حقوق سایبری

حقوق سایبری

چارچوبی نوین برای جرم یابی سایبری: شناسایی بدافزارهای استگانوگرافی در تصاویر با تکیه بر یادگیری عمیق

نوع مقاله : مقاله پژوهشی

نویسندگان
1 گروه مدیریت فناوری اطلاعات، واحد تهران مرکزی، دانشگاه آزاد اسلامی، تهران، ایران
2 گروه مدیریت صنعتی، واحد تهران مرکزی، دانشگاه آزاد اسلامی، تهران، ایران
چکیده
امروزه شناسایی بدافزارهای پنهان‌شده در تصاویر به کمک استگانوگرافی، به یکی از چالش‌های کلیدی در جرم‌یابی سایبری و تحلیل ادله دیجیتال تبدیل شده است. این پژوهش چارچوبی نوین مبتنی بر یادگیری عمیق برای کشف، مکان‌یابی و طبقه‌بندی بدافزارهای استگانوگرافی در تصاویر ارائه می‌دهد. روش‌های متداول استگانالیز که بر پایه‌ی یادگیری نظارت‌شده طراحی شده‌اند، اگرچه در تشخیص الگوریتم‌های شناخته‌شده عملکرد قابل‌قبولی دارند، اما با دو کاستی اساسی روبرویند: نخست، وابستگی شدید به الگوریتم پنهان‌نگاری، و دوم، افت چشمگیر عملکرد در بارهای مخفی پایین (زیر ۰.۱ بیت بر پیکسل). پژوهش حاضر با ارائه‌ی چارچوبی یکپارچه به نام CONAFP (شبکه یک‌کلاسه‌ی تطبیقی با تصفیه‌ی ویژگی تقابلی)، به دنبال رفع این محدودیت‌ها است. چارچوب پیشنهادی از سه بخش اصلی شکل گرفته است: نخست، بخش بازسازی مبتنی بر شبکه‌های مولد تقابلی (GAN) با بهره‌گیری از معماری U-Net و متمایزگر PatchGAN، تصویر ورودی را به نسخه‌ای پاک بازسازی می‌کند. دوم، بخش استخراج ویژگی با محاسبه‌ی باقیمانده و اعمال تبدیلات چندمقیاسه و توجه بین‌مقیاسی ، ردپای پنهان‌نگاری را برجسته‌تر می‌سازد. سوم، بخش تشخیص یک‌کلاسه با استفاده از روش Deep SVDD، که تنها با داده‌های سالم (تصاویر پاک) آموزش دیده است، هرگونه انحراف از الگوی نرمال را به عنوان یک ناهنجاری شناسایی می‌کند. برای غلبه بر ناپایداری ذاتی آموزش GAN در معماری‌های ترکیبی، از یک استراتژی آموزشی دو مرحله‌ای استفاده شده است: پیش‌آموزش مجزا و سپس تنظیم دقیق سرتاسری (End-to-End). یافته‌های این پژوهش گویای آن است که برای مقابله با بدافزارهای پنهان‌شده در تصاویر، نیازی به شناسایی الگوریتم پنهان‌نگاری نداریم؛ بلکه با مدل‌سازی مفهوم «سالم بودن» و تفکیک آن از فرآیند بازسازی تصویر، می‌توانیم به یک سیستم تشخیص ناهنجاری دست یابیم که مستقل از الگوریتم مهاجم است. این یک تغییر پارادایم از «تشخیص ردپای جرم» به «تشخیص انحراف از نرمال بودن» است که افق‌های جدیدی را در حوزه‌ی امنیت سایبری و مقابله با تهدیدات ناشناخته می‌گشاید. این پژوهش با ارائه‌ی چارچوبی یکپارچه و تفکیک نقش GAN از Deep SVDD، گامی در مسیر تغییر پارادایم در طراحی سیستم‌های استگانالیز آینده برداشته است.
کلیدواژه‌ها
موضوعات

عنوان مقاله English

A Novel Framework for Cyber Forensics: Detecting Steganographic Malware in Images Using Deep Learning

نویسندگان English

Alireza Nadermohammadi 1
Mohammad Ali Ali Afshar Kazemi 2
Jalal Haghighat Monfared 2
1 Department of Information Technology Management, CT,C., Islamic Azad University, Tehran, Iran
2 Department of Industrial Management, CT,C., Islamic Azad University, Tehran, Iran
چکیده English

