TCP/IP protocol basically have much vulnerability in protocol itself. Specially, ICMP is ubiquitous to almost every TCP/IP based network. Thereupon, many networks consider ICMP traffic to be benign and will allow it to be passed through, unmolested. So, attackers can tunnel (covert channel) any information they want through it. To detect an ICMP cover channel, we use SVM which has excellent performance in pattern classification. Our experimnta show that the proposed method can detect an ICMP covert channel among normal ICMP traffic using SCM.
展开▼