DocumentCode
2300403
Title
Covert DCF: A DCF-Based Covert Timing Channel in 802.11 Networks
Author
Holloway, Russell ; Beyah, Raheem
Author_Institution
Counter Threat Unit, Dell SecureWorks, Atlanta, GA, USA
fYear
2011
fDate
17-22 Oct. 2011
Firstpage
570
Lastpage
579
Abstract
Covert communications have been used for many decades. Accordingly, when digital communications moved to the forefront it was natural that covert channels be proposed to operate over these networks. Covert channels are general purpose transmission mediums that can be used for good (e.g., an additional layer of security) or bad (e.g., to conduct various proximity-based attacks in wireless LANs). However, their use has been limited as a result of their low throughput. One area that is promising for covert channels is wireless networks. Specifically, those that employ carrier sense multiple access with collision avoidance (CSMA/CA) (e.g., 802.11 networks). These schemes introduce randomness in the network that provides good cover for a covert timing channel. In this paper, we propose a relatively high bandwidth covert timing channel for 802.11 networks (Covert DCF). We exploit the random backoff in the distributed coordinated function (DCF), used to avoid collisions, to provide cover for our covert timing channel. Covert DCF provides significant improvements over other recent covert channels in the area of throughput, while maintaining high accuracy and remaining undetectable. We are able to covertly achieve throughput of 1800 bps while maintaining 99% accuracy. This throughput is approximately 17 times faster than that of current covert timing channels. Covert DCF is robust in that it can adapt to various network conditions.
Keywords
carrier sense multiple access; telecommunication security; wireless LAN; wireless channels; 802.11 network; CSMA/CA; DCF-based covert timing channel; carrier sense multiple access; collision avoidance; covert DCF; covert communication; distributed coordinated function; proximity-based attack; wireless LAN; Accuracy; IEEE 802.11 Standards; Protocols; Security; Throughput; Timing; Wireless communication; 802.11 DCF; MAC misbehavior; covert channel; steganography; wireless LANs;
fLanguage
English
Publisher
ieee
Conference_Titel
Mobile Adhoc and Sensor Systems (MASS), 2011 IEEE 8th International Conference on
Conference_Location
Valencia
ISSN
2155-6806
Print_ISBN
978-1-4577-1345-3
Type
conf
DOI
10.1109/MASS.2011.60
Filename
6076655
Link To Document