1 / 12100%
The Realm of Steganography
Taylor Provencher
Liberty University
Abstract
Technology continues to evolve which is allowing for opportunities in the aspect of digital
steganography. Steganography is when messages or data is hidden from view. Steganography
continues to cause major issues in the cybercrime division. Forensic experts should focus more
attention on learning the proper training and defenses to decipher and prevent steganography
cybercrime. This paper will focus on the different methods and techniques of steganography, its
participation in cybercrime, and the available defenses and training for forensic experts.
Keywords: steganography, forensic experts, hidden, cybercrime
Introduction
Steganography has immersed into the technology realm because of the inflation of the
Internet and computer power. There are several new ways to send digital information in an
encrypted and protected demeanor. This causes many questions on the aspect of cyber security.
Steganography has various aspects that address the need for proper security and defenses.
Before understanding a topic, it is important to first understand the root or origin of the
term being discussed. The word steganography comes from the Greek words “stegos” which
means “cover” and “grafia” which means “writing”. There are several methods and techniques
that are available when using steganography.
According to the article, “Steganography and error-correcting codes”, C. Munuera
explains, “At the moment, steganographic techniques are used in order to guarantee
security and privacity on open systems (as the Internet). They also play a role in
electronic commerce, where they are used to prevent illegal uses of digital information”
(Munuera, 2007).
These techniques can be simple or extremely complicated depending on the steganographic
algorithm and method used.
Besides the growth of the Internet, information and data security has become an
extremely pressing issue in the aspects of technology and the digital realm. Communications that
are exchanged over the Internet will continue to rise because of the criminal use of digital
steganography. The rise in these steganographic criminal attacks is because of the profit and
opportunities that comes from an intrusion. That is the key goal that motivates any intruder to
seek to steal from a helpless victim.
Several scientific journals explain the process and methods that correlate with the topic of
digital steganography.
According to the article, “Comparative Study of Digital Audio Steganography
Techniques” by Fatiha Djebbar and other authors states, “The growing use of Internet
among public masses and the abundant availability of public and private digital data has
driven industry professionals and researchers to pay a particular attention to data
protection. Currently, three main methods are being used: cryptography, water-marking,
and steganography” (Djebbar, Ayad, Meraim & Harram, 2012).
This paper will express the aspects of the method of steganography while briefly talking about
cryptography and its correlation to digital steganography.
Methods and Techniques
Steganographic techniques are functional for corresponding data over independently open
channels. There are four different types of steganography. Steganography contains three
elements within a basic model; the carrier image, the message, and the key. Those different types
of steganography include the following: text steganography, image steganography, audio
steganography, and video steganography. Text steganography consists of hiding a text or
multiple texts behind other text file(s). Three way that individuals can hide text behind different
text file(s) is by format-based method, random and statistical method, and linguistics method.
As for image steganography, it is a two-step process. First, the combination of message
and carrier via creating a stego image (Babita & Kaus, 2017). The next step is to extract the
hidden message image from the created stego image (Babita & Kaus, 2017). Image
steganography can be broken down into four sub-techniques. Those techniques include the
following: spatial domain technique, transform domain technique, distortion technique, and
masking and filtering.
Spatial domain happens when bits are changed to hide the data. These changes occur
within the pixel’s values. Transform domain is when information or data is ingrained in the
transform space. According to Aiswarya Baby and Hema Krishnan, “In this domain, the image
is transformed from spatial domain to frequency domain by using any transforms and after a
transformation process, the embedding process will be done in proper transform coefficients”
(Baby & Krishnan, 2017). Distortion begins when the cover is slightly distorted in the copy
message and can be detected by examining the original image. Masking and filtering involve a
24-bit image and grayscale image only. This type of image steganography hides the important
data in compelling zones instead of concealing it within the noise level.
Audio steganography is believed to be embedded among sound which can be considered
“cover media”. Low-bit encoding, phase coding, spread spectrum, and echo hiding are all apart
of audio steganography. Low-bit encoding can also be referred to as Least Significant Bit (LSB).
According to Fatiha Djebbar and other authors, “Traditionally, it is based on embedding each bit
from the message in the least bit of the cover audio in a deterministic way” (Djebbar, Ayad,
Meraim & Harram, 2012). Unfortunately, there is a downfall to this traditional way of low-bit
encoding. This type of method symbolizes the low robustness to noise addition. What this means
is that this method lacks security achievement because of the constant vulnerability even to
straightforward attacks.
