{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,16]],"date-time":"2026-07-16T02:42:46Z","timestamp":1784169766249,"version":"3.55.0"},"reference-count":44,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2026,2,23]],"date-time":"2026-02-23T00:00:00Z","timestamp":1771804800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2026,2,23]],"date-time":"2026-02-23T00:00:00Z","timestamp":1771804800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["1624668 and 1921485"],"award-info":[{"award-number":["1624668 and 1921485"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["2335046"],"award-info":[{"award-number":["2335046"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Cybersecurity"],"abstract":"<jats:title>Abstract<\/jats:title>\n                  <jats:p>The flexibility and complexity of IPv6 extension headers allow attackers to create covert channels or bypass security mechanisms, leading to potential data breaches or system compromises. The mature development of machine learning has become the primary detection technology option used to mitigate covert communication threats. However, the complexity of detecting covert communication, evolving injection techniques, and scarcity of data make building machine-learning models challenging. In previous related research, machine learning has shown good performance in detecting covert communications, but oversimplified attack scenario assumptions cannot represent the complexity of modern covert technologies and make it easier for machine learning models to detect covert communications. To bridge this gap, in this study, we analyzed the packet structure and network traffic behavior of IPv6, used encryption algorithms, and performed covert communication injection without changing network packet behavior to get closer to real attack scenarios. In addition to analyzing and injecting methods for covert communications, this study also uses comprehensive machine learning techniques to train the model proposed in this study to detect threats, including traditional decision trees such as random forests and gradient boosting, as well as complex neural network architectures such as CNNs and LSTMs, to achieve detection accuracy of over 90%. This study details the methods used for dataset augmentation and the comparative performance of the applied models, reinforcing insights into the adaptability and resilience of the machine learning application in IPv6 covert communication. We further introduce a Generative AI-driven script refinement framework, leveraging prompt engineering as a preliminary exploration of how generative agents can assist in covert communication detection and model enhancement.<\/jats:p>","DOI":"10.1186\/s42400-025-00485-z","type":"journal-article","created":{"date-parts":[[2026,2,23]],"date-time":"2026-02-23T02:02:15Z","timestamp":1771812135000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["Ai\/ml based detection and categorization of covert communication in IPv6 network"],"prefix":"10.1186","volume":"9","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-5009-221X","authenticated-orcid":false,"given":"Mohammad Wali Ur","family":"Rahman","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yu-Zheng","family":"Lin","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Carter","family":"Weeks","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"David","family":"Ruddell","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jeff","family":"Gabriellini","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Bill","family":"Hayes","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Salim","family":"Hariri","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Pratik","family":"Satam","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"suffix":"Jr.","given":"Edward V.","family":"Ziegler","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2026,2,23]]},"reference":[{"key":"485_CR1","unstructured":"Ackerman G, Johnson D, Stackpole B (2015) Covert channel using icmpv6 and ipv6 addressing, 63. The Steering Committee of The World Congress in Computer Science, Computer Engineering and Applied Computing (WorldComp)"},{"key":"485_CR2","doi-asserted-by":"crossref","unstructured":"Amante S, Rajahalme J, Carpenter BE, Jiang S (2011) IPv6 Flow Label Specification. RFC 6437 https:\/\/www.rfc-editor.org\/info\/rfc6437","DOI":"10.17487\/rfc6437"},{"key":"485_CR3","unstructured":"Baker F, Black DL, Nichols K, Blake SL (1998) Definition of the Differentiated Services Field (DS Field) in the IPv4 and IPv6 Headers. RFC 2474 (1998). https:\/\/www.rfc-editor.org\/info\/rfc2474"},{"key":"485_CR4","unstructured":"Beale J, Orebaugh A, Ramirez G (2006) Wireshark & Ethereal network protocol analyzer toolkit (Elsevier)"},{"key":"485_CR5","doi-asserted-by":"publisher","first-page":"103486","DOI":"10.1109\/ACCESS.2023.3318172","volume":"11","author":"P Bedi","year":"2023","unstructured":"Bedi P, Jindal V, Dua A (2023) Spyipv6: locating covert data in one or a combination of ipv6 header field (s). IEEE Access 11:103486\u2013103501","journal-title":"IEEE Access"},{"key":"485_CR6","doi-asserted-by":"crossref","unstructured":"Berger J, Klein A, Pinkas B (2020) Flaw label: Exploiting ipv6 flow label, IEEE, pp 1259\u20131276","DOI":"10.1109\/SP40000.2020.00075"},{"key":"485_CR7","doi-asserted-by":"publisher","first-page":"e4076","DOI":"10.1002\/ett.4076","volume":"32","author":"BS Bhati","year":"2021","unstructured":"Bhati BS, Chugh G, Al-Turjman F, Bhati NS (2021) An improved ensemble based intrusion detection technique using xgboost. Trans Emerg Telecommun Technol 32:e4076","journal-title":"Trans Emerg Telecommun Technol"},{"key":"485_CR8","doi-asserted-by":"publisher","first-page":"36","DOI":"10.1109\/MC.2009.54","volume":"42","author":"CE Caicedo","year":"2009","unstructured":"Caicedo CE, Joshi JB, Tuladhar SR (2009) Ipv6 security challenges. Computer 42:36\u201342","journal-title":"Computer"},{"key":"485_CR9","unstructured":"CAIDA. The caida anonymized 2019 internet traces (2019). https:\/\/www.caida.org\/data\/overview\/"},{"key":"485_CR10","doi-asserted-by":"publisher","first-page":"1641","DOI":"10.3390\/app11041641","volume":"11","author":"L Caviglione","year":"2021","unstructured":"Caviglione L (2021) Trends and challenges in network covert channels countermeasures. Appl Sci 11:1641","journal-title":"Appl Sci"},{"key":"485_CR11","doi-asserted-by":"publisher","first-page":"100975","DOI":"10.1016\/j.softx.2022.100975","volume":"17","author":"L Caviglione","year":"2022","unstructured":"Caviglione L, Schaffhauser A, Zuppelli M, Mazurczyk W (2022) Ipv6cc: Ipv6 covert channels for testing networks against stegomalware and data exfiltration. SoftwareX 17:100975","journal-title":"SoftwareX"},{"key":"485_CR12","doi-asserted-by":"crossref","unstructured":"Caviglione L, Zuppelli M, Mazurczyk W, Schaffhauser A, Repetto M (2021) Code augmentation for detecting covert channels targeting the ipv6 flow label, IEEE, pp 450\u2013456","DOI":"10.1109\/NetSoft51509.2021.9492661"},{"key":"485_CR13","unstructured":"Chen X, Lin M, Sch\u00e4rli N, Zhou D (2023) Teaching large language models to self-debug. arXiv preprint arXiv:2304.05128"},{"key":"485_CR14","doi-asserted-by":"publisher","first-page":"684","DOI":"10.1109\/TNSM.2022.3213807","volume":"20","author":"X Deng","year":"2022","unstructured":"Deng X et al (2022) Flow topology-based graph convolutional network for intrusion detection in label-limited iot networks. IEEE Trans Netw Serv Manage 20:684\u2013696","journal-title":"IEEE Trans Netw Serv Manage"},{"key":"485_CR15","doi-asserted-by":"publisher","first-page":"3392","DOI":"10.1007\/s11227-022-04783-y","volume":"79","author":"M Douiba","year":"2023","unstructured":"Douiba M, Benkirane S, Guezzaz A, Azrour M (2023) An improved anomaly detection model for iot security using decision tree and gradient boosting. J Supercomput 79:3392\u20133411","journal-title":"J Supercomput"},{"key":"485_CR16","doi-asserted-by":"publisher","first-page":"110661","DOI":"10.1109\/ACCESS.2022.3215132","volume":"10","author":"A Dua","year":"2022","unstructured":"Dua A, Jindal V, Bedi P (2022a) Detecting and locating storage-based covert channels in internet protocol version 6. IEEE Access 10:110661\u2013110675","journal-title":"IEEE Access"},{"key":"485_CR17","doi-asserted-by":"crossref","unstructured":"Dua A, Jindal V, Bedi P (2022b) Dicch-d: detecting ipv6-based covert channels using dnn, Springer, pp 42\u201353","DOI":"10.1007\/978-3-031-20977-2_4"},{"key":"485_CR18","doi-asserted-by":"publisher","first-page":"38391","DOI":"10.1109\/ACCESS.2022.3164392","volume":"10","author":"MA Elsadig","year":"2022","unstructured":"Elsadig MA, Gafar A (2022) Covert channel detection: machine learning approaches. IEEE Access 10:38391\u201338405","journal-title":"IEEE Access"},{"key":"485_CR19","doi-asserted-by":"publisher","first-page":"213","DOI":"10.1016\/j.procs.2016.06.047","volume":"89","author":"N Farnaaz","year":"2016","unstructured":"Farnaaz N, Jabbar M (2016) Random forest modeling for network intrusion detection system. Proc Comput Sci 