A covert data transport protocol

A covert data transport protocol
复制标题

隐蔽数据传输协议

DOI:
--
复制
发表时间:
2016
期刊:
International Conference on Malicious and Unwanted Software
影响因子:
--
通讯作者:
R. Brooks
R. Brooks
中科院分区:
--
文献类型:
--
作者:
Yu Fu;Zhe Jia;Lu Yu;Xingsi Zhong;R. Brooks

文献摘要

被引文献

相似文献

企业和国家防火墙都过滤网络连接。对于数据取证和僵尸网络清除应用程序,重要的是建立信息源。在本文中,我们描述了一个数据传输层,它允许客户端传输加密的数据,提供有关数据源没有可辨别的信息。我们使用域生成算法(DGA)将AES加密数据编码为当前工具无法可靠区分的域名。域名使用(免费)动态DNS服务注册。数据传输格式不易受到深度数据包检测(DPI)的攻击。
Both enterprise and national firewalls filter network connections. For data forensics and botnet removal applications, it is important to establish the information source. In this paper, we describe a data transport layer which allows a client to transfer encrypted data that provides no discernible information regarding the data source. We use a domain generation algorithm (DGA) to encode AES encrypted data into domain names that current tools are unable to reliably differentiate from valid domain names. The domain names are registered using (free) dynamic DNS services. The data transmission format is not vulnerable to Deep Packet Inspection (DPI).