Uncovering hidden digital traces: Investigating steganography in encrypted IoT traffic
2025 (English)Independent thesis Advanced level (degree of Master (One Year)), 10 credits / 15 HE credits
Student thesis
Abstract [en]
The increasing use of encrypted communication in Internet of Things (IoT) networks has improved data confidentiality but, simultaneously, has raised new problems regarding forensic analysis, notably in identifying hidden threats. In this thesis, it is investigated whether steganographic activity in encrypted IoT traffic can be detected through analyzing metadata rather than decrypting the underlying content. A detection framework was tested and assessed on three different steganographic embedding methods, which were packet size manipulation, time-based encoding, and message sequencing. These methods were used on MQTT over TLS traffic within a controlled environment and the results were evaluated to assess the potential of the framework to decode hidden binary messages from deviation in metadata patterns.
It was developed in Python and designed to adapt automatically for different captures without manual threshold settings. More than 400 traffic captures, both steganographic and normal traffic, were processed. The detection accuracy was 100 percent in the final test phase, with no false positives encountered during the testing using normal traffic. The results also showed that minimal variations in packet size or delay, as low as a matter of bytes or milliseconds, were enough to add detectable patterns. The method successfully decoded various types of messages, such as passwords, hashes, and alphanumeric strings, to prove its usefulness. This research proves that metadata-based forensic analysis can effectively reveal certain types of steganographic communication in encrypted IoT environments without violating user privacy or requiring access to encrypted payloads.
Place, publisher, year, edition, pages
2025.
Keywords [en]
IoT, Steganography, Encrypted Traffic, Metadata, TLS, Network forensics, MQTT, Network security
National Category
Computer and Information Sciences
Identifiers
URN: urn:nbn:se:hh:diva-56309OAI: oai:DiVA.org:hh-56309DiVA, id: diva2:1966825
Subject / course
Digital Forensics
Educational program
Master's Programme in Network Forensics, 60 credits
Supervisors
Examiners
2025-06-112025-06-102025-10-01Bibliographically approved