89:213\u2013217","journal-title":"Proc Comput Sci"},{"key":"485_CR20","doi-asserted-by":"crossref","unstructured":"Floyd S, Ramakrishnan DKK, Black DL (2001) The Addition of Explicit Congestion Notification (ECN) to IP. RFC 3168. https:\/\/www.rfc-editor.org\/info\/rfc3168","DOI":"10.17487\/rfc3168"},{"key":"485_CR21","doi-asserted-by":"crossref","DOI":"10.1007\/978-3-319-10247-4","volume-title":"Data preprocessing in data mining","author":"S Garc\u00eda","year":"2015","unstructured":"Garc\u00eda S, Luengo J, Herrera F et al (2015) Data preprocessing in data mining, vol 72. Springer, Singapore"},{"key":"485_CR22","doi-asserted-by":"publisher","first-page":"104512","DOI":"10.1016\/j.cose.2025.104512","volume":"156","author":"X Gong","year":"2025","unstructured":"Gong X et al (2025) Feature selection method for network intrusion based on hybrid meta-heuristic dynamic optimization algorithm. Comput Secur 156:104512","journal-title":"Comput Secur"},{"key":"485_CR23","doi-asserted-by":"crossref","unstructured":"Houmansadr A, Brubaker C Shmatikov V (2013) The parrot is dead: observing unobservable network communications, IEEE, pp 65\u201379","DOI":"10.1109\/SP.2013.14"},{"key":"485_CR24","doi-asserted-by":"publisher","first-page":"115524","DOI":"10.1016\/j.eswa.2021.115524","volume":"185","author":"Y Imrana","year":"2021","unstructured":"Imrana Y, Xiang Y, Ali L, Abdul-Rauf Z (2021) A bidirectional lstm deep learning approach for intrusion detection. Expert Syst Appl 185:115524","journal-title":"Expert Syst Appl"},{"key":"485_CR25","doi-asserted-by":"publisher","first-page":"e8316","DOI":"10.1002\/cpe.8316","volume":"37","author":"MA Khadse","year":"2025","unstructured":"Khadse MA, Dakhane DM (2025) A review on network covert channel construction and attack detection. Concurr Comput Practi Exp 37:e8316","journal-title":"Concurr Comput Practi Exp"},{"key":"485_CR26","doi-asserted-by":"publisher","first-page":"101574","DOI":"10.1109\/ACCESS.2021.3097247","volume":"9","author":"J Lansky","year":"2021","unstructured":"Lansky J et al (2021) Deep learning-based intrusion detection systems: a systematic review. IEEE Access 9:101574\u2013101599","journal-title":"IEEE Access"},{"key":"485_CR27","doi-asserted-by":"publisher","first-page":"102289","DOI":"10.1016\/j.cose.2021.102289","volume":"106","author":"J Liu","year":"2021","unstructured":"Liu J, Gao Y, Hu F (2021) A fast network intrusion detection system using adaptive synthetic oversampling and lightgbm. Comput Secur 106:102289","journal-title":"Comput Secur"},{"key":"485_CR28","first-page":"147","volume-title":"Covert channels in ipv6","author":"NB Lucena","year":"2005","unstructured":"Lucena NB, Lewandowski G, Chapin SJ (2005) Covert channels in ipv6. Springer, Singapore, pp 147\u2013166"},{"key":"485_CR29","doi-asserted-by":"crossref","unstructured":"Mazurczyk W, Pow\u00f3jski K, Caviglione L (2019) Ipv6 covert channels in the wild, 1\u20136","DOI":"10.1145\/3360664.3360674"},{"key":"485_CR30","doi-asserted-by":"publisher","first-page":"8162","DOI":"10.3390\/app12168162","volume":"12","author":"L Mohammadpour","year":"2022","unstructured":"Mohammadpour L, Ling TC, Liew CS, Aryanfar A (2022) A survey of cnn-based network intrusion detection. Appl Sci 12:8162","journal-title":"Appl Sci"},{"key":"485_CR31","doi-asserted-by":"publisher","first-page":"1988","DOI":"10.1109\/COMST.2018.2883147","volume":"21","author":"F Pacheco","year":"2018","unstructured":"Pacheco F, Exposito E, Gineste M, Baudoin C, Aguilar J (2018) Towards the deployment of machine learning solutions in network traffic classification: a systematic survey. IEEE Commun Surv Tutor 21:1988\u20132014","journal-title":"IEEE Commun Surv Tutor"},{"key":"485_CR32","doi-asserted-by":"publisher","first-page":"73907","DOI":"10.1109\/ACCESS.2020.2988055","volume":"8","author":"J Pacheco","year":"2020","unstructured":"Pacheco J, Benitez VH, Felix-Herran LC, Satam P (2020) Artificial neural networks-based intrusion detection system for internet of things fog nodes. IEEE Access 8:73907\u201373918","journal-title":"IEEE Access"},{"key":"485_CR33","doi-asserted-by":"publisher","first-page":"2226","DOI":"10.1109\/TAI.2025.3544173","volume":"6","author":"MWU Rahman","year":"2025","unstructured":"Rahman MWU, Nevarez R, Mim LT, Hariri S (2025) Multi-agent actor-critic generative ai for query resolution and analysis. IEEE Trans Artif Intell 6:2226\u20132240","journal-title":"IEEE Trans Artif Intell"},{"key":"485_CR34","doi-asserted-by":"crossref","unstructured":"Repetto M, Caviglione L, Zuppelli M (2021) bccstego: A