• DocumentCode
    1910675
  • Title

    Building Covert Channels over the Packet Reordering Phenomenon

  • Author

    El-Atawy, Adel ; Al-Shaer, Ehab

  • Author_Institution
    Sch. of Comput., DePaul Univ., Chicago, IL
  • fYear
    2009
  • fDate
    19-25 April 2009
  • Firstpage
    2186
  • Lastpage
    2194
  • Abstract
    New modes of communication have shown themselves to be needed for more secure and private types of data. Steganography or data-hiding through covert channels can be highly motivated by today´s security requirements and various needs of applications. Moreover, the amount of information in the Internet traffic is not bounded by what is contained in packets payload; there is considerable hidden capacity within packets and flows characteristics to build robust and stealthy covert channels. In this paper, we propose using the packet reordering phenomenon as the media to carry a hidden channel. As a naturally occurring behavior of packets traveling the Internet, it can as well be induced to send a signal to the receiving end. Specific permutations are selected to enhance the reliability of the channel, while their distribution was selected to imitate real traffic and increase stealthiness. The robustness of such channel is analyzed, and its bandwidth is calculated. A simple tool is implemented to communicate over the natural phenomenon of packet reordering. Reliability and capacity of the techniques are evaluated and promising results show the potential of the proposed approach.
  • Keywords
    Internet; computer network reliability; data encapsulation; security of data; telecommunication channels; telecommunication security; telecommunication traffic; Internet traffic; channel reliability; data privacy; data security; data-hiding; packet reordering phenomenon; Bandwidth; Computer hacking; Data communication; Data security; Information security; Internet; Payloads; Robustness; Steganography; Transport protocols;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    INFOCOM 2009, IEEE
  • Conference_Location
    Rio de Janeiro
  • ISSN
    0743-166X
  • Print_ISBN
    978-1-4244-3512-8
  • Electronic_ISBN
    0743-166X
  • Type

    conf

  • DOI
    10.1109/INFCOM.2009.5062143
  • Filename
    5062143