Evasive IPv6 Covert Channels: Design, Machine Learning Detection, and Explainable AI Evaluation
Identifikátory výsledku
Kód výsledku v IS VaVaI
<a href="https://www.isvavai.cz/riv?ss=detail&h=RIV%2F00216305%3A26220%2F26%3A0198552" target="_blank" >RIV/00216305:26220/26:0198552 - isvavai.cz</a>
Výsledek na webu
<a href="https://www.scitepress.org/Papers/2025/135561/135561.pdf" target="_blank" >https://www.scitepress.org/Papers/2025/135561/135561.pdf</a>
DOI - Digital Object Identifier
<a href="http://dx.doi.org/10.5220/0013556100003979" target="_blank" >10.5220/0013556100003979</a>
Alternativní jazyky
Jazyk výsledku
angličtina
Název v původním jazyce
Evasive IPv6 Covert Channels: Design, Machine Learning Detection, and Explainable AI Evaluation
Popis výsledku v původním jazyce
Adopting a dual approach, this paper presents a framework that integrates two complementary components: CovertGen6, a novel tool for generating realistic IPv6 covert channel attack packets, and a framework of detection system based on multiple machine learning models. CovertGen6 outperforms existing tools by producing diverse, evasive attack scenarios that are captured by Wireshark and converted into CSV datasets for analysis. These authentic datasets are then used to train and evaluate machine learning models for detecting IPv6 covert channels, with the Random Forest classifier achieving a binary classification AuC of 0.985 and a multi-label classification F1-score of 90.3%. Additionally, the explainable AI technique is incorporated to transparently interpret model decisions and pinpoint the specific header fields used for covert injections. This dual approach bridges the gap between theoretical research and practical network security, laying a robust foundation for intrusion detection systems in IPv6 networks.
Název v anglickém jazyce
Evasive IPv6 Covert Channels: Design, Machine Learning Detection, and Explainable AI Evaluation
Popis výsledku anglicky
Adopting a dual approach, this paper presents a framework that integrates two complementary components: CovertGen6, a novel tool for generating realistic IPv6 covert channel attack packets, and a framework of detection system based on multiple machine learning models. CovertGen6 outperforms existing tools by producing diverse, evasive attack scenarios that are captured by Wireshark and converted into CSV datasets for analysis. These authentic datasets are then used to train and evaluate machine learning models for detecting IPv6 covert channels, with the Random Forest classifier achieving a binary classification AuC of 0.985 and a multi-label classification F1-score of 90.3%. Additionally, the explainable AI technique is incorporated to transparently interpret model decisions and pinpoint the specific header fields used for covert injections. This dual approach bridges the gap between theoretical research and practical network security, laying a robust foundation for intrusion detection systems in IPv6 networks.
Klasifikace
Druh
D - Stať ve sborníku
CEP obor
—
OECD FORD obor
20202 - Communication engineering and systems
Návaznosti výsledku
Projekt
<a href="/cs/project/VK01030019" target="_blank" >VK01030019: Interaktivní kontrolní seznamy pro efektivní testování kybernetické bezpečnosti</a><br>
Návaznosti
P - Projekt vyzkumu a vyvoje financovany z verejnych zdroju (s odkazem do CEP)<br>S - Specificky vyzkum na vysokych skolach
Ostatní
Rok uplatnění
2025
Kód důvěrnosti údajů
S - Úplné a pravdivé údaje o projektu nepodléhají ochraně podle zvláštních právních předpisů
Údaje specifické pro druh výsledku
Název statě ve sborníku
Proceedings of the International Conference on Security and Cryptography
ISBN
978-989-758-760-3
ISSN
—
e-ISSN
—
Počet stran výsledku
10
Strana od-do
666-675
Název nakladatele
SciTePress
Místo vydání
Bilbao, Spain
Místo konání akce
Bilbao
Datum konání akce
11. 6. 2025
Typ akce podle státní příslušnosti
WRD - Celosvětová akce
Kód UT WoS článku
—