Covert Communications through Network Configuration Messages

TitleCovert Communications through Network Configuration Messages
Publication TypeJournal Article
Year of Publication2013
AuthorsR. Rios, J. A. Onieva, and J. Lopez
JournalComputers & Security
Volume39, Part A
Pagination34 - 46
Date PublishedNov 2013
PublisherElsevier
ISSN Number0167-4048
KeywordsCovert channels, Information Warfare, Intrusion Detection, Network Security, System Information Security
Abstract

Covert channels are a form of hidden communication that may violate the integrity of systems. Since their birth in Multi-Level Security systems in the early 70’s they have evolved considerably, such that new solutions have appeared for computer networks mainly due to vague protocols specifications. In this paper we concentrate on short-range covert channels and analyze the opportunities of concealing data in various extensively used protocols today. From this analysis we observe several features that can be effectively exploited for subliminal data transmission in the Dynamic Host Configuration Protocol (DHCP). The result is a proof-of-concept implementation, HIDE\_DHCP, which integrates three different covert channels each of which accommodate to different stealthiness and capacity requirements. Finally, we provide a theoretical and experimental analysis of this tool in terms of its reliability, capacity, and detectability.

DOI10.1016/j.cose.2013.03.004
Citation Keyrios2013a
Paper File: 
https://nics.uma.es:8082/sites/default/files/papers/rios2013a_0.pdf

Supported by PISCIS SPRINT ARES