<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>LinkGard Security Blog &#187; Demeratus</title>
	<atom:link href="http://www.linkgard.com/security_blog/tags/demeratus/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.linkgard.com/security_blog</link>
	<description>Security Thoughts and Insight in Black and White</description>
	<lastBuildDate>Thu, 18 Feb 2010 14:05:47 +0000</lastBuildDate>
	
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Introduction to Steganography and Steganalysis</title>
		<link>http://www.linkgard.com/security_blog/introduction-to-steganography-and-steganalysis/</link>
		<comments>http://www.linkgard.com/security_blog/introduction-to-steganography-and-steganalysis/#comments</comments>
		<pubDate>Sat, 23 May 2009 00:44:43 +0000</pubDate>
		<dc:creator>Hovanes</dc:creator>
				<category><![CDATA[Covert Channel]]></category>
		<category><![CDATA[Cryptography]]></category>
		<category><![CDATA[data hiding]]></category>
		<category><![CDATA[Demeratus]]></category>
		<category><![CDATA[digital signal processing]]></category>
		<category><![CDATA[steganalysis]]></category>
		<category><![CDATA[steganography]]></category>
		<category><![CDATA[Yeghishe Charents]]></category>

		<guid isPermaLink="false">http://www.linkgard.com/security_blog/?p=76</guid>
		<description><![CDATA[While visiting the American University of Armenia today, I stumbled upon a talk by Dr. Sos Agaian on digital signal processing and steganalysis. I have been interested in this area for years and Dr. Agaian’s talk gave me insight on some new and interesting research into this area while providing me with motivation to share [...]]]></description>
			<content:encoded><![CDATA[<div id="attachment_87" class="wp-caption alignright" style="width: 160px"><a href="http://www.linkgard.com/security_blog/wp-content/uploads/2009/05/hyangwonjeong.jpg"><img class="size-thumbnail wp-image-87" title="ORIGINAL" src="http://www.linkgard.com/security_blog/wp-content/uploads/2009/05/hyangwonjeong-150x150.jpg" alt="Hyangwonjeong pavillion inside Gyeongbokgung Palace in Seoul, Korea. (Original, see below for steg image.)" width="150" height="150" /></a><p class="wp-caption-text">Hyangwonjeong pavillion inside Gyeongbokgung Palace in Seoul, Korea. (Original, see below for steg image.)</p></div>
<p>While visiting the <a href="http://www.aua.am" target="_blank">American University of Armenia</a> today, I stumbled upon a talk by <a title="Sos Agaian" href="http://engineering.utsa.edu/~sagaian/" target="_blank">Dr. Sos Agaian</a> on <strong>digital signal processing</strong> and <strong>steganalysis</strong>. I have been interested in this area for years and Dr. Agaian’s talk gave me insight on some new and interesting research into this area while providing me with motivation to share my thoughts here. I hope to cover specifics about Dr. Agaian&#8217;s research results in a future posting. With this post, I would like to give an introduction to <strong>steganography </strong>and <strong>steganalysis </strong>for those who are new to this topic.</p>
<p>&#8212;</p>
<p class="MsoNormal"><a title="Susa" href="http://en.wikipedia.org/wiki/Susa" target="_blank">Susa</a> (or modern day <a title="Shush, Iran" href="http://en.wikipedia.org/wiki/Shush,_Iran" target="_blank">Shush, Iran</a>) is one of the most ancient settlements known to man and one of the capitals of the Persian Empire. Much older than Rome, this city has played an important role in world history. <span> </span>It is also where <strong>steganography </strong>is believed to have first been used.</p>
<p class="MsoNormal">It was there that in the 5<sup>th</sup> century B.C. &#8211; according to Herodotus – a deposed king of Sparta by the name of Demaratus witnessed the plans by Persia to attack the Greeks. The Persian emperor Xerxes I had allegedly amassed one of the largest fighting forces in history and was intent on conquering all Greek city-states. Demaratus, still loyal to his people, decided to warn his compatriots of the impeding attack. In order to avoid detection, Demaratus used a pair of wooden folding tablets. Scraping off the original wax he inscribed news of the impeding attack and covered the tablets with fresh wax. His secret message to the Spartans reached its destination disguised as blank tablets. Thanks to Demaratus, the Greeks were able to prepare and fend off the Persian attack.</p>
<p class="MsoNormal">Armenian poet Yeghishe Charents, during the height of Soviet repression and censorship in the 1930s, penned a poem titled “The Message,” seemingly paying tribute to the Soviets. The poem includes these lines:</p>
<p class="MsoNormal" style="margin-left: 0.5in;"><em>A new light shone on the world.<br />
Who brought this sun?<br />
&#8230; It is only this sunlight<br />
Which for centuries will stay alive.</em></p>
