hh.sePublications
Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
Uncovering hidden digital traces: Investigating steganography in encrypted IoT traffic
Halmstad University, School of Information Technology.
Halmstad University, School of Information Technology.
2025 (English)Independent thesis Advanced level (degree of Master (One Year)), 10 credits / 15 HE creditsStudent thesis
Abstract [en]

The increasing use of encrypted communication in Internet of Things (IoT) networks has improved data confidentiality but, simultaneously, has raised new problems regarding forensic analysis, notably in identifying hidden threats. In this thesis, it is investigated whether steganographic activity in encrypted IoT traffic can be detected through analyzing metadata rather than decrypting the underlying content. A detection framework was tested and assessed on three different steganographic embedding methods, which were packet size manipulation, time-based encoding, and message sequencing. These methods were used on MQTT over TLS traffic within a controlled environment and the results were evaluated to assess the potential of the framework to decode hidden binary messages from deviation in metadata patterns.

It was developed in Python and designed to adapt automatically for different captures without manual threshold settings. More than 400 traffic captures, both steganographic and normal traffic, were processed. The detection accuracy was 100 percent in the final test phase, with no false positives encountered during the testing using normal traffic. The results also showed that minimal variations in packet size or delay, as low as a matter of bytes or milliseconds, were enough to add detectable patterns. The method successfully decoded various types of messages, such as passwords, hashes, and alphanumeric strings, to prove its usefulness. This research proves that metadata-based forensic analysis can effectively reveal certain types of steganographic communication in encrypted IoT environments without violating user privacy or requiring access to encrypted payloads. 

Place, publisher, year, edition, pages
2025.
Keywords [en]
IoT, Steganography, Encrypted Traffic, Metadata, TLS, Network forensics, MQTT, Network security
National Category
Computer and Information Sciences
Identifiers
URN: urn:nbn:se:hh:diva-56309OAI: oai:DiVA.org:hh-56309DiVA, id: diva2:1966825
Subject / course
Digital Forensics
Educational program
Master's Programme in Network Forensics, 60 credits
Supervisors
Examiners
Available from: 2025-06-11 Created: 2025-06-10 Last updated: 2025-10-01Bibliographically approved

Open Access in DiVA

fulltext(965 kB)74 downloads
File information
File name FULLTEXT02.pdfFile size 965 kBChecksum SHA-512
7c4a900093997e33ea631f7353c104a3541784bc12ae92bc623fbde2711a7aa2d06e4239ee11ae62847f241705f7cb8008fc539eb7cdc58d88dc7730a7a495b7
Type fulltextMimetype application/pdf

By organisation
School of Information Technology
Computer and Information Sciences

Search outside of DiVA

GoogleGoogle Scholar
Total: 75 downloads
The number of downloads is the sum of all downloads of full texts. It may include eg previous versions that are now no longer available

urn-nbn

Altmetric score

urn-nbn
Total: 315 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf