<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//TaxonX//DTD Taxonomic Treatment Publishing DTD v0 20100105//EN" "../../nlm/tax-treatment-NS0.dtd">
<article xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:tp="http://www.plazi.org/taxpub" article-type="research-article" dtd-version="3.0" xml:lang="en">
  <front>
    <journal-meta>
      <journal-id journal-id-type="publisher-id">109</journal-id>
      <journal-id journal-id-type="index">urn:lsid:arphahub.com:pub:3dc5f44e-8666-58db-bc76-a455210e8891</journal-id>
      <journal-title-group>
        <journal-title xml:lang="en">JUCS - Journal of Universal Computer Science</journal-title>
        <abbrev-journal-title xml:lang="en">jucs</abbrev-journal-title>
      </journal-title-group>
      <issn pub-type="ppub">0948-695X</issn>
      <issn pub-type="epub">0948-6968</issn>
      <publisher>
        <publisher-name>Journal of Universal Computer Science</publisher-name>
      </publisher>
    </journal-meta>
    <article-meta>
      <article-id pub-id-type="doi">10.3217/jucs-025-11-1396</article-id>
      <article-id pub-id-type="publisher-id">22669</article-id>
      <article-categories>
        <subj-group subj-group-type="heading">
          <subject>Research Article</subject>
        </subj-group>
        <subj-group subj-group-type="scientific_subject">
          <subject>B.4.1 - Data Communications Devices</subject>
          <subject>C.2.2 - Network Protocols</subject>
          <subject>C.2.5 - Local and Wide-Area Networks</subject>
          <subject>C.2.6 - Internetworking</subject>
          <subject>D.4.6 - Security and Protection</subject>
          <subject>K.6.5 - Security and Protection</subject>
          <subject>K.7.m - Miscellaneous</subject>
        </subj-group>
      </article-categories>
      <title-group>
        <article-title>Detection of Size Modulation Covert Channels Using Countermeasure Variation</article-title>
      </title-group>
      <contrib-group content-type="authors">
        <contrib contrib-type="author" corresp="yes">
          <name name-style="western">
            <surname>Wendzel</surname>
            <given-names>Steffen</given-names>
          </name>
          <email xlink:type="simple">wendzel@hs-worms.de</email>
          <uri content-type="orcid">https://orcid.org/0000-0002-1913-5912</uri>
        </contrib>
        <contrib contrib-type="author" corresp="no">
          <name name-style="western">
            <surname>Link</surname>
            <given-names>Florian</given-names>
          </name>
          <xref ref-type="aff" rid="A1">1</xref>
        </contrib>
        <contrib contrib-type="author" corresp="no">
          <name name-style="western">
            <surname>Eller</surname>
            <given-names>Daniela</given-names>
          </name>
          <xref ref-type="aff" rid="A1">1</xref>
        </contrib>
        <contrib contrib-type="author" corresp="no">
          <name name-style="western">
            <surname>Mazurczyk</surname>
            <given-names>Wojciech</given-names>
          </name>
          <xref ref-type="aff" rid="A2">2</xref>
        </contrib>
      </contrib-group>
      <aff id="A1">
        <label>1</label>
        <addr-line content-type="verbatim">Worms University of Applied Sciences, Worms, Germany</addr-line>
        <institution>Worms University of Applied Sciences</institution>
        <addr-line content-type="city">Worms</addr-line>
        <country>Germany</country>
      </aff>
      <aff id="A2">
        <label>2</label>
        <addr-line content-type="verbatim">Warsaw University of Technology, Warsaw, Poland</addr-line>
        <institution>Warsaw University of Technology</institution>
        <addr-line content-type="city">Warsaw</addr-line>
        <country>Poland</country>
      </aff>
      <author-notes>
        <fn fn-type="corresp">
          <p>Corresponding author: Steffen Wendzel (<email xlink:type="simple">wendzel@hs-worms.de</email>).</p>
        </fn>
        <fn fn-type="edited-by">
          <p>Academic editor: </p>
        </fn>
      </author-notes>
      <pub-date pub-type="collection">
        <year>2019</year>
      </pub-date>
      <pub-date pub-type="epub">
        <day>28</day>
        <month>11</month>
        <year>2019</year>
      </pub-date>
      <volume>25</volume>
      <issue>11</issue>
      <fpage>1396</fpage>
      <lpage>1416</lpage>
      <uri content-type="arpha" xlink:href="http://openbiodiv.net/10B00F27-2892-5FCE-AA8B-5660EEDA9526">10B00F27-2892-5FCE-AA8B-5660EEDA9526</uri>
      <uri content-type="zenodo_dep_id" xlink:href="https://zenodo.org/record/4840918">4840918</uri>
      <history>
        <date date-type="received">
          <day>15</day>
          <month>02</month>
          <year>2019</year>
        </date>
        <date date-type="accepted">
          <day>26</day>
          <month>07</month>
          <year>2019</year>
        </date>
      </history>
      <permissions>
        <copyright-statement>Steffen Wendzel, Florian Link, Daniela Eller, Wojciech Mazurczyk</copyright-statement>
        <license license-type="creative-commons-attribution" xlink:href="" xlink:type="simple">
          <license-p>This article is freely available under the J.UCS Open Content License.</license-p>
        </license>
      </permissions>
      <abstract>
        <label>Abstract</label>
        <p>Network covert channels enable stealthy communications for malware and data exfiltration. For this reason, developing effective countermeasures for these threats is important for the protection of individuals and organizations. However, due to the large number of available covert channel techniques, it is considered impractical to develop countermeasures for all existing covert channels. In recent years, researchers started to develop countermeasures that (instead of only countering one particular hiding technique) can be applied to a whole family of similar hiding techniques. These families are referred to as hiding patterns. Considering above, the main contribution of this paper is to introduce the concept of countermeasure variation. Countermeasure variation is a slight modification of a given countermeasure that was designed to detect covert channels of one specific hiding pattern so that the countermeasure can also detect covert channels that are representing other hiding patterns. We exemplify countermeasure variation using the compressibility score, the ε-similarity and the regularity metric originally presented by Cabuk et al. All three methods are used to detect covert channels that utilize the Inter-packet Times pattern and we show that countermeasure variation allows the application of these countermeasures to detect covert channels of the Size Modulation pattern, too.</p>
      </abstract>
    </article-meta>
  </front>
</article>
