Covert Messaging through TCP Timestamps
Covert channels exist in most communications systems and allow individuals to communicate truly undectably. However, covert channels are seldom used due to their complexity. A protocol for sending data over a common class of low-bandwidth covert channels has been developed. The protocol is secure against attack by powerful adversaries. The design of a practical system implementing the protocol on a standard platform (Linux) exploiting a channel in a common communications system (TCP timestamps) is presented. A partial implementation of this system has been accomplished.
KeywordsHash Function Transmission Control Protocol Shared Secret Occupation Number Packet Header
Unable to display preview. Download preview PDF.
- Aba01.C. Abad. Ip checksum covert channels and selected hash collision. http://www.gravitino.net/~aempirei/papers/pccc.pdf, 2001.
- Cac98.C. Cachin. An information-theoretic model for steganography. In D. Aucsmith, editor, Information Hiding, 2nd International Workshop, volume 1525 of Lecture Notes in Computer Science, pages 306–318. Springer, 1998. Revised version, March 2001, available as Cryptology ePrint Archive, Report 2000/028, http://eprint.iacr.org/.CrossRefGoogle Scholar
- DJ01.r. D. Eastlake and P. Jones. Us secure hash algorithm 1 (sha1). Rfc, Network Working Group, 2001. http://www.ietf.org/rfc/rfc3174.txt.
- FAP99.M. G. K. Fabian A.P. Petitcolas, Ross J. Anderson. Information hiding-a survey. In Proceedings of the IEEE. 1999.Google Scholar
- III.J. W. G. III. Countermeasures and tradeoffs for a class of covert timing channels.Google Scholar
- McH95.J. McHugh. Covert Channel Analysis. Portland State University, 1995.Google Scholar
- MK94.I. Moskowitz and M. Kang. Covert channels-here to stay? In COMPASS’ 94, pages 235–243. 1994.Google Scholar
- MM94.I. S. Moskowitz and A. R. Miller. Simple timing channels. In IEEE Computer Society Symposium on Research in Security and Privacy, pages 56–61. IEEE Press, 1994.Google Scholar
- Row96.C. H. Rowland. Covert channels in the tcp/ip protocol suite. First Monday, http://www.firstmonday.dk/issues/issue25/rowland/, 1996.
- Sim84.G. Simmons. The prisoners’ problem and the subliminal channel. In CRYPTO’ 83, pages 51–67. Plenum Press, 1984.Google Scholar
- Sim93.G. J. Simmons. The subliminal channels in the u.s. digital signature algorithm (dsa). In W. Wolfowicz, editor, 3rd Symposium on: State and Progress of Research in Cryptography, pages 35–54. Rome, Italy, 1993.Google Scholar
- SM.e. a. Steve McCanne. libpcap, the packet capture library. http://www.tcpdump.org.
- UCD99.Uc davis denial of service (dos) project meeting notes. http://seclab. cs.ucdavis.edu/projects/denial-service/meetings/01-27-99m.html, 1999.