Entropy Analysis
Definition
A statistical technique that measures the randomness of data in a field or stream. Protocol fields that should contain low-entropy predictable values (such as a TTL or a constant padding byte) show anomalously high entropy when used to carry compressed or encrypted covert data.
- Measures
- Randomness of data in a field or stream
- Flags
- Predictable fields carrying unexpectedly high entropy
- Used against
- Compressed or encrypted covert channel payloads
Common questions
Why does high entropy in a protocol field suggest a covert channel?+
Fields such as a TTL or padding byte are expected to hold predictable, low-entropy values in normal traffic. When those fields carry compressed or encrypted data instead, their entropy jumps toward the maximum, standing out statistically even though each individual packet looks superficially valid.
Can entropy analysis alone confirm steganography, or does it need corroboration?+
It is a screening signal, not proof. High entropy narrows down which fields or streams merit deeper protocol analysis; confirming an actual covert channel still requires reconstructing and decoding the suspected payload.
Related terms
- Covert Channel
- Any communication path that was not intended by the system designer and that bypasses access-control or monitoring policies. Network covert channels are...
- DNS Tunnelling
- Encoding data inside DNS queries and responses to exfiltrate information or carry command-and-control traffic through a network that permits DNS but blocks...
- Protocol Anomaly Detection
- A detection method that compares observed network traffic against the formal specification of each protocol (its RFC or standard) and flags fields...
- Storage Channel
- A covert channel that encodes information in the value of a protocol field, such as the IP Identification field or a DNS...
- Timing Channel
- A covert channel that encodes information in the intervals between network events, such as inter-packet delays, rather than in packet content. Timing...