Design of Transport Layer Based Hybrid Covert Channel Detection Engine
نویسندگان
چکیده
Computer network is unpredictable due to information warfare and is prone to various attacks. Such attacks on network compromise the most important attribute, the privacy. Most of such attacks are devised using special communication channel called ``Covert Channel''. The word ``Covert'' stands for hidden or non-transparent. Network Covert Channel is a concealed communication path within legitimate network communication that clearly violates security policies laid down. The non-transparency in covert channel is also referred to as trapdoor. A trapdoor is unintended design within legitimate communication whose motto is to leak information. Subliminal channel, a variant of covert channel works similarly except that the trapdoor is set in a cryptographic algorithm. A composition of covert channel with subliminal channel is the ``Hybrid Covert Channel''. Hybrid covert channel is homogenous or heterogeneous mixture of two or more variants of covert channels either active at same instance or at different instances of time. Detecting such malicious channel activity plays a vital role in removing threat to the legitimate network. In this paper, we present a study of multi-trapdoor covert channels and introduce design of a new detection engine for hybrid covert channel in transport layer visualized in TCP and SSL.
منابع مشابه
Entropy Based Detection And Behavioral Analysis Of Hybrid Covert Channeling Secured Communication
Covert channels is a vital setup in the analysing the strength of security in a network. Covert Channel is illegitimate channelling over the secured channel and establishes a malicious conversation. The trap-door set in such channels proliferates making covert channel sophisticated to detect their presence in network firewall. This is due to the intricate covert scheme that enables to build rob...
متن کاملطراحی و ارزیابی روش کدگذاری ترکیبی برای کانال پوششی زمانبندیدار در شبکه اینترنت
Covert channel means communicating information through covering of overt and authorized channel in a manner that existence of channel to be hidden. In network covert timing channels that use timing features of transmission packets to modulating covert information, the appropriate encoding schema is very important. In this paper, a hybrid encoding schema proposed through combining "the inter-pac...
متن کاملAn Application Layer Covert Channel: Information Hiding With Cha ng
The purpose of our project was the implementation of an application-layer covert channel, with guaranteed con dentiality via cha ng. A covert channel is a means of passing information between two parties in such a manner that the existence of the communication channel itself is not obvious to the casual observer. Additionally, the implementation of a covert channel is enhanced through encryptio...
متن کاملNumerical Modeling of an Innovative Bipolar Plate Design Based on the Leaf Venation Patterns for PEM Fuel Cells
Flow channel design on bipolar plates has a direct effect on Proton Exchange Membrane (PEM) fuel cell performance. It has been found out that the flow field design has a deterministic role on the mass transport and water management, and therefore on the achieved power in PEM Fuel cells. This study concentrates on improvements in the fuel cell performance through optimization of channel dimensio...
متن کاملProtoLeaks: A Reliable and Protocol-Independent Network Covert Channel
We propose a theoretical framework for a network covert channel based on enumerative combinatorics. It offers protocol independence and avoids detection by using a mimicry defense. Using a network monitoring phase, traffic is analyzed to detect which application-layer protocols are allowed through the firewalls. Using these results, a covert channel is built based on permutations of benign netw...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید
ثبت ناماگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید
ورودعنوان ژورنال:
- CoRR
دوره abs/1101.0104 شماره
صفحات -
تاریخ انتشار 2010