Abstract
Hiding information in network traffic may lead to leakage of confidential information. In this paper we introduce a new steganographic system: the PadSteg (Padding Steganography). To authors’ best knowledge it is the first information hiding solution which represents inter-protocol steganography i.e. usage of relation between two or more protocols from the TCP/IP stack to enable secret communication. PadSteg utilizes ARP and TCP protocols together with an Etherleak vulnerability (improper Ethernet frame padding) to facilitate secret communication for hidden groups in LANs (Local Area Networks). Basing on real network traces we confirm that PadSteg is feasible in today’s networks and we estimate what steganographic bandwidth is achievable while limiting the chance of disclosure. We also point at possible countermeasures against PadSteg.
References
Rowland, C. (1997). Covert channels in the TCP/IP protocol suite. First Monday. Peer Reviewed Journal on the Internet, July 1997.
Zander, S., Armitage, G., & Branch, P. (2007). A survey of covert channels and countermeasures in computer network protocols. IEEE Communications Surveys and Tutorials, 9(3), 44–57.
Petitcolas, F., Anderson, R., & Kuhn, M. (1999). Information hiding—a survey. IEEE Special Issue on Protection of Multimedia Content, July 1999.
Murdoch, S. J., & Lewis, S. (2005). Embedding covert channels into TCP/IP. In Information hiding (pp. 247–261).
Ahsan, K., & Kundur, D. (2002). Practical data hiding in TCP/IP. In Proc. ACM wksp. multimedia security, December 2002.
Kundur, D., & Ahsan, K. (2003). Practical Internet steganography: data hiding in IP. In Proc. Texas wksp. security of information systems, April 2003.
Fisk, G., Fisk, M., Papadopoulos, C., & Neil, J. (2002). Eliminating steganography in Internet traffic with active wardens. In Lecture notes in computer science: Vol. 2578. Proc. 5th international workshop on information hiding (pp. 18–35).
Lucena, N. B., Lewandowski, G., & Chapin, S. J. (2005). Covert channels in IPv6. In Proc. privacy enhancing technologies (PET) (pp. 147–166), May 2005
Arkin, O., & Anderson, J. (2003). Ethernet frame padding information leakage (Atstake report). http://packetstorm.codar.com.br/advisories/atstake/atstake_etherleak_report.pdf.
Plummer, D. C. (1982). An ethernet address resolution protocol. RFC 826, November 1982.
Girling, C. G. (1987). Covert channels in LAN’s. IEEE Transactions on Software Engineering, SE-13(2), 292–296.
Handel, T., & Sandford, M. (1996). Hiding data in the OSI network model. In Proceedings of the first international workshop on information hiding (pp. 23–38).
Wolf, M. (1989). Covert channels in LAN protocols. In Proc. wksp. local area network security (LANSEC) (pp. 91–101).
Mazurczyk, W., & Szczypiorski, K. (2008). Steganography of VoIP streams. In R. Meersman & Z. Tari (Eds.), Lecture notes in computer science: Vol. 5332. OTM 2008, Part II (pp. 1001–1018). Proc. of the 3rd international symposium on information security (IS’08), Monterrey, Mexico, November 2008. Berlin: Springer.
Mazurczyk, W., Smolarczyk, M., & Szczypiorski, K. Retransmission steganography and its detection. Soft Computing, 15(3), 505–515.
Jankowski, B., Mazurczyk, W., & Szczypiorski, K. Information hiding using improper frame padding. Submitted to 14th international telecommunications network strategy and planning symposium (Networks 2010), 27–30.09.2010, Warsaw, Poland.
Author information
Authors and Affiliations
Corresponding author
Rights and permissions
Open Access This is an open access article distributed under the terms of the Creative Commons Attribution Noncommercial License (https://creativecommons.org/licenses/by-nc/2.0), which permits any noncommercial use, distribution, and reproduction in any medium, provided the original author(s) and source are credited.
About this article
Cite this article
Jankowski, B., Mazurczyk, W. & Szczypiorski, K. PadSteg: introducing inter-protocol steganography. Telecommun Syst 52, 1101–1111 (2013). https://doi.org/10.1007/s11235-011-9616-z
Published:
Issue Date:
DOI: https://doi.org/10.1007/s11235-011-9616-z
Keywords
- Steganography
- ARP
- Frame padding
- Etherleak