Asynchronous Covert Communication Using BitTorrent Trackers

Mathieu Cunche 1, * Mohamed Ali Kaafar 1 Roksana Boreli 2, 3
* Corresponding author
1 PRIVATICS - Privacy Models, Architectures and Tools for the Information Society
Inria Grenoble - Rhône-Alpes, CITI - CITI Centre of Innovation in Telecommunications and Integration of services
Abstract : Covert channels enable communicating parties to exchange messages without being detected by an external observer. In this paper we propose a novel covert channel mechanism based on BitTorrent trackers. The proposed mechanism uses common HTTP commands, thus having the appearance of genuine web traffic and consists of communications that are both indirect and asynchronous: no messages are directly exchanged between the sender and the receiver (of covert communications) and there is a potentially considerable delay between the sender's message to the relaying party and the receiver collecting this message. We present details of the proposed scheme in which a centralized BitTorrent tracker is used for storing covert messages and evaluate its performance based on the implemented prototype. We analyze the detectability of covert communications by an adversary and show that, while the common nature of the BitTorrent traffic and the large number of clients make the detection unlikely, the low temporal correlation between the writer and the reader (the two communicating parties) further increases the detection difficulty. Finally we discuss a variant of our scheme that uses a decentralized tracker (based on distributed hash tables), increasing the scalability and enabling a larger number of parallel covert communication channels.
Document type :
Reports
Liste complète des métadonnées

Cited literature [13 references]  Display  Hide  Download

https://hal.inria.fr/hal-01011739
Contributor : Mathieu Cunche <>
Submitted on : Friday, June 27, 2014 - 11:25:10 AM
Last modification on : Saturday, October 27, 2018 - 1:19:56 AM
Document(s) archivé(s) le : Saturday, September 27, 2014 - 10:40:36 AM

File

RR-8554.pdf
Files produced by the author(s)

Identifiers

  • HAL Id : hal-01011739, version 1

Citation

Mathieu Cunche, Mohamed Ali Kaafar, Roksana Boreli. Asynchronous Covert Communication Using BitTorrent Trackers. [Research Report] RR-8554, INRIA. 2014. ⟨hal-01011739⟩

Share

Metrics

Record views

357

Files downloads

316