作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2012, Vol. 38 ›› Issue (08): 114-116. doi: 10.3969/j.issn.1000-3428.2012.08.037

• 安全技术 • 上一篇    下一篇

隐蔽流树方法的分析与改进

王聪聪,鞠时光,宋香梅   

  1. (江苏大学计算机科学与通信工程学院,江苏 镇江 212013)
  • 收稿日期:2011-07-11 出版日期:2012-04-20 发布日期:2012-04-20
  • 作者简介:王聪聪(1986-),女,硕士研究生,主研方向:信息安全,数据库技术;鞠时光,教授、博士生导师;宋香梅,讲师、硕士

Analysis and Improvement of Covert Flow Tree Method

WANG Cong-cong, JU Shi-guang, SONG Xiang-mei   

  1. (School of Computer Science and Telecommunication Engineering, Jiangsu University, Zhenjiang 212013, China)
  • Received:2011-07-11 Online:2012-04-20 Published:2012-04-20

摘要: 利用隐蔽流树方法搜索隐蔽通道时,获得的操作序列中只有极少部分真正构成隐蔽通道,增加了后续手工分析的工作量。为此,提出一种改进的隐蔽流树方法。根据信息流图进行建树,设计信息流规则,并给出隐蔽流树的自动分析算法。以一个文件系统为例进行分析,结果验证了改进方法的正确性。

关键词: 隐蔽流树, 隐蔽通道, 信息流图, 信息流规则, 共享资源矩阵

Abstract: When using Covert Flow Tree(CFT) method to search covert channel, only few operation sequences really constitute covert channel. It increases the subsequent manual analysis work. In order to solve this problem, this paper proposes an improved Covert Flow Tree(CFT) method. It uses the information flow graph to constitute trees, designs the statement information flow rule, and gives the tree traversal algorithm for automated analysis. It uses the pedagogical file system as analyzing example, and result shows the accuracy of the improved method.

Key words: Covert Flow Tree(CFT), covert channel, information flow graph, information flow rule, Shared Resource Matrix(SRM)

中图分类号: