• English
  • Deutsch
  • Log In
    Password Login
    Research Outputs
    Fundings & Projects
    Researchers
    Institutes
    Statistics
Repository logo
Fraunhofer-Gesellschaft
  1. Home
  2. Fraunhofer-Gesellschaft
  3. Konferenzschrift
  4. Detection of covert channels in TCP retransmissions
 
  • Details
  • Full
Options
2018
Conference Paper
Title

Detection of covert channels in TCP retransmissions

Abstract
In this paper we describe the implementation and detection of a network covert channel based on TCP retransmissions. For the detection, we implemented and evaluated two statistical detection measures that were originally designed for inter-arrival time-based covert channels, namely the e-similarity and the compressibility. The e-similarity originally measures the similarity of two timing distributions. The compressibility indicates the presence of a covert channel by measuring the compression ratio of a textual representation of concatenated inter-arrival times. We modified both approaches so that they can be applied to the detection of retransmission-based covert channels, i.e. we performed a so-called countermeasure variation. Our initial results indicate that the e-similarity can be considered a promising detection method for retransmission-based covert channels while the compressibility itself provides insufficient results but could potentially be used as a classification feature.
Author(s)
Zillien, Sebastian
Wendzel, Steffen
Mainwork
Secure IT systems. 23rd Nordic conference, NordSec 2018. Proceedings  
Conference
Nordic Conference on Secure IT Systems (NordSec) 2018  
DOI
10.1007/978-3-030-03638-6_13
Language
English
Fraunhofer-Institut für Kommunikation, Informationsverarbeitung und Ergonomie FKIE  
  • Cookie settings
  • Imprint
  • Privacy policy
  • Api
  • Contact
© 2024