Skip to Main Content (Press Enter)

Logo CNR
  • ×
