Logo image
Stealthier Inter-packet timing covert channels
Journal article   Open access   Peer reviewed

Stealthier Inter-packet timing covert channels

S. Zander, G. Armitage and P. Branch
NETWORKING 2011, Vol.6640, pp.458-470
2011
pdf
stealthier.pdfDownloadView
Author’s Version Open Access
url
Link to Published Version *Subscription may be requiredView

Abstract

Covert channels aim to hide the existence of communication. Recently proposed packet-timing channels encode covert data in inter-packet times, based on models of inter-packet times of normal traffic. These channels are detectable if normal inter-packet times are not independent identically-distributed, which we demonstrate is the case for several network applications. We show that ~80% of channels are detected with a false positive rate of 0.5%. We then propose an improved channel that is much harder to detect. Only ~9% of our new channels are detected at a false positive rate of 0.5%. Our new channel uses packet content for synchronisation and works with UDP and TCP traffic. The channel capacity reaches over hundred bits per second depending on overt traffic and network jitter.

Details

Metrics

408 File views/ downloads
67 Record Views
Logo image