339-346. [22] LI Y X,ZHOU A M,ZHENG R F,et al.Detection of Network Storage Covert Channel over ICMP Protocol Based on SVM[J].Journal of Information Security Research,2022,6(2):122-130. [23] XU X D,WANG C A,ZHU S R.Covert channel detection in ICMP payload based on information entropy SVM[J].Journal of Computer Applications,2009,29(7):1796-1798. [24] SAYADI S,ABBES T,BOUHOULA A.Detection of coverttunnels over ICMP protocol[C]//14th International Conference on Computer Systems and Applications.IEEE,2017:1247-1252. [25] HAN X,XU L,REN M,et al.A naive bayesian network intrusion detection algorithm based on principal component analysis[C]//7th International Conference on Information Technology in Medicine and Education.IEEE,2015:325-328. [26] ALMUSAWI A,ARNINTOOSI H.DNS Tunneling detectionmethod based on multilabel support vector machine[J/OL].https://doi.org/10.1155/2018/6137098. [27] PALAU F,CATANIA C,GUERRA J,et al.DNS tunneling:a deep learning based lexicographical detection approach[J].arXiv:2006.06122,2020. [28] WANG Y,AN J,HUANG W.Using CNN-based representation learning method for malicious traffic identification[C]//17th International Conference on Computer and Information Science.IEEE,2018:400-404. [29] Icmptunnel offical website [EB/OL].https://github.com/Dha-valKapillicmp. [30] LI Q,WANG B,WEN X,et al.Malicious traffic predictionmodel for ResNet based on Maple-IDS dataset[J].Network Daily News,2025(May):23-24. |
|
||