Network Based Detection of Passive Covert Channels in TCP/IP

  • Authors:
  • Eugene Tumoian;Maxim Anikeev

  • Affiliations:
  • Taganrog State University;Taganrog State University

  • Venue:
  • LCN '05 Proceedings of the The IEEE Conference on Local Computer Networks 30th Anniversary
  • Year:
  • 2005

Quantified Score

Hi-index 0.00

Visualization

Abstract

A new method of covert channel detection in Initial Sequence Number (ISN) of TCP/IP is proposed in the paper. The detection is based on ISN generation model of original OS. Whenever any statistical deviations of ISN network packet from the ISN model are discovered; it is considered that this ISN packet is generated by malicious software, which tries to create a covert channel. The method was tested using experimental data generated by NUSHU covert channel creation tool, which has been developed by Joanna Rutkowska.