Skip to Main Content (Press Enter)

Logo CNR
  • ×
  • Home
  • Persone
  • Pubblicazioni
  • Strutture
  • Competenze

UNI-FIND
Logo CNR

|

UNI-FIND

cnr.it
  • ×
  • Home
  • Persone
  • Pubblicazioni
  • Strutture
  • Competenze
  1. Pubblicazioni

Detecting Covert Channels Through Code Augmentation

Contributo in Atti di convegno
Data di Pubblicazione:
2021
Abstract:
Modern malware increasingly exploits information hiding or steganography to elude security frameworks and remain unnoticed for long periods. To this aim, a prime technique relies upon the ability of creating covert channels to bypass the limits imposed by a sandbox or to exfiltrate data towards a remote server. Unfortunately, detecting a covert channel is not a trivial task and often requires to inspect a composite set of information, e.g., the behavior of a software or statistical indicators of network traffic. Therefore, in this paper we investigate the adoption of code augmentation features offered by the Linux kernel to gather data useful to reveal the presence of covert communications. To prove the effectiveness of the approach, we tested a lightweight program to detect covert channels targeting IPv6 conversations. Results indicate that technologies like the extended Berkeley Packet Filter can offer a foundation to frameworks for spotting and mitigating covert communications.
Tipologia CRIS:
04.01 Contributo in Atti di convegno
Keywords:
covert channels; code augmentation; cybersecurity; information hiding; security; networking
Elenco autori:
Zuppelli, Marco; Caviglione, Luca; Repetto, Matteo
Autori di Ateneo:
CAVIGLIONE LUCA
REPETTO MATTEO
ZUPPELLI MARCO
Link alla scheda completa:
https://iris.cnr.it/handle/20.500.14243/397206
Titolo del libro:
Proceedings of the Italian Conference on Cybersecurity (ITASEC 2021)
Pubblicato in:
CEUR WORKSHOP PROCEEDINGS
Series
  • Utilizzo dei cookie

Realizzato con VIVO | Designed by Cineca | 26.5.0.0 | Sorgente dati: PREPROD (Ribaltamento disabilitato)