paper-with-me

홈 › Papers

Reliable Detection of Compressed and Encrypted Data

2021-03-31 · Fabio De Gaspari, Dorjan Hitaj, Giulio Pagnotta, Lorenzo De Carli, Luigi V. Mancini

Several cybersecurity domains, such as ransomware detection, forensics and data analysis, require methods to reliably identify encrypted data fragments. Typically, current approaches employ statistics derived from byte-level distribution, such as entropy estimation, to identify encrypted fragments. However, modern content types use compression techniques which alter data distribution pushing it closer to the uniform distribution. The result is that current approaches exhibit unreliable encryption detection performance when compressed data appears in the dataset. Furthermore, proposed approaches are typically evaluated over few data types and fragment sizes, making it hard to assess their practical applicability. This paper compares existing statistical tests on a large, standardized dataset and shows that current approaches consistently fail to distinguish encrypted and compressed data on both small and large fragment sizes. We address these shortcomings and design EnCoD, a learning-based classifier which can reliably distinguish compressed and encrypted data. We evaluate EnCoD on a dataset of 16 different file types and fragment sizes ranging from 512B to 8KB. Our results highlight that EnCoD outperforms current approaches by a wide margin, with accuracy ranging from ~82 for 512B fragments up to ~92 for 8KB data fragments. Moreover, EnCoD can pinpoint the exact format of a given data fragment, rather than performing only binary classification like previous approaches.

📄 PDF Abstract BibTeX arXiv:2103.17059

Code (0)

등록된 구현이 없습니다.

Tasks

Binary Classification

Similar Papers 제목 키워드 기반

EnCoD: Distinguishing Compressed and Encrypted File Fragments

2020-10-15 · Fabio De Gaspari, Dorjan Hitaj, Giulio Pagnotta, Lorenzo De Carli 외

Reliable identification of encrypted file fragments is a requirement for several security applications, including ransomware detection, digital forensics, and traffic analysis. A popular approach consists of estimating h…

Robust Privacy-Preserving Motion Detection and Object Tracking in Encrypted Streaming Video

2021-08-30 · Xianhao Tian, Peijia Zheng, Jiwu Huang

Video privacy leakage is becoming an increasingly severe public problem, especially in cloud-based video surveillance systems. It leads to the new need for secure cloud-based video applications, where the video is encryp…

Motion DetectionMoving Object DetectionMultiple Object TrackingObject+5

Detecting Compressed Cleartext Traffic from Consumer Internet of Things Devices

2018-05-07 · Daniel Hahn, Noah Apthorpe, Nick Feamster

Data encryption is the primary method of protecting the privacy of consumer device Internet communications from network observers. The ability to automatically detect unencrypted data in network traffic is therefore an e…

BIG-bench Machine Learning

A Privacy-Preserving Content-Based Image Retrieval Scheme Allowing Mixed Use Of Encrypted And Plain Images

2020-10-31 · Kenta Iida, Hitoshi Kiya

In this paper, we propose a novel content based-image retrieval scheme allowing the mixed use of encrypted and plain images for the first time. In the proposed scheme, images are encrypted by a block-scrambling method de…

Content-Based Image RetrievalImage RetrievalPrivacy PreservingRetrieval

Feature Analysis of Encrypted Malicious Traffic

2023-12-06 · Anish Singh Shekhawat, Fabio Di Troia, Mark Stamp

In recent years there has been a dramatic increase in the number of malware attacks that use encrypted HTTP traffic for self-propagation or communication. Antivirus software and firewalls typically will not have access t…