• DocumentCode
    2311455
  • Title

    Masquerading a Wired Covert Channel into a Wireless-like Channel

  • Author

    Guirguis, Mina ; Valdez, Jason

  • Author_Institution
    Comput. Sci. Dept., Texas State Univ., San Marcos, TX
  • fYear
    2008
  • fDate
    7-9 Dec. 2008
  • Firstpage
    439
  • Lastpage
    444
  • Abstract
    This paper presents a novel method to implement a covert channel that is based on inducing dynamics to convey a covert message. These dynamics are induced in a manner that emulates the normal operation of a hypothetical virtual channel. As a case study, this paper focuses on a scenario whereby TCP packet losses are induced to change the behavior of the Additive-Increase Multiplicative-Decrease (AIMD) congestion control mechanism of TCP to convey the covert message. From the outside, the TCP connection appears to be a normal connection that is traversing a congested link or a lossy wireless link. However, the sender, through monitoring the packets that get retransmitted, will decode the covert message. Packet losses are induced based on a hashing algorithm with specific hash patterns that are chosen a priori to emulate a specific loss rate. We have assessed the performance of this covert channel through simple analysis, simulation and real Internet experiments. We illustrate the existence of an optimal packet drop rate that maximizes the throughput of the covert channel.
  • Keywords
    channel coding; cryptography; decoding; telecommunication congestion control; telecommunication security; transport protocols; wireless channels; AIMD congestion control mechanism; TCP packet loss; additive-increase multiplicative-decrease; covert message decoding; covert message dynamics; hashing algorithm; lossy wireless link; packet monitoring; virtual channel; wired covert channel masquerade; wireless-like channel; Analytical models; Communication channels; Computer science; Decoding; Error correction codes; Internet; Monitoring; Performance analysis; TCPIP; Timing;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Performance, Computing and Communications Conference, 2008. IPCCC 2008. IEEE International
  • Conference_Location
    Austin, Texas
  • ISSN
    1097-2641
  • Print_ISBN
    978-1-4244-3368-1
  • Electronic_ISBN
    1097-2641
  • Type

    conf

  • DOI
    10.1109/PCCC.2008.4745090
  • Filename
    4745090