Skip to Main Content (Press Enter)

Logo CNR
  • ×
  • Home
  • Persone
  • Pubblicazioni
  • Strutture
  • Competenze

UNI-FIND
Logo CNR

|

UNI-FIND

cnr.it
  • ×
  • Home
  • Persone
  • Pubblicazioni
  • Strutture
  • Competenze
  1. Pubblicazioni

pcapStego: A Tool for Generating Traffic Traces for Experimenting with Network Covert Channels

Contributo in Atti di convegno
Data di Pubblicazione:
2021
Abstract:
The increasing diffusion of malware endowed with steganographic and cloaking capabilities requires tools and techniques for conducting research activities, testing real deployments and elaborating mitigation mechanisms. To investigate attacks targeting network and appliances, a core requirement concerns the availability of suitable traffic traces, which can be used to derive mathematical models for simulation or to develop machine-learning-based countermeasures. Unfortunately, the young nature of threats injecting secrets or cloaking their presence within network traffic, the high protocol- dependent nature of the various embedding processes, and privacy issues, prevent the vast diffusion of datasets to perform research. Therefore, in this paper we present pcapStego, a tool for creating network covert channels within .pcap files. This approach has two major advantages: it allows to prepare large datasets starting from real network traces, and it generates "replayable" conversations useful for both emulating attacks or conduct pentesting campaigns. To prove the effectiveness of the tool, we showcase the generation of network covert channels targeting IPv6 traffic, which is gaining momentum and it is expected to be a major target for future attacks.
Tipologia CRIS:
04.01 Contributo in Atti di convegno
Keywords:
covert channels; information hiding; cybersecurity; traffic generation
Elenco autori:
Zuppelli, Marco; Caviglione, Luca
Autori di Ateneo:
CAVIGLIONE LUCA
ZUPPELLI MARCO
Link alla scheda completa:
https://iris.cnr.it/handle/20.500.14243/396902
  • Dati Generali

Dati Generali

URL

https://dl.acm.org/doi/abs/10.1145/3465481.3470067
  • Utilizzo dei cookie

Realizzato con VIVO | Designed by Cineca | 26.5.0.0 | Sorgente dati: PREPROD (Ribaltamento disabilitato)