Artificial Steganographic Network Data Generation Concept and Evaluation of Detection Approaches to secure Industrial Control Systems against Steganographic Attacks

Tom Neubert, Claus Vielhauer, Christian Kraetzer · 2021

Since industrial control systems (ICS) play an important role in our everyday life, their protection is of great importance. At the same time, security researchers observe an increasing usage of steganographic methods in IT networks used by attackers to embed hidden communication in order to stay undetected as long as possible. This leads to a novel digital threat which includes the embedding of steganographic hidden communication in ICS networks. Thus, novel detection approaches specified for steganographic attacks have to be elaborated. Detectors are often based on machine learning approaches and require training and test data. However, the embedding of sophisticated hidden communication in an ICS is a very time consuming and challenging task which currently leads to a lack of suitable training and test data for the evaluation of detection mechanisms. To address this gap, this work presents an artificial steganographic network data (ASND) generation concept for an easy generation of sophisticated steganographic network data which can be provided for the evaluation of detection mechanisms. In this paper, an exemplary data set is created by ASND generation concept and used to evaluate a state-of-the-art detector and a novel detector, also introduced in this work. The accuracy of the detectors is determined and compared. The novel detector reaches a maximum detection accuracy of 92.5%.

Read the paper · More papers on PaperTik