Evasive IPv6 Covert Channels: Design, Machine Learning Detection, and Explainable AI Evaluation
The result's identifiers
Result code in IS VaVaI
<a href="https://www.isvavai.cz/riv?ss=detail&h=RIV%2F00216305%3A26220%2F26%3A0198552" target="_blank" >RIV/00216305:26220/26:0198552 - isvavai.cz</a>
Result on the web
<a href="https://www.scitepress.org/Papers/2025/135561/135561.pdf" target="_blank" >https://www.scitepress.org/Papers/2025/135561/135561.pdf</a>
DOI - Digital Object Identifier
<a href="http://dx.doi.org/10.5220/0013556100003979" target="_blank" >10.5220/0013556100003979</a>
Alternative languages
Result language
angličtina
Original language name
Evasive IPv6 Covert Channels: Design, Machine Learning Detection, and Explainable AI Evaluation
Original language description
Adopting a dual approach, this paper presents a framework that integrates two complementary components: CovertGen6, a novel tool for generating realistic IPv6 covert channel attack packets, and a framework of detection system based on multiple machine learning models. CovertGen6 outperforms existing tools by producing diverse, evasive attack scenarios that are captured by Wireshark and converted into CSV datasets for analysis. These authentic datasets are then used to train and evaluate machine learning models for detecting IPv6 covert channels, with the Random Forest classifier achieving a binary classification AuC of 0.985 and a multi-label classification F1-score of 90.3%. Additionally, the explainable AI technique is incorporated to transparently interpret model decisions and pinpoint the specific header fields used for covert injections. This dual approach bridges the gap between theoretical research and practical network security, laying a robust foundation for intrusion detection systems in IPv6 networks.
Czech name
—
Czech description
—
Classification
Type
D - Article in proceedings
CEP classification
—
OECD FORD branch
20202 - Communication engineering and systems
Result continuities
Project
<a href="/en/project/VK01030019" target="_blank" >VK01030019: Interactive checklists for effective cybersecurity testing</a><br>
Continuities
P - Projekt vyzkumu a vyvoje financovany z verejnych zdroju (s odkazem do CEP)<br>S - Specificky vyzkum na vysokych skolach
Others
Publication year
2025
Confidentiality
S - Úplné a pravdivé údaje o projektu nepodléhají ochraně podle zvláštních právních předpisů
Data specific for result type
Article name in the collection
Proceedings of the International Conference on Security and Cryptography
ISBN
978-989-758-760-3
ISSN
—
e-ISSN
—
Number of pages
10
Pages from-to
666-675
Publisher name
SciTePress
Place of publication
Bilbao, Spain
Event location
Bilbao
Event date
Jun 11, 2025
Type of event by nationality
WRD - Celosvětová akce
UT code for WoS article
—