Covert Channels and Countermeasures in Computer Network Protocols[Reprinted from IEEE Communications Surveys and Tutorials]

  • Authors:
  • S. Zander;G. Armitage;P. Branch

  • Affiliations:
  • Univ. of Technol. Melbourne, Melbourne;-;-

  • Venue:
  • IEEE Communications Magazine
  • Year:
  • 2007

Quantified Score

Hi-index 0.25

Visualization

Abstract

Covert channels are used for the secret transfer of information. Encryption only protects communication from being decoded by unauthorized parties, whereas covert channels aim to hide the very existence of the communication. Initially, covert channels were identified as a security threat on monolithic systems such as mainframes. More recently, focus has shifted toward covert channels in computer network protocols. The huge amount of data and large number of different protocols in the Internet is ideal as a high-bandwidth vehicle for covert communication. This article provides an overview of the existing techniques for creating covert channels in widely deployed network protocols, and common methods for their detection, elimination, and capacity limitation.