TY - GEN
T1 - Noise tolerant symbolic learning of Markov models of tunneled protocols
AU - Bhanu, Harakrishnan
AU - Schwier, Jason
AU - Craven, Ryan
AU - Ozcelik, Ilker
AU - Griffin, Christopher
AU - Brooks, Richard R.
PY - 2011
Y1 - 2011
N2 - Recent research has exposed timing side channel vulnerabilities in many security applications. Hidden Markov models (HMMs) have used timing data to extract passwords from cryptographically protected communications tunnels. We extend that work to show how HMM models of protocols can be extracted directly from observations of protocol timing artifacts with no a priori knowledge. Since our approach uses symbolic reasoning, an important question is how to best translate continuous data observations to symbolic data. This translation is problematic when observation variance makes continuous to symbolic translation unreliable. We examine this problem and show that the HMMs we infer compensate automatically for significant observation jitter and symbol misclassification. Experimental verification is presented.
AB - Recent research has exposed timing side channel vulnerabilities in many security applications. Hidden Markov models (HMMs) have used timing data to extract passwords from cryptographically protected communications tunnels. We extend that work to show how HMM models of protocols can be extracted directly from observations of protocol timing artifacts with no a priori knowledge. Since our approach uses symbolic reasoning, an important question is how to best translate continuous data observations to symbolic data. This translation is problematic when observation variance makes continuous to symbolic translation unreliable. We examine this problem and show that the HMMs we infer compensate automatically for significant observation jitter and symbol misclassification. Experimental verification is presented.
UR - http://www.scopus.com/inward/record.url?scp=80052466528&partnerID=8YFLogxK
UR - http://www.scopus.com/inward/citedby.url?scp=80052466528&partnerID=8YFLogxK
U2 - 10.1109/IWCMC.2011.5982729
DO - 10.1109/IWCMC.2011.5982729
M3 - Conference contribution
AN - SCOPUS:80052466528
SN - 9781424495399
T3 - IWCMC 2011 - 7th International Wireless Communications and Mobile Computing Conference
SP - 1310
EP - 1314
BT - IWCMC 2011 - 7th International Wireless Communications and Mobile Computing Conference
T2 - 7th International Wireless Communications and Mobile Computing Conference, IWCMC 2011
Y2 - 4 July 2011 through 8 July 2011
ER -