<p class="MsoNormal">The poem bypassed the censors and was happily published as propaganda until they figured out that the first letter of every line spelled an entirely different and more nationalistic message: <em>“O Armenian people, your only salvation is in the power of your unity.&#8221; </em>Charents was not allowed to publish thereafter and in a year or so disappeared under mysterious circumstances that are not so mysterious to those familiar with the history of Stalin’s purges. Charents may have been eliminated but due to his successful use of steganography his message is alive today and for generations to come.</p>
<p>The art and science of hiding information with a secret meaning inside other seemingly innocuous media is known as <strong>steganography</strong>. Attempting to detect and decipher these messages is called <strong>steganalysis</strong>. Steganography also can be characterized as a specific form of <strong>covert channel</strong>.</p>
<p>These are popular areas of study in security today due to the apparent ability to effortlessly communicate in a secret and secure manner in adversarial conditions. In particular, governments are concerned with terrorists being able to use this technology to communicate with each other bypassing detection.</p>
<p>Many different media can be used for the purpose of steganography, including:</p>
<div id="attachment_82" class="wp-caption alignright" style="width: 160px"><a href="http://www.linkgard.com/security_blog/wp-content/uploads/2009/05/temple1.jpg"><img class="size-thumbnail wp-image-82" title="Steganographic Image" src="http://www.linkgard.com/security_blog/wp-content/uploads/2009/05/temple1-150x150.jpg" alt="Image above with hidden text." width="150" height="150" /></a><p class="wp-caption-text">Image above with hidden text.</p></div>
<ul>
<li><!--[if !supportLists]--><strong>Images</strong>: Images can be used for steganography. There are various methods that can be used. One of the methods is called Least Significant Bit (LSB) where data is hidden in the least significant bits of pixels in an image reducing the quality of an image by a very small and possibly visually undetectable manner. Consider the photo of at the top of this post. For illustration purposes, I have embedded the contents of a small text file inside the beautiful image (right).</li>
</ul>
<ul>
<li><!--[if !supportLists]--><strong>Audio</strong>: Steganography using audio is a bit more complex than images but still possible. In order to hide data in audio, you must have a good algorithm for detecting peaks in an audio waveform and hide the data within the peaks. Secret data can be embedded in one of the thousands of MPG files on a computer for instance.</li>
</ul>
<ul>
<li><!--[if !supportLists]--><strong>Video</strong>: A video simply consists of many frames of images. Messages can be hidden in just one or some of the frames.</li>
</ul>
<ul>
<li><!--[if !supportLists]--><strong>Text:</strong> Consider white space in a full-justified text document. The combination of spaces (some double spaces and single spaces) can convey special meaning and thus act as a covert channel. Besides white spaces, the following can also be used to convey special meaning: letter frequency, word frequency, grammar style, and so forth.</li>
</ul>
<p class="MsoNormal"><strong>Steganalysis </strong>involves detecting whether <strong>steganography </strong>is used and being able to extract the hidden message. A variety of <strong>steganalysis </strong>methods exist, depending on the type of medium involved.</p>
<p class="MsoNormal">One way to visually see the difference between the original and steganographic image is to obtain a color histogram of both images.  You can see that the histogram on the right is slightly different than the one on the left. In simple terms steg analysis usually involves figuring out a mathematical model that would help us determine if an image is abnormal in the sense that it contains hidden information, without the benefit of having the original image.</p>
<p class="MsoNormal" style="text-align: center;">
<div id="attachment_102" class="wp-caption aligncenter" style="width: 403px"><a href="http://www.linkgard.com/security_blog/wp-content/uploads/2009/05/histogram_comparison1.jpg"><img class="size-full wp-image-102" title="histogram_comparison1" src="http://www.linkgard.com/security_blog/wp-content/uploads/2009/05/histogram_comparison1.jpg" alt="Comparison of histograms." width="393" height="132" /></a><p class="wp-caption-text">Comparison of histograms.</p></div>
<p class="MsoNormal">For this particular case the relatively small amount of hidden data we injected (only 1K for an 813K file) makes steganalysis much more difficult. I will cover more steganalysis techniques in future postings on this blog.</p>
<p class="MsoNormal">Smart users of steganography will also rely on tactically choosing the carrier image. For instance, binary images (those composed of only 2 colors) do not yield themselves well to steganography. Thus, someone wishing to conceal his/her traces would pick images that have features that would make it easy to hide bits of information.</p>
<p class="MsoNormal"><strong>Generating Stego Image</strong></p>
<p class="MsoNormal">Here is how I generated the steganographic image above:</p>
<blockquote>
<pre class="MsoNormal">$ outguess -k "linkgard" -d ~/mess.txt ~/ORIG.jpg ~/STEG.jpg
Reading /home/user/ORIG.jpg....
