Publication: Covert channel limitation via special dummy traffic generating
Дата
2023
Авторы
Epishkina, A.
Karapetyants, N.
Kogos, K.
Lebedev, P.
Journal Title
Journal ISSN
Volume Title
Издатель
Аннотация
© 2022, The Author(s), under exclusive licence to Springer-Verlag France SAS, part of Springer Nature.Covert channels in information systems may cause a protected data leakage and lead to violation of data confidentiality or integrity. Moreover, some types of covert channels can function even in case of network data encryption, tunneling or traffic firewall protection. A technique to eliminate such channels is traffic normalization which means sending packets with equal lengths and fixed header fields with equal inter-packets delays that leads to significant decreasing of efficient communication channels capacity and missing of functional capabilities of network protocols. Another way to counteract covert channel is to detect an active channel and limit it capacity. In this paper, we investigate covert channel protection means in packet networks based on their capacity limitation. We suggest a technique to counteract data leakage via covert channel based on dummy traffic generating and estimate maximum residual capacity of covert channel in case of counteracting measures for stream and block encryption of traffic and different distributions for covert channel and dummy traffic. Also we give recommendation for choosing the parameters of counteraction tool.
Описание
Ключевые слова
Цитирование
Covert channel limitation via special dummy traffic generating / Epishkina, A. [et al.] // Journal of Computer Virology and Hacking Techniques. - 2023. - 10.1007/s11416-022-00428-z
URI
https://www.doi.org/10.1007/s11416-022-00428-z
https://www.scopus.com/record/display.uri?eid=2-s2.0-85130174225&origin=resultslist
http://gateway.webofknowledge.com/gateway/Gateway.cgi?GWVersion=2&SrcAuth=Alerting&SrcApp=Alerting&DestApp=WOS_CPL&DestLinkType=FullRecord&UT=WOS:000799436900001
https://openrepository.mephi.ru/handle/123456789/29840
https://www.scopus.com/record/display.uri?eid=2-s2.0-85130174225&origin=resultslist
http://gateway.webofknowledge.com/gateway/Gateway.cgi?GWVersion=2&SrcAuth=Alerting&SrcApp=Alerting&DestApp=WOS_CPL&DestLinkType=FullRecord&UT=WOS:000799436900001
https://openrepository.mephi.ru/handle/123456789/29840