ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Online business Toolkit

Secret codes 'not hidden in Web images'

Matt Loney ZDNet.co.uk

Published: 26 Sep 2001 13:27 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A study of more than two million images downloaded from eBay auctions appears to show little evidence that terrorists -- or indeed anybody else -- is using the images to hide encoded messages.

The study, by Niels Provos and Peter Honeyman at the University of Michigan, was carried out in response to reports that terrorists are using steganography to hide their communications in images on Internet sites such as Amazon and eBay.

The researchers analysed the images to look for evidence of a type of encryption called steganography, which refers to the practice of hiding the existence of a message. If an image on eBay did have a message encoded into it, it would be indistinguishable to the casual observer from the original image. The weakness of such systems, say the researchers, is that they rely on the secrecy of the encoding system.

"Once the encoding system is known, the steganographic system is defeated," they say in their paper: Detecting Steganographic Content on the Internet.

Provost and Honeyman wrote a program called Crawl to search eBay for images to download, and it retrieved more than two million images ranging between 20KB and 400KB in size. Images smaller than 20KB are considered too small to hide steganographic content reliably. They then used a cluster of 60 computers to search the images for evidence of content hidden using three common steganographic encoders: JSteg, JPHide and OutGuess.

Statistical analysis can be used to reveal whether an image is likely to have been modified by steganography, say the researchers, and they used a program called Stegdetect to sift through the images looking for evidence.

Of the two million images downloaded by Crawl, the researchers found 17,000 images that at first sight appeared to have steganographic content. But statistical analysis alone cannot be used to prove that a particular image contains steganographic content; it can only indicate a likelihood that it does.

To prove that steganographic content had been hidden within these images, the researchers used their network of computers to mount a distributed dictionary attack, which they assert should have been successful in at least a few cases, citing research showing that 25 percent of all passwords are vulnerable to such attacks. The dictionary attacks were, however, unsuccessful.

The researchers offered three possibilities for their failure to confirm a single piece of steganographic content in a single image. First, that there is no significant use of steganography on the Internet; second, that nobody uses any of the steganographic systems that they checked for; and third, that all users of steganographic systems carefully choose passwords that are not susceptible to password attacks.

Both the latter two answers were dismissed by Provos and Honeymoon. Even if there were images containing steganographic content, said the researchers, it is inconceivable that at least some were not encoded using common programs. Similarly, they found it inconceivable that every image could have been encoded using a strong password.

"The most likely explanation is that there is no use of steganography on the Internet," say the researchers in conclusion. However, the researchers now plan to widen their search from eBay to include content from USENET image groups.

See the Net Crime News Section for the latest on hacking, fraud, viruses and related issues.

Have your say instantly, and see what others have said. Click on the TalkBack button and go to the Security forum.

Let the editors know what you think in the Mailroom. And read other letters.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
60 out of 124 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:







Related Jobs

Document Image Processing (DIP) Architect Required

My client is seeking a IXOS Architect who fully understands the architecture required for a SAP driven scanning solution, along with over 5 ...

C++ Software Developer - Coventry - 35,000

An international software house based in Coventry is searching for a strong C++ developer with fantastic C++ and image processing skills. As the ...

IBM Websphere Message Broker- Flow Developer- ESQL JAVA

IBM Websphere Message Broker (WBIMB) Flow Developer (ESQL or JAVA) urgently required by my West Midlands client for a short term contract. You will ...

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

Featured Talkback

I wonder, who needs .asia domain? I cannot imagine, what would be useful for Microsoft.asia? Toyota.asia? Then let's register .europe (if .eu is too short). Or perhaps Microsoft.southamerica, Dell.australiaandnewzealand, Coca-Cola.africa... Sound funny? Then why not just use the global and country domains? Or perhaps it is time to drop the domains at all?

By: LadyRoot

Read full story:
Businesses advised to register .asia domains