JPEG compression quality set to 75
Extracting usable bits:   441867 bits
Correctable message size: 8102 bits, 1.83%
Encoded '/home/user/mess.txt': 4992 bits, 624 bytes
Finding best embedding...
    0:  2512(50.0%)[50.3%], bias  2505(1.00), saved:    -2, total:  0.57%
    1:  2443(48.6%)[48.9%], bias  2428(0.99), saved:     6, total:  0.55%
   12:  2447(48.7%)[49.0%], bias  2374(0.97), saved:     6, total:  0.55%
   28:  2432(48.4%)[48.7%], bias  2320(0.95), saved:     8, total:  0.55%
28, 4752: Embedding data: 4992 in 441867
Bits embedded: 5024, changed: 2432(48.4%)[48.7%], bias: 2320, tot: 441028,
skip: 436004
Foiling statistics: corrections: 844, failed: 0, offset: 83.645251 +-
220.522425
Total bits changed: 4752 (change 2432 + bias 2320)
Storing bitmap into data...
Writing /home/user/STEG.jpg....</pre>
</blockquote>
<p class="MsoNormal">Note: Original image is 813Kb.  Maximum usable/recommended steg bandwidth is reported as ~ 1K.</p>
<p class="MsoNormal"><strong>Further reading</strong></p>
<ul>
<li><span><a title="Wikipedia entry on Steganography" href="http://en.wikipedia.org/wiki/Steganography" target="_blank">Wikipedia entry</a> on the topic.</span></li>
<li><a href="http://www.citi.umich.edu/u/provos/papers/practical.pdf">Hide and Seek: An Introduction to Stegangography</a> &#8211; Niels Provos and Peter Honeyman,	<em>IEEE Security &amp; Privacy Magazine</em>, May/June 2003.</li>
<li><a href="http://www.amazon.com/exec/obidos/ASIN/0471444499/honeyd-20">Hiding in Plain Sight : Steganography and the Art of Covert Communication</a> &#8211; Explains how to use stegdetect and stegbreak.</li>
<li><a href="http://forensics.cs.uri.edu/Steg_Detection.pdf" target="_blank">Automated Steganography Detection</a> &#8211; Kevin Bryan, Raghu Menon, Neil Bennett, Victor Fay-Wolfe &#8211; University of Rhode Island, Department of Computer Science, Digital Forensics Center.</li>
</ul>
<p class="MsoNormal"><strong>Tools</strong></p>
<p class="MsoNormal">I used a couple of aged but tried and true tools to produce the images and analysis are listed below:</p>
<ul>
<li><span><a href="http://www.outguess.org/download.php" target="_blank">Stegdetect</a> is a Linux-based application that will allow you to insert hidden data in JPG files and detect if steganography exists in an image. A variety of statistical methods are used for detection.</span></li>
<li><span><a href="http://www.outguess.org/download.php" target="_blank">OutGuess</a> is another tool by the same author (Niels Provos) that uses a different method of hiding the data.</span></li>
<li><span><a href="http://www.gimp.org/" target="_blank">The GIMP!</a> For the histograms.<br />
</span></li>
</ul>
<p>Updates:</p>
<ul>
<li>5/23/2009 &#8211; Minor edits and updated sections.</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.linkgard.com/security_blog/introduction-to-steganography-and-steganalysis/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