The next part of audio steganography is phase coding. Phase coding is the process of
replacing preferred phase segments from audio signal spectrum with original hidden data. Phase
segments must remain small so that inaudibility is ensured. The third part of audio steganography
is spread spectrum. This particular method uses a frequency spectrum to send and receive hidden
data. Djebbar and other authors explain what this means, “basically, data are multiplied by an
M- sequence code known to both sender and receiver, then hidden in the cover audio” (Djebbar,
Ayad, Meraim & Harram, 2012). The final ‘part of audio steganography is echo hiding. By
creating an echo to enhance the signal of the host it will embed data into proper audio noises and
signals. This then creates an echo signal that involves the following components: initial
amplitude, the offset, and the decay rate. These components ensure that the hidden data is not
audible.
Video steganography involves the mixture of image and sound in the process of sending
its combined form over transmission medium. There are several forms of using video to hide
sensitive information or data. These forms are the following: Least Significance Bit (LSB),
spread spectrum, compressed video steganography, non-uniform rectangular transform, and
masking and filtering. Regardless the type of steganography, criminals tend to use whatever type
necessary to commit malicious crimes. Scripture often talks about crime and the different aspects
and consequences that come of committing it. Romans 12:19 states, “Dearly beloved, avenge not
yourselves, but [rather] give place unto wrath: for it is written, Vengeance [is] mine; I will repay,
saith the Lord” (King James Version).
Participation in Cybercrime
Steganography has started a digital revolution in the cybercrime unit. There are two
major crimes that utilize steganography and those are terrorists and pedophile groups. Terrorist
groups such as al-Qaeda use favorite websites to communicate via hidden messages or images.
According to Natasha Garcia, “In 2010, a Russian spy ring conversed and connected by posting
images encoded with secret messages to public websites. The Department of Justice (DOJ)
recovered over one hundred messages that were concealed within online pictures” (Garcia,
2018). As for pedophile groups, “Shadowz Brotherhood” was a group known for using material
involving children hidden within image files. This group was uncovered by the European Police
Office (Europol), which in turn allowed for this office to discover the steganographic
applications being used.
Corporate, organizational, societal, national, international, and military levels are
protected against cybercrime only after personal measures have been established for protection.
According to Regner Sabillon and other authors, “Technology by itself is not enough, the
integration of other fields like training, awareness, social aspects, culture, laws,
prosecution, and international cooperation are needed to blend with technical solutions to
tackle cybercrime” (Sabillon, Cano, Cavaller & Serra, 2016).
It is important that forensic science specialists and law enforcement personnel take the initiative
to pursue the proper training and defenses to protect against criminal steganographic attacks.
These groups’ behaviors should be studied and used to pursue other groups or organization that
try to use steganography in the same ways. There are several training options and defenses
available to reduce the involvement steganography has in cybercrime.
Training and Defenses
Lately, forensic specialists have not been interested in specializing in digital
steganography because steganography has been perceived as a non-threating issue within the
cybercrime field. Digital steganography does pose a threat to the cybercrime field. There are
several types of threats that digital steganography is involved with. Child pornography groups
and terrorist groups commonly use steganography to conceal the groups data and
communications between each other. This information should give light to the reason why
there should be proper training and security and defense protocols available.
One training program that is available is Black Hat. Black Hat allows a training program
to be available for forensic specialists to become familiar with the up-to-date steganographic
techniques and tools. According to Garcia, “This hands-on course also provides trainees with
experience in the latest investigation methods such as analyzing and recovering hidden data in
various cover types” (Garcia, 2018). These training courses help forensic science specialist
students prepare themselves to master the recovery of encrypted data or information through
aspects like detection, cracking, and analysis. Communities and law enforcement personnel
should make this training required and available for all personnel wishing to join the forensic
science field. Some forms of security and defenses already exist among the realm of digital
steganography. Scripture speaks about security in several different verses. For example,
Jeremiah 46:27 states the following verse, “But fear not thou, O my servant Jacob, and be not
dismayed, O Israel: for, behold, I will save thee from afar off, and thy seed from the land of their
captivity; and Jacob shall return, and be in rest and at ease, and none shall make [him] afraid”
(King James Version).
The one form of security model that is available involves the use of visual cryptography
and the neural network. This essentially means that a AES algorithm is needed to be used to
properly use a certain cryptography technique. According to Baby and Krishnan explains the
AES algorithm does the following: “The cover image is divided into blocks and energy
coefficient for each block is identified using IWT. The neural network is used to identify the
best location in host image in order to embed the secret data” (Baby & Krishnan, 2017).
Providing security and defenses against steganography does not have to be as complicated as
finding an
algorithm but rather simply by examining the strengthens and weaknesses of digital
steganography. This allows for the opportunity to implement proper strategic security and
defenses against malicious acts and crimes committed while using digital steganography.
