Protocol Proxy: An FTE-based Covert Channel

Protocol Proxy: An FTE-based Covert Channel
复制标题

DOI:
10.1016/j.cose.2020.101777
复制
发表时间:
2020-02
期刊:
Comput. Secur.
影响因子:
--
通讯作者:
Jon Oakley;Lu Yu;Xingsi Zhong;G. Venayagamoorthy;R. Brooks
Jon Oakley;Lu Yu;Xingsi Zhong;G. Venayagamoorthy;R. Brooks
中科院分区:
其他
文献类型:
--
作者:
Jon Oakley;Lu Yu;Xingsi Zhong;G. Venayagamoorthy;R. Brooks

文献摘要

被引文献

相似文献

在恶意网络环境中,用户必须在不被发现的情况下进行通信。这包括融入现有的交通。在某些情况下,需要更高程度的保密。我们提出了一种基于概念验证的格式转换加密(FTE)的隐蔽通道,用于通过受保护的静态协议隧道传输TCP流量。受保护的静态协议是基于udp的协议,具有可变字段,不能在没有附带损害(例如电网故障)的情况下被阻止。我们(1)将TCP流量转换为UDP流量,(2)引入基于观测的FTE,(3)用确定性隐马尔可夫模型(HMM)建模包间时序。由此产生的协议代理具有非常低的检测概率,是当前隐蔽通道的替代方案。我们通过UDP协议建立TCP会话隧道并保证传输。基于观察的FTE确保了传统的基于规则的分析或DPI无法检测到流量。一个确定性HMM确保协议代理准确地模拟包间时间,以避免被侧信道分析检测。最后,选择受保护的静态协议会阻碍有状态协议分析,并导致误报的附带损害。
In a hostile network environment, users must communicate without being detected. This involves blending in with the existing traffic. In some cases, a higher degree of secrecy is required. We present a proof-of-concept format transforming encryption (FTE)-based covert channel for tunneling TCP traffic throughprotected staticprotocols. Protected static protocols are UDP-based protocols with variable fields that cannot be blocked without collateral damage, such as power grid failures. We (1) convert TCP traffic to UDP traffic, (2) introduce observation-based FTE, and (3) model interpacket timing with a deterministic Hidden Markov Model (HMM). The resulting Protocol Proxy has a very low probability of detection and is an alternative to current covert channels. We tunnel a TCP session through a UDP protocol and guarantee delivery. Observation-based FTE ensures traffic cannot be detected by traditional rule-based analysis or DPI. A deterministic HMM ensures the Protocol Proxy accurately models interpacket timing to avoid detection by side-channel analysis. Finally, the choice of aprotected staticprotocol foils stateful protocol analysis and causes collateral damage with false positives.