Difference between revisions of "Hidden channels"

From ForensicsWiki
Jump to: navigation, search
(New page: {{expand}} '''Hidden channels''' (covert channels) are communication channels that transmit information without the authorization or knowledge of the channel's designer, owner, or operato...)
 
m
 
(3 intermediate revisions by the same user not shown)
Line 1: Line 1:
{{expand}}
 
 
 
'''Hidden channels''' (covert channels) are communication channels that transmit information without the authorization or knowledge of the channel's designer, owner, or operator.
 
'''Hidden channels''' (covert channels) are communication channels that transmit information without the authorization or knowledge of the channel's designer, owner, or operator.
  
Line 13: Line 11:
  
 
* IP ID;
 
* IP ID;
* TCP SEQ/ACK numbers;
+
* TCP ISN;
 
* TCP options;
 
* TCP options;
 +
* DNS ID;
 +
* HTTP cookie;
 
* etc.
 
* etc.
 +
 +
== Detection of hidden channels ==
 +
 +
Generally, it is impossible to detect well-designed hidden channels by means of traffic analysis. For example, information hidden within TLS ''Client/Server Hello'' random bytes in encrypted form cannot be distinguished from bytes produced by secure random number generator.
 +
 +
However, it is possible to detect hidden channels by detecting attendant events, such as successful intrusion attempts. Some hidden channels produce network anomalies, for example, hidden channels using DNS ID to hide information may produce large number of DNS queries without further communication between hosts.
  
 
== External Links ==
 
== External Links ==
  
* [http://www.firstmonday.org/issues/issue2_5/rowland/ Covert Channels in the TCP/IP Protocol Suite]
+
* [http://en.wikipedia.org/wiki/Covert_channel Wikipedia: Covert channel]
 +
* [http://gray-world.net/ Unusual firewall bypassing techniques, network and computer security]
 +
* [http://www.sans.org/reading_room/whitepapers/covert/ SANS InfoSec Reading Room - Covert Channels]
  
 
[[Category:Network Forensics]]
 
[[Category:Network Forensics]]
 
[[Category:Steganography]]
 
[[Category:Steganography]]

Latest revision as of 10:42, 17 February 2009

Hidden channels (covert channels) are communication channels that transmit information without the authorization or knowledge of the channel's designer, owner, or operator.

Common Uses

  • Bypassing network filters;
  • Bypassing network sniffers.

Techniques

Information can be hidden within:

  • IP ID;
  • TCP ISN;
  • TCP options;
  • DNS ID;
  • HTTP cookie;
  • etc.

Detection of hidden channels

Generally, it is impossible to detect well-designed hidden channels by means of traffic analysis. For example, information hidden within TLS Client/Server Hello random bytes in encrypted form cannot be distinguished from bytes produced by secure random number generator.

However, it is possible to detect hidden channels by detecting attendant events, such as successful intrusion attempts. Some hidden channels produce network anomalies, for example, hidden channels using DNS ID to hide information may produce large number of DNS queries without further communication between hosts.

External Links