DocumentCode
3705290
Title
Analysis and monitoring of hidden TCP traffic based on an open-source covert timing channel
Author
Angelo Liguori;Francesco Benedetto;Gaetano Giunta;Nils Kopal;Arno Wacker
Author_Institution
University Roma Tre, Via V. Volterra 62, 00146 Rome, Italy
fYear
2015
Firstpage
667
Lastpage
674
Abstract
Many contexts dealing with sensitive information require high-robustness and high-assurance certified security systems that should not be affected by known vulnerabilities. Covert channels are illicit paths that could be exploited by attackers to convey illicit data flows that contravene the security policies. Many implementations of the so-called Covert Storage Channels exist, whereas no implementation of Covert Timing Channels is available. In this paper, we first discuss an Open-Source Covert Timing Channel implementation, describing in detail our innovative approach. Then, we analyze real TCP traffic in the presence of our covert channel for three scenarios of interest, varying the number of hops and round trip time of the connections. The results, from real network traffic monitoring, confirm the validity of our open-source covert timing channel implementation for hidden TCP traffic analysis, in different environmental and operating network conditions.
Keywords
"Security","Open source software","Context","Monitoring","Synchronization","Conferences"
Publisher
ieee
Conference_Titel
Communications and Network Security (CNS), 2015 IEEE Conference on
Type
conf
DOI
10.1109/CNS.2015.7346885
Filename
7346885
Link To Document