{"id":{"repo_id":"auckland-ms","oai_identifier":"oai:researchspace.auckland.ac.nz:2292/60751"},"canonical_url":"https://search.dev.ndltd.org/etd/auckland-ms/oai:researchspace.auckland.ac.nz:2292/60751","repository":{"repo_id":"auckland-ms","name":"University of Auckland","base_url":"https://researchspace.auckland.ac.nz/server/oai/request"},"display":{"title":"Novel Directions in Network Steganalysis","abstract":"Network steganography is the art of exploiting network protocols or network flows to innocuously hide information. Network steganalysis is the study of analysing network traffic and flows to prevent any illicit use of steganography. Using statistical metrics to compare malicious and matching benign flows has been a solid methodological approach in network steganalysis. This approach may not work in many practical situations, however, because it is difficult to acquire both malicious and matching benign flows. A fundamental question thus inspires this thesis: What if we only have the malicious flows on hand? That is, what if we do not have access to the matching benign flow so there is nothing to compare against? Moreover, while it is critical to detect the fraction of malicious flows with a steganalysis technique, there is a lack of measurement on how much damage malicious flows cause. This leads to another question: Can we estimate how much information a malicious flow contains, thereby indicating potential damage? This thesis investigates the use of complexity derivates and a re-embedding technique to answer the two fundamental questions posed above. The experiments presented here show that it is possible to detect and estimate the amount of malicious information accurately in a number of different scenarios. However, this method is semi-automatic and relies on a significant amount of manual work, making it impractical for large-scale networks that may generate a significant number of network flows. Therefore, this thesis investigates and proposes a number of approaches to fully automate the process.","abstract_html":"Network steganography is the art of exploiting network protocols or network flows to innocuously hide information. Network steganalysis is the study of analysing network traffic and flows to prevent any illicit use of steganography. Using statistical metrics to compare malicious and matching benign flows has been a solid methodological approach in network steganalysis. This approach may not work in many practical situations, however, because it is difficult to acquire both malicious and matching benign flows. A fundamental question thus inspires this thesis: What if we only have the malicious flows on hand? That is, what if we do not have access to the matching benign flow so there is nothing to compare against? Moreover, while it is critical to detect the fraction of malicious flows with a steganalysis technique, there is a lack of measurement on how much damage malicious flows cause. This leads to another question: Can we estimate how much information a malicious flow contains, thereby indicating potential damage? This thesis investigates the use of complexity derivates and a re-embedding technique to answer the two fundamental questions posed above. The experiments presented here show that it is possible to detect and estimate the amount of malicious information accurately in a number of different scenarios. However, this method is semi-automatic and relies on a significant amount of manual work, making it impractical for large-scale networks that may generate a significant number of network flows. Therefore, this thesis investigates and proposes a number of approaches to fully automate the process.","abstract_has_math":false,"creators":["Seo, Jun O"],"institution":"ResearchSpace@Auckland","degree_name":"PhD","degree_level":"Doctoral","degree_discipline":"Computer Science","degree_department":null,"school":null,"contributors":[],"advisors":["Manoharan, Sathiamoorthy","Speidel, Ulrich"],"committee_chairs":[],"committee_members":[],"year":2021,"date_issued":"2021","date_published":"2021","updated_at":"2026-07-24T01:03:18Z","subjects":[],"languages":[],"rights":["Items in ResearchSpace are protected by copyright, with all rights reserved, unless otherwise indicated."],"rights_urls":["https://researchspace.auckland.ac.nz/docs/uoa-docs/rights.htm"],"identifier_entries":[]},"links":{"outbound_url":"https://hdl.handle.net/2292/60751","outbound_label":"Handle","outbound_source":"dc:identifier.uri"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor.advisor","label":"Advisor","values":["Manoharan, Sathiamoorthy","Speidel, Ulrich"]},{"key":"dc:creator","label":"Author","values":["Seo, Jun O"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date.accessioned","label":"Dc Date Accessioned","values":["2022-08-10T02:47:33Z"]},{"key":"dc:date.available","label":"Dc Date Available","values":["2022-08-10T02:47:33Z"]},{"key":"dc:date.issued","label":"Date","values":["2021"]},{"key":"dc:publisher","label":"Institution","values":["ResearchSpace@Auckland"]},{"key":"dc:relation.isreferencedby","label":"Dc Relation Isreferencedby","values":["UoA"]},{"key":"dc:type","label":"Dc Type","values":["Thesis"]},{"key":"thesis:degree_discipline","label":"Discipline","values":["Computer Science"]},{"key":"thesis:degree_level","label":"Degree Level","values":["Doctoral"]},{"key":"thesis:degree_name","label":"Degree Name","values":["PhD"]},{"key":"thesis:institution_name","label":"Thesis Institution Name","values":["The University of Auckland"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:rights","label":"Dc Rights","values":["Items in ResearchSpace are protected by copyright, with all rights reserved, unless otherwise indicated."]