munotes®

Steganography: Hiding That There Is a Message at All

Get access to whole semester resourcesSemester Pass

Chapter Sixteen

Syllabus topic Module 1, "Classical Encryption Techniques: Steganography"

Pages 81 to 85 of 678

In one line

Encryption hides what the message says. Steganography hides that there is a message. An opponent who sees a cipher knows something secret is being sent; an opponent who sees a holiday photograph does not.

In the wording a student can write in an examination: steganography is the practice of concealing the existence of a message, in contrast to cryptography, which conceals its contents. A plaintext message is hidden inside an innocuous-looking cover, so that a third party observing the cover has no reason to suspect that any communication is taking place.

Why anybody would use it

Because sometimes the dangerous fact is not the content but the traffic. Three situations make the distinction real.

Where encryption is forbidden or suspicious. If the use of encryption is itself illegal, or invites attention, a ciphertext is a confession. A picture is not.

Where you are hiding from traffic analysis rather than from a reader. The previous chapters established that encryption leaves the pattern of communication visible. Steganography attacks that directly: there is no pattern, because there is no apparent message.

Where the two are combined, which is what a careful party actually does: encrypt the message, then hide the ciphertext. Then an opponent who does not find it learns nothing at all, and an opponent who finds it still faces the cipher. That layering is the right answer to "compare steganography and cryptography": they are not alternatives.

The classical methods

These are the ones MU's reading list names, and they are worth knowing because the ideas recur.

Character marking. Selected letters of printed text are overwritten in pencil. The marks are invisible in ordinary light and show when the paper is held at an angle.

Invisible ink. A substance that leaves no visible trace until heat or a chemical is applied.

Pin punctures. Small pin holes over selected letters, invisible unless the paper is held up to a light.

Typewriter correction ribbon. Used between the lines typed with a black ribbon, so the result is invisible unless the paper is examined under a strong light.

The first-letter method. A message whose first letters, or the letters at some other agreed positions, spell out the real message. The classical name for this is an acrostic, and it is the one form of steganography a student can construct on paper in an examination.

The modern method, performed

A digital image stores each pixel as a number. Changing the last bit of that number changes the brightness of one pixel by one part in 256, which no eye detects. So a message can be written one bit at a time into the last bits of the pixel bytes, and the picture still looks like the picture.

munotes.in81

Steganography: Hiding That There Is a Message at All

The program below builds a 16 by 16 grey picture so that it is complete in itself, hides a twelve-character message in it, prints what changed, and reads the message back.

# A picture, and a message hidden in the last bit of each byte of it.
# The picture is made here rather than read from a file, so the program is
# complete and the numbers below are its own.

WIDTH, HEIGHT = 16, 16

def make_picture():
    """A grey gradient. Each pixel is one byte, 0 black to 255 white."""
    return bytearray(((x * 16 + y * 3) % 256) for y in range(HEIGHT)
                     for x in range(WIDTH))

def to_bits(message):
    data = message.encode("ascii") + b"\x00"
    return [(b >> (7 - i)) & 1 for b in data for i in range(8)]

def hide(picture, message):
    out = bytearray(picture)
    bits = to_bits(message)
    if len(bits) > len(out):
        raise ValueError("the picture is too small for the message")
    for i, bit in enumerate(bits):
        out[i] = (out[i] & 0xFE) | bit
    return out

def reveal(picture):
    bits, chars = [], []
    for byte in picture:
        bits.append(byte & 1)
        if len(bits) == 8:
            value = 0
            for b in bits:
                value = (value << 1) | b
            if value == 0:
                return "".join(chars)
            chars.append(chr(value))
            bits = []
    return "".join(chars)

original = make_picture()
message = "PAPER LEAKED"
carrier = hide(original, message)

print("picture size      :", WIDTH, "by", HEIGHT, "=", len(original), "bytes")
print("message           :", message)
print("bits to hide      :", len(to_bits(message)), "so", len(to_bits(message)),
      "of", len(original), "bytes are touched")
print()
print("the first twelve bytes, before and after:")
print("   before:", " ".join("%3d" % b for b in original[:12]))
print("   after :", " ".join("%3d" % b for b in carrier[:12]))
print("   change:", " ".join("%+3d" % (carrier[i] - original[i]) for i in range(12)))
print()
changed = sum(1 for i in range(len(original)) if original[i] != carrier[i])
print("bytes changed     :", changed, "of", len(original))
print("largest change    :", max(abs(carrier[i] - original[i]) for i in range(len(original))))
print("recovered message :", reveal(carrier))
print()
print("and here is why it is not encryption: anybody who suspects the trick")
print("reads it straight out, with no key at all.")
picture size      : 16 by 16 = 256 bytes
message           : PAPER LEAKED
bits to hide      : 104 so 104 of 256 bytes are touched

the first twelve bytes, before and after:
   before:   0  16  32  48  64  80  96 112 128 144 160 176
   after :   0  17  32  49  64  80  96 112 128 145 160 176
   change:  +0  +1  +0  +1  +0  +0  +0  +0  +0  +1  +0  +0

bytes changed     : 46 of 256
largest change    : 1
recovered message : PAPER LEAKED

and here is why it is not encryption: anybody who suspects the trick
reads it straight out, with no key at all.
munotes.in82

Steganography: Hiding That There Is a Message at All

Read four things out of that run.

104 bits were written and only 46 bytes changed. A bit is only written when it differs from the bit already there, and about half the time it does not. That is worth noticing because it is why the method is hard to see: a random message overwrites a random half of the bits it touches.

The largest change to any byte is 1. Out of a range of 256. The picture is visually identical, and that is the whole claim of least significant bit steganography, stated as a measurement rather than as an assurance.