framework for investigating network covert channels, pp 1\u20137","DOI":"10.1145\/3465481.3470028"},{"key":"485_CR35","doi-asserted-by":"publisher","first-page":"1077","DOI":"10.1109\/TNSM.2020.3036138","volume":"18","author":"P Satam","year":"2020","unstructured":"Satam P, Hariri S (2020) Wids: An anomaly based intrusion detection system for wi-fi (ieee 802.11) protocol. IEEE Trans Netw Serv Manage 18:1077\u20131091","journal-title":"IEEE Trans Netw Serv Manage"},{"key":"485_CR36","doi-asserted-by":"publisher","first-page":"1185","DOI":"10.1007\/s00521-010-0487-0","volume":"21","author":"M Sheikhan","year":"2012","unstructured":"Sheikhan M, Jadidi Z, Farrokhi A (2012) Intrusion detection using reduced-size rnn based on feature grouping. Neural Comput Appl 21:1185\u20131190","journal-title":"Neural Comput Appl"},{"key":"485_CR37","doi-asserted-by":"crossref","unstructured":"Simmons GJ, Chaum D (ed) (1984) The prisoners\u2019 problem and the subliminal channel. (ed.Chaum, D.) Advances in Cryptology: Proceedings of Crypto 83, Springer, pp 51\u201367","DOI":"10.1007\/978-1-4684-4730-9_5"},{"key":"485_CR38","first-page":"123","volume":"15","author":"J Smith","year":"2011","unstructured":"Smith J, Doe J (2011) Security and privacy considerations for ipv6 address generation mechanisms. J Netw Secur 15:123\u2013135","journal-title":"J Netw Secur"},{"key":"485_CR39","unstructured":"Suprun O et al (2025) Development of a modified steganographic model of data transmission using ipv6 protocol"},{"key":"485_CR40","doi-asserted-by":"crossref","unstructured":"Wang J et al (2022) Cc-guard: An ipv6 covert channel detection method based on field matching, IEEE, pp 1416\u20131421","DOI":"10.1109\/HPCC-DSS-SmartCity-DependSys57074.2022.00219"},{"key":"485_CR41","first-page":"50528","volume":"37","author":"J Yang","year":"2024","unstructured":"Yang J et al (2024) Swe-agent: Agent-computer interfaces enable automated software engineering. Adv Neural Inf Process Syst 37:50528\u201350652","journal-title":"Adv Neural Inf Process Syst"},{"key":"485_CR42","doi-asserted-by":"crossref","unstructured":"Zhang H et al (2023) How far have edge clouds gone? a spatial-temporal analysis of edge network latency in the wild, pp 1\u201310","DOI":"10.1109\/IWQoS57198.2023.10188741"},{"issue":"1","key":"485_CR43","doi-asserted-by":"publisher","first-page":"258","DOI":"10.1109\/TCCN.2024.3421309","volume":"11","author":"L Zhang","year":"2024","unstructured":"Zhang L et al (2024) A self-attention mechanism-based model to detect ipv6 multi-field covert channels. IEEE Trans Cognit Commun Netw 11(1):258\u2013273","journal-title":"IEEE Trans Cognit Commun Netw"},{"key":"485_CR44","doi-asserted-by":"crossref","unstructured":"Zuppelli M, Caviglione L (2021) pcapstego: A tool for generating traffic traces for experimenting with network covert channels","DOI":"10.1145\/3465481.3470067"}],"container-title":["Cybersecurity"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-025-00485-z.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1186\/s42400-025-00485-z","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-025-00485-z.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,2,23]],"date-time":"2026-02-23T02:02:19Z","timestamp":1771812139000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1186\/s42400-025-00485-z"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,2,23]]},"references-count":44,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2026,12]]}},"alternative-id":["485"],"URL":"https:\/\/doi.org\/10.1186\/s42400-025-00485-z","relation":{},"ISSN":["2523-3246"],"issn-type":[{"value":"2523-3246","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,2,23]]},"assertion":[{"value":"26 February 2025","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"14 September 2025","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"23 February 2026","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare that they have no Conflict of interest. The authors have no relevant financial or non-financial interests to disclose. The authors have no Conflict of interest to declare that are relevant to the content of this article. All authors certify that they have no affiliations with or involvement in any organization or entity with any financial interest or non-financial interest in the subject matter or materials discussed in this manuscript. The authors have no financial or proprietary interests in any material discussed in this article.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing Interests"}}],"article-number":"33"}}