},{"key":"dc:rights.uri","label":"Rights URI","values":["https://researchspace.auckland.ac.nz/docs/uoa-docs/rights.htm"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier.uri","label":"Identifier URI","values":["https://hdl.handle.net/2292/60751"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description.abstract","label":"Abstract","values":["Network steganography is the art of exploiting network protocols or network flows to innocuously hide information. Network steganalysis is the study of analysing network traffic and flows to prevent any illicit use of steganography. Using statistical metrics to compare malicious and matching benign flows has been a solid methodological approach in network steganalysis. This approach may not work in many practical situations, however, because it is difficult to acquire both malicious and matching benign flows. A fundamental question thus inspires this thesis: What if we only have the malicious flows on hand? That is, what if we do not have access to the matching benign flow so there is nothing to compare against? Moreover, while it is critical to detect the fraction of malicious flows with a steganalysis technique, there is a lack of measurement on how much damage malicious flows cause. This leads to another question: Can we estimate how much information a malicious flow contains, thereby indicating potential damage? This thesis investigates the use of complexity derivates and a re-embedding technique to answer the two fundamental questions posed above. The experiments presented here show that it is possible to detect and estimate the amount of malicious information accurately in a number of different scenarios. However, this method is semi-automatic and relies on a significant amount of manual work, making it impractical for large-scale networks that may generate a significant number of network flows. Therefore, this thesis investigates and proposes a number of approaches to fully automate the process."]},{"key":"dc:title","label":"Title","values":["Novel Directions in Network Steganalysis"]}]}],"canonical_facts":{"dc:contributor.advisor":["Manoharan, Sathiamoorthy","Speidel, Ulrich"],"dc:creator":["Seo, Jun O"],"dc:date.accessioned":["2022-08-10T02:47:33Z"],"dc:date.available":["2022-08-10T02:47:33Z"],"dc:date.issued":["2021"],"dc:description.abstract":["Network steganography is the art of exploiting network protocols or network flows to innocuously hide information. Network steganalysis is the study of analysing network traffic and flows to prevent any illicit use of steganography. Using statistical metrics to compare malicious and matching benign flows has been a solid methodological approach in network steganalysis. This approach may not work in many practical situations, however, because it is difficult to acquire both malicious and matching benign flows. A fundamental question thus inspires this thesis: What if we only have the malicious flows on hand? That is, what if we do not have access to the matching benign flow so there is nothing to compare against? Moreover, while it is critical to detect the fraction of malicious flows with a steganalysis technique, there is a lack of measurement on how much damage malicious flows cause. This leads to another question: Can we estimate how much information a malicious flow contains, thereby indicating potential damage? This thesis investigates the use of complexity derivates and a re-embedding technique to answer the two fundamental questions posed above. The experiments presented here show that it is possible to detect and estimate the amount of malicious information accurately in a number of different scenarios. However, this method is semi-automatic and relies on a significant amount of manual work, making it impractical for large-scale networks that may generate a significant number of network flows. Therefore, this thesis investigates and proposes a number of approaches to fully automate the process."],"dc:identifier.uri":["https://hdl.handle.net/2292/60751"],"dc:publisher":["ResearchSpace@Auckland"],"dc:relation.isreferencedby":["UoA"],"dc:rights":["Items in ResearchSpace are protected by copyright, with all rights reserved, unless otherwise indicated."],"dc:rights.uri":["https://researchspace.auckland.ac.nz/docs/uoa-docs/rights.htm"],"dc:title":["Novel Directions in Network Steganalysis"],"dc:type":["Thesis"],"thesis:degree_discipline":["Computer Science"],"thesis:degree_level":["Doctoral"],"thesis:degree_name":["PhD"],"thesis:institution_name":["The University of Auckland"]},"updated_at":"2026-07-24T01:03:18Z"}