One aspect of security against digital steganography is heavily reliant upon the efficiency
of steganographic noise. According to Hai-Tao Song and other authors explains, “After secret
messages being embedded totally, when the KL divergence between the cover image and the
stego image is the smallest, modification method corresponding to the steganographic noise is
optimal” (Song, Tang, Kou, Sun & Jiang, 2019). What this statement is saying is that the primary
purpose of a strategic security protocol is receiving the steganographic noise required to diminish
the KL divergence.
Conclusion
Due to the progression of the Internet and technology, steganography has become a
topic of discussion in the cybercrime and cybersecurity fields. Steganography can use a lot more
research and resources to ensure proper training and defenses. The training and defenses need to
be available not only security and cybersecurity personnel but also local law enforcement
personnel as well. It is important to be well-versed with the topic so that when the time comes
forensic science specialists and law enforcement personnel can take the necessary precautions
and steps to stop the criminals that are missing steganography.
Now because of the progression of the Internet, attacks have amplified on communication
computer users.
According to Baby and Krishnan, “Protecting the data is a big challenge for computer
users. Cryptography and steganography are widely used techniques to ensure
security. Both techniques have many applications in computer science and other
related fields.
Both methods provide security in their own ways, but to add multiple layers of security it
is always a good practice to use combination of these techniques (Baby & Krishnan,
2017).
Overall, the best strategy depends on the advantages each technique presents and the initial
application restrictions and the requirements that are involved in that like embedded data security
level, hiding capacity, and encountered attacks resistance.
Bibliography
Babita, E., & Kaur, E. (2017). A review: network security based on cryptography &
steganography techniques. International Journal of Advanced Research in
Computer Science, 8(4), 161-165. Retrieved from https://search-proquest-
com.ezproxy.liberty.edu/docview/1912629349?pq-origsite=summon
Baby, A., & Krishnan, H. (2017). Combined strength of steganography and cryptography - A
literature survey. International Journal of Advanced Research in Computer Science,
8(3), 1007-1010. Retrieved from https://search-proquest-
com.ezproxy.liberty.edu/docview/1901457380?pq-origsite=summon
Djebbar, F., Ayad, B., Meraim, K., & Hamam, H. (2012). Comparative study of digital audio
steganography techniques. EURASIP Journal on Audio, Speech, And Music Processing,
25, 1-16. doi: DOI:10.1186/1687-4722-2012-25
Garcia, N. (2018). Digital steganography and its existence in cybercrime. Scientific and
Practical Cyber Security Journal, 2(2), 18-24. Retrieved from
https://www.researchgate.net/publication/326098434_Digital_steganography_and_its_exi
stence_in_cybercrime
Holy Bible, King James Version.
Munuera, C. (2007). Steganography and error-correcting codes. Signal Processing, 87(6), 1528-
1533. doi: https://doi.org/10.1016/j.sigpro.2006.12.008
Ogiela, M., & Koptyra, K. (2015). False and multi-secret steganography in digital images. Soft
Computing, 19(11), 3331-3339. Retrieved from https://link-springer-
com.ezproxy.liberty.edu/article/10.1007%2Fs00500-015-1728-z
Ramaiya, M., Goyal, D., & Hemrajani, N. (2017). Data hiding in image using cryptography and
steganography: An investigation. International Journal of Advanced Research in
Computer Science, 8(7), 953-956. Retrieved from https://search-proquest-
com.ezproxy.liberty.edu/docview/1931130093?pq-origsite=summon
Sabillon, R., Cano, J., Cavaller, V., & Serra, J. (2016). Cybercrime and cybercriminals: A
comprehensive study. International Journal of Computer Networks and
Communications Security, 4(6), 165-176. Retrieved from https://search-proquest-
com.ezproxy.liberty.edu/docview/1874038161?pq-origsite=summon
Sharma, R., Ganotra, R., Dhall, S., & Gupta, S. (2018). Performance comparison of
steganography techniques. International Journal of Computer Network and Information
Security, 9, 37-46. doi: DOI:10.5815/ijcnis.2018.09.04
Song, H., Tang, G., Kou, G., Sun, Y., & Jiang, M. (2019). Digital steganography model and
embedding optimization strategy. Multimedia Tools and Applications, 78(7), 8271-8288.
Retrieved from https://link-springer-com.ezproxy.liberty.edu/article/10.1007%2Fs11042-
018-6810-y
Steganography/Steganalysis - Research - Digital Forensics and Cyber Security Center at the
University of Rhode Island. (2019). Retrieved from https://dfcsc.uri.edu/research/steg
Students also viewed