CSP-Based General Detection Model of Network Covert Storage Channels - Inria - Institut national de recherche en sciences et technologies du numérique Accéder directement au contenu
Communication Dans Un Congrès Année : 2013

CSP-Based General Detection Model of Network Covert Storage Channels

Hui Zhu
  • Fonction : Auteur
  • PersonId : 1003111
Tingting Liu
  • Fonction : Auteur
Guanghui Wei
  • Fonction : Auteur
Beishui Liu
  • Fonction : Auteur
Hui Li
  • Fonction : Auteur

Résumé

A network covert channel is a malicious conversation mechanism, which brings serious security threat to security-sensitive systems and is usually difficult to be detected. Data are hidden in the header fields of protocols in network covert storage channels. In this paper, a general detection model based on formal protocol analysis for identifying possible header fields in network protocols that may be used as covert storage channels is proposed. The protocol is modeled utilizing the Communication Sequential Processes (CSP), in which a modified property of header fields is defined and the header fields are classified into three types in accordance to the extent to which their content can be altered without impairing the communication. At last, verification of the model in Transmission Control Protocol (TCP) shows that the proposed method is effective and feasible.
Fichier principal
Vignette du fichier
978-3-642-36818-9_51_Chapter.pdf (689.9 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

hal-01480205 , version 1 (01-03-2017)

Licence

Paternité

Identifiants

Citer

Hui Zhu, Tingting Liu, Guanghui Wei, Beishui Liu, Hui Li. CSP-Based General Detection Model of Network Covert Storage Channels. 1st International Conference on Information and Communication Technology (ICT-EurAsia), Mar 2013, Yogyakarta, Indonesia. pp.459-468, ⟨10.1007/978-3-642-36818-9_51⟩. ⟨hal-01480205⟩
73 Consultations
87 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More