论文标题

反见(您看到了吗?):一个放大的秘密通道,指向先前看到的数据

DYST (Did You See That?): An Amplified Covert Channel That Points To Previously Seen Data

论文作者

Wendzel, Steffen, Schmidbauer, Tobias, Zillien, Sebastian, Keller, Jörg

论文摘要

秘密渠道是隐形沟通渠道,可实现流动对手和合法场景,从恶意软件沟通到记者和审查制度的机密信息交换。我们介绍了一个新的秘密渠道,我们称之为历史记录秘密频道。我们进一步提出了一个新的范式:秘密通道放大。到目前为止,所有秘密频道都需要制作看似合理的流动,或者需要修改第三方流动,从而模仿不可思议的行为。相比之下,历史记录秘密渠道可以通过指出常规网络节点创建的未改变的合法流量来通信。只有秘密通信过程的一小部分需要秘密频道的发送者传输秘密信息。可以通过不同的协议/渠道发送此信息。我们的方法允许放大秘密频道的消息大小,即,将秘密频道的发送者与所交换的整体秘密数据相关的实际传输秘密数据的比例最小化。此外,我们扩展了当前的秘密渠道分类法,以显示如何对历史频道进行分类。我们描述了可以实现历史记录秘密通道,分析这些频道的特征的多种情况,并显示如何优化它们的配置。

Covert channels are stealthy communication channels that enable manifold adversary and legitimate scenarios, ranging from malware communications to the exchange of confidential information by journalists and censorship circumvention. We introduce a new class of covert channels that we call history covert channels. We further present a new paradigm: covert channel amplification. All covert channels described until now need to craft seemingly legitimate flows or need to modify third-party flows, mimicking unsuspicious behavior. In contrast, history covert channels can communicate by pointing to unaltered legitimate traffic created by regular network nodes. Only a negligible fraction of the covert communication process requires the transfer of covert information by the covert channel's sender. This information can be sent through different protocols/channels. Our approach allows an amplification of the covert channel's message size, i.e., minimizing the fraction of actually transferred secret data by a covert channel's sender in relation to the overall secret data being exchanged. Further, we extend the current taxonomy for covert channels to show how history channels can be categorized. We describe multiple scenarios in which history covert channels can be realized, analyze the characteristics of these channels, and show how their configuration can be optimized.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源