Nowadays, detecting malware hidden within images via steganography has become a key challenge in cyber forensics and digital evidence analysis. This research presents a novel deep learning-based framework for the detection, localization, and classification of steganographic malware in images. Conventional steganalysis methods based on supervised learning, while performing acceptably in detecting known algorithms, face two fundamental shortcomings: first, a heavy reliance on the specific steganography algorithm used; and second, a significant performance drop at low embedding rates (below 0.1 bits per pixel). The present study aims to overcome these limitations by introducing an integrated framework named CONAFP (Adaptive One-Class Network with Adversarial Feature Refinement). The proposed framework comprises three main components: first, a reconstruction module based on Generative Adversarial Networks (GANs)—utilizing a U-Net architecture and a PatchGAN discriminator—reconstructs the input image into a clean version. Second, a feature extraction module highlights steganographic traces by calculating residuals and applying multi-scale transformations and cross-scale attention mechanisms. Third, a one-class detection module, employing the Deep SVDD method and trained solely on benign data (clean images), identifies any deviation from the normal pattern as an anomaly. To overcome the inherent instability of training GANs within hybrid architectures, a two-stage training strategy—comprising separate pre-training followed by end-to-end fine-tuning—has been employed. The study’s findings demonstrate that detecting malware hidden in images does not require identifying the specific steganography algorithm; instead, by modeling the concept of "normality" and decoupling it from the image reconstruction process, an anomaly detection system independent of the attacker's algorithm can be achieved. This represents a paradigm shift from "detecting traces of the crime" to "detecting deviations from normality," opening new horizons in cybersecurity and the mitigation of unknown threats. By presenting an integrated framework and distinguishing the roles of GANs and Deep SVDD, this research advances the paradigm shift in the design of future steganalysis systems.

کلیدواژه‌ها English

Steganalysis
decision-level one-class learning
Generative Adversarial Networks (GANs)
جاه بین، زهرا ، بیگی زاد، علی محد (1399) جرم شناسی سایبری، انتشارات جامعه شناسان، چاپ اول، تهران
علیوردی نیا، اکبر، انواری، آمنه (1394) جرایم سایبری در ایران، مصادیق جرایم سایبری و راهکارهای مقابله با آن، کنفرانس بین المللی علوم انسانی، روانشناسی و علوم اجتماعی، تهران
Boroumand, M., Chen, M., & Fridrich, J. (2019). Deep residual network for steganalysis of digital images. IEEE Transactions on Information Forensics and Security, 14(5), 1181–1193. https://doi.org/10.1109/TIFS.2018.2871749
Caviglione, L., Wendzel, S., & Mazurczyk, W. (2017). The future of digital forensics: Challenges and the road ahead. IEEE Security & Privacy, 15(6), 12–17. https://doi.org/10.1109/MSP.2017.4251102
Fridrich, J., & Kodovský, J. (2012). Rich models for steganalysis of digital images. IEEE Transactions on Information Forensics and Security, 7(3), 868–882. https://doi.org/10.1109/TIFS.2012.2190402
Fridrich, J. and M. Goljan, "Practical steganalysis of digital images - state of the art," in Proceedings of SPIE Photonics Imaging 2002, Security and Watermarking of Multimedia Contents, vol. 4675, pp. 1-13, 2002.
Fridrich, J. and T. Filler, "Practical methods for minimizing embedding impact in steganography," in Electronic Imaging, Security, Steganography, and Watermarking of Multimedia Contents IX, Proc. SPIE, vol. 6505, pp. 0201-0215, 2007.
Fridrich , J. T. Pevny, and J. Kodovsky, "Statistically undetectable JPEG steganography: Dead ends, challenges, and opportunities," in Proceedings of the 9th ACM Multimedia & Security Workshop, pp. 3-14, Dallas, TX, September 20-21, 2007.
Holub, V., & Fridrich, J. (2014). Digital image steganography using universal distortion. In Proceedings of the First ACM Workshop on Information Hiding and Multimedia Security (pp. 59–68). Association for Computing Machinery. https://doi.org/10.1145/2600918.2600920
Li, B., Wang, M., Huang, J., & Li, X. (2014). A new cost function for spatial image steganography. In 2014 IEEE International Conference on Image Processing (ICIP) (pp. 4206–4210). IEEE. https://doi.org/10.1109/ICIP.2014.7025854
Mazurczyk, W., & Caviglione, L. (2015). Steganography in modern smartphones and mitigation techniques. IEEE Communications Surveys & Tutorials, 17(1), 334–357. https://doi.org/10.1109/COMST.2014.2350994
Qian, Y., Dong, J., Wang, W., & Tan, T. (2015). Deep learning for steganalysis via convolutional neural networks. In A. Alattar, N. D. Memon, & C. D. Heitzenrater (Eds.), Media Watermarking, Security, and Forensics 2015 (Vol. 9409, p. 94090J). SPIE. https://doi.org/10.1117/12.2083479
Xu, G., Wu, H. Z., & Shi, Y. Q. (2016). Structural design of convolutional neural networks for steganalysis. IEEE Signal Processing Letters, 23(5), 708–712. https://doi.org/10.1109/LSP.2016.2543023
Xu,G. "Deep convolutional neural network to detect J-UNIWARD," in Proceedings of the 5th ACM Workshop on Information Hiding and Multimedia Security, pp. 67-73, 2017.
Ye, J., Ni, J., & Yi, Y. (2017). Deep learning hierarchical representations for image steganalysis. IEEE Transactions on Information Forensics and Security, 12(11), 2545–2557. https://doi.org/10.1109/TIFS.2017.2710946
Yousfi, Y., Butora, J., Fridrich, J., & Giboulot, Q. (2021). Breaking ALASKA: Color separation for steganalysis in JPEG domain. In Proceedings of the 2021 ACM Workshop on Information Hiding and Multimedia Security (pp. 61–72). Association for Computing Machinery. https://doi.org/10.1145/3437891.3437897

مقالات آماده انتشار، پذیرفته شده
انتشار آنلاین از 15 مهر 1405