• DocumentCode
    1288406
  • Title

    Characterizing the Efficacy of the NRL Network Pump in Mitigating Covert Timing Channels

  • Author

    Gorantla, Siva K. ; Kadloor, Sachin ; Kiyavash, Negar ; Coleman, Todd P. ; Moskowitz, Ira S. ; Kang, Myong H.

  • Author_Institution
    Coordinated Sci. Lab., Univ. of Illinois, Urbana, IL, USA
  • Volume
    7
  • Issue
    1
  • fYear
    2012
  • fDate
    2/1/2012 12:00:00 AM
  • Firstpage
    64
  • Lastpage
    75
  • Abstract
    The Naval Research Laboratory (NRL) Network Pump, or Pump, is a standard for mitigating covert channels that arise in a multilevel secure (MLS) system when a high user (HU) sends acknowledgements to a low user (LU). The issue here is that HU can encode information in the "timings" of the acknowledgements. The Pump aims at mitigating the covert timing channel by introducing buffering between HU and LU, as well as adding noise to the acknowledgment timings. We model the working of the Pump in certain situations, as a communication system with feedback and use then this perspective to derive an upper bound on the capacity of the covert channel between HU and LU in the Pump. This upper bound is presented in terms of a directed information flow over the dynamics of the system. We also present an achievable scheme that can transmit information over this channel. When the support of the noise added by Pump to acknowledgment timings is finite, the achievable rate is nonzero, i.e., infinite number of bits can be reliably communicated. If the support of the noise is infinite, the achievable rate is zero and hence a finite number of bits can be communicated.
  • Keywords
    channel capacity; computer network reliability; computer network security; data communication; encoding; military communication; naval engineering; MLS system; NRL network pump efficacy; Naval Research Laboratory; acknowledgment timings; communication reliability; communication system; covert channel capacity; covert timing channel mitigation; directed information flow; high user; information encoding; information transmission; low user; multilevel secure system; upper bound; Cryptography; Encoding; Materials; Noise; Noise measurement; Timing; Upper bound; Information-theoretic bounds; NRL network pump; network security; queueing theory; timing channels;
  • fLanguage
    English
  • Journal_Title
    Information Forensics and Security, IEEE Transactions on
  • Publisher
    ieee
  • ISSN
    1556-6013
  • Type

    jour

  • DOI
    10.1109/TIFS.2011.2163398
  • Filename
    5970117