首页> 外文会议>International conference on risks and security of internet and systems >An Approach for Thwarting Malicious Secret Channel: The Case of IP Record Route Option Header-Based Covert Channels
【24h】

An Approach for Thwarting Malicious Secret Channel: The Case of IP Record Route Option Header-Based Covert Channels

机译:阻止恶意秘密通道的一种方法:基于IP记录路由选项标头的隐蔽通道

获取原文

摘要

The Internet constitutes actually one of the main communication platforms for cybercriminals and terrorists to exchange secret messages and hidden information. The use of clear or non-encrypted network traffic to communicate over the Internet allows steganalysis process and surveillance agencies to easily identify the presence of secret messages and hidden information, and classify the involved entities as potential cyber criminals or terrorists. However, covert channels can be an efficient and remedial communication solution for cybercriminals and terrorists to exchanged secret messages and hidden information. In fact, most covert channels attempt to send clear and non- encrypted messages embedded in the fields of network packets in order to offer robust communication channels against steganalysis. Nevertheless, covert channels are an immense cause of security concern and are classified as a serious threat because they can be used to pass malicious messages. This explains why detection and elimination of covert channels are considered a big issue that faces security systems and needs to be addressed. In this paper, a novel approach for detecting a particular type of covert channels is discussed. The covert channel uses the IP Record route option header in network IP packets to send secret messages and hidden information. The paper demonstrates that this type of covert channels is not robust enough against steganalysis. The proposed detection approach is based on the IP Loose source route option header. Conducted experiments show that the proposed approach is simple and straightforward to implement and can contribute to identifying malicious online activities of cyber criminals and terrorists.
机译:互联网实际上是网络罪犯和恐怖分子交换秘密信息和隐藏信息的主要通信平台之一。使用清晰或未加密的网络流量在Internet上进行通信,隐匿分析过程和监视机构可以轻松识别秘密消息和隐藏信息的存在,并将所涉及的实体归类为潜在的网络罪犯或恐怖分子。但是,隐蔽渠道可以成为网络犯罪分子和恐怖分子交换秘密信息和隐藏信息的有效和补救性通信解决方案。实际上,大多数隐蔽通道试图发送嵌入在网络数据包字段中的明文和非加密消息,以便提供强大的通信通道来进行隐写分析。但是,隐蔽通道是引起安全问题的巨大原因,并被归类为严重威胁,因为它们可用于传递恶意消息。这解释了为什么检测和消除秘密通道被认为是安全系统面临的一个大问题,需要加以解决。在本文中,讨论了一种用于检测特定类型的隐蔽通道的新颖方法。隐蔽通道使用网络IP数据包中的IP记录路由选项标头发送秘密消息和隐藏信息。本文表明,这种类型的隐蔽通道不足以抵抗隐写分析。提议的检测方法基于IP松散源路由选项标头。进行的实验表明,该方法简单易行,可以帮助识别网络罪犯和恐怖分子的恶意在线活动。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号