The message came back exactly. The terminating zero byte tells the reader where to stop, which is a detail every implementation needs and most descriptions omit: without it you cannot tell the message from the picture's own last bits.

A twelve-character message needed 104 of 256 bytes. So the capacity of a cover is about one eighth of its size, and that is the arithmetic to quote: one bit per byte, so one character per eight bytes. A one-megabyte photograph hides about 128 kilobytes, which is a great deal of text, and that is why the method is used.

The weaknesses, honestly

It is not secure, in the sense this subject uses the word. There is no key. Anybody who suspects that the last bits of a picture carry a message reads it out, which is exactly what the reveal function does. The security is entirely in the opponent's ignorance of the method, and the chapter on the symmetric cipher model already dealt with that: it is security through obscurity.

Statistical detection works. The last bits of a real photograph are not random, they are correlated with the image. A hidden message makes them look random, and that difference is measurable. The field that does this is called steganalysis, and simple tests catch simple hides reliably.

The overhead is enormous. Concealing a few hundred bits of message needed a cover of several thousand bits. An answer should quote the ratio: eight cover bits carry one message bit in the method above.

Any change to the cover destroys the message. Recompressing the picture, resizing it, or saving it in a format that discards detail removes the last bits and with them the message. A file that has passed through a social media platform has almost certainly lost it.

Distinctions that carry marks

CryptographySteganography
Hidesthe contents of the messagethe existence of the message
An opponent who interceptsknows a secret is being sentsuspects nothing
Needs a keyyesin the simple form, no
Fails whenthe key is compromisedthe method is guessed
Overheadthe ciphertext is about the size of the plaintextthe cover is many times the message
Survives re-encoding of the carrieryesusually not
Best practiceuse both: encrypt, then hide the ciphertext
munotes.in83

Steganography: Hiding That There Is a Message at All

SteganographyWatermarking
Purposesecret communicationproving ownership or tracing a copy
The hidden data isa message for a recipienta mark about the carrier itself
Should survive attacknot necessarilyyes, that is the requirement
Should be undetectableyesnot always; a visible watermark is normal

A worked example: which one does the job

The requirement. A journalist inside an organisation wants to send a document to a colleague. Two different threats.

Threat A: the network operator can read the traffic. Encryption answers this. The operator sees an encrypted file, cannot read it, and the job is done. Steganography would be pointless extra work.

Threat B: the network operator will act against anybody who sends an encrypted file. Encryption fails here, not because it can be broken but because using it is the offence. Steganography answers this: the journalist sends a photograph.

The correct design for both threats at once. Encrypt the document with a key the colleague already holds, then hide the ciphertext in the photograph. If the cover is never suspected, nothing is learned. If it is suspected and the ciphertext extracted, the cipher still stands. Two independent failures are needed instead of one, which is the principle of defence in depth and the reason the two techniques belong together.

Quick revision

  • Steganography hides the existence of a message; cryptography hides its contents.
  • Classical methods: character marking, invisible ink, pin punctures, typewriter correction ribbon, and the acrostic or first-letter method.
  • Modern method: least significant bit substitution in an image or audio file. One bit per byte, so one character per eight bytes.
  • In the run: a 12-character message in a 256-byte picture touched 104 bytes, changed 46, and the largest change to any byte was 1.
  • A terminator is needed so the reader knows where the message ends.
  • Weaknesses: no key, so it is security through obscurity; statistical steganalysis detects it; huge overhead; destroyed by recompressing the carrier.
  • Watermarking is the related technique for proving ownership, and it must survive attack rather than merely avoid detection.
  • Best practice: encrypt, then hide, so that two independent failures are needed.

Test yourself

1. Distinguish steganography from cryptography. Cryptography conceals the contents of a message, so an interceptor knows that a secret is being sent but cannot read it. Steganography conceals the existence of the message by hiding it inside an innocuous cover, so an interceptor has no reason to suspect a communication at all.

munotes.in84

Steganography: Hiding That There Is a Message at All

2. Name four classical steganographic techniques. Character marking, in which selected letters of printed text are overwritten in pencil; invisible ink; pin punctures over chosen letters; and the use of a typewriter correction ribbon between the lines. The first-letter or acrostic method is a fifth.

3. Explain least significant bit steganography and state its capacity. Each pixel of an image is stored as a number, and changing its lowest bit alters the brightness by one part in 256, which is invisible. The message's bits are written one per byte into those lowest bits. The capacity is therefore one bit per byte of cover, that is one character per eight bytes, so a one-megabyte image holds about 128 kilobytes of text.

4. In the chapter's run, 104 bits were hidden and only 46 bytes changed. Why? Because a bit is only altered when it differs from the bit already in that position, and for a roughly random message that is about half the time. The consequence is that a hide touches fewer bytes than it writes bits, which makes it harder to notice.

5. Give three weaknesses of steganography. It has no key in its simple form, so its security rests entirely on the method not being guessed, which is security through obscurity. Statistical analysis, called steganalysis, detects it, because the lowest bits of a real photograph are correlated with the image and a hidden message makes them look random. And the overhead is very large, with eight cover bits needed per message bit.

6. Why is a hidden message lost when a picture is uploaded to a social media platform? Because such platforms recompress and often resize the image, and both operations discard exactly the fine detail that the lowest bits carry. The cover survives visually and the message does not.

7. What is the correct way to combine the two techniques, and why? Encrypt the message first and hide the resulting ciphertext in the cover. Then an opponent must both discover the hiding method and break the cipher, so two independent defences must fail rather than one; and if the cover is never suspected, nothing at all is learned.

munotes.in85

The rest of this subject

These notes are cut from the University's printed syllabus. Open the syllabus itself for the same subject.

Issue
Done!