2009 IEEE International Conference on
Systems, Man, and Cybernetics |
![]() |
Abstract
Network flow watermarking schemes have been proposed to trace attackers in the presence of stepping stones or anonymized channels. Most existing interval-based watermarking schemes are ineffective at tracing multiple network flows in parallel due to their interference with each other, while recently proposed Direct Sequence Spread Spectrum (DSSS) watermarking technique is unsuitable for tracing low data rate traffic. By combining interval centroid based watermarking (ICBW) modulation approaches with spread spectrum (SS) based watermarking coding techniques, we herein propose an Interval Centroid Based Spread Spectrum Watermarking scheme (ICBSSW) for efficiently tracing multiple network flows in parallel. Based on our proposed theoretical model, a statistical analysis of ICBSSW, with no assumptions or limitations concerning the distribution of packet times, proves its effectiveness despite traffic timing perturbation and robustness against multi-flow attacks. The experiments using a large number of synthetically generated SSH traffic flows demonstrate that ICBSSW can efficiently trace multiple flows simultaneously and achieve high secrecy by utilizing multiple PN codes as random seeds for randomizing the location of the embedded watermark across multiple flows.