Skip to Main Content (Press Enter)

Logo CNR
  • ×
  • Home
  • Persone
  • Pubblicazioni
  • Strutture
  • Competenze

UNI-FIND
Logo CNR

|

UNI-FIND

cnr.it
  • ×
  • Home
  • Persone
  • Pubblicazioni
  • Strutture
  • Competenze
  1. Pubblicazioni

Code Layering for the Detection of Network Covert Channels in Agentless Systems

Articolo
Data di Pubblicazione:
2022
Abstract:
The growing interest in agentless and serverless environments for the implementation of virtual/container network functions makes monitoring and inspection of network services challenging tasks. A major requirement concerns the agility of deploying security agents at runtime, especially to effectively address emerging and advanced attack patterns. This work investigates a framework leveraging the extended Berkeley Packet Filter to create ad-hoc security layers in virtualized architectures without the need of embedding additional agents. To prove the effectiveness of the approach, we focus on the detection of network covert channels, i.e., hidden/parasitic network conversations difficult to spot with legacy mechanisms. Experimental results demonstrate that different types of covert channels can be revealed with a good accuracy while using limited resources compared to existing cybersecurity tools (i.e., Zeek and libpcap).
Tipologia CRIS:
01.01 Articolo in rivista
Keywords:
information hiding; covert channels; cybersecurity; code layering; eBPF
Elenco autori:
Zuppelli, Marco; Caviglione, Luca; Repetto, Matteo
Autori di Ateneo:
CAVIGLIONE LUCA
REPETTO MATTEO
ZUPPELLI MARCO
Link alla scheda completa:
https://iris.cnr.it/handle/20.500.14243/440256
Pubblicato in:
IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT
Journal
  • Utilizzo dei cookie

Realizzato con VIVO | Designed by Cineca | 26.5.1.0 | Sorgente dati: PREPROD (Ribaltamento disabilitato)