FINDING · DETECTION

Unsupervised and semi-supervised anomaly detection methods (OCSVM, Isolation Forest, shallow autoencoders) perform near-random when attempting to detect multimedia protocol tunneling: OCSVM achieves average AUC between 0.518–0.584 across all tested configurations, Isolation Forest between 0.519–0.557, and autoencoders reach a maximum AUC of 0.702 only under optimal hyperparameter search. The paper concludes that labeled training data is a hard requirement for effective covert-channel detection.

From 2018-barradas-effectiveEffective Detection of Multimedia Protocol Tunneling using Machine Learning · §5, Table 5 · 2018 · USENIX Security Symposium

Implications

Tags

censors
generic
techniques
ml-classifier
defenses
steganographymimicry

Extracted by claude-sonnet-4-6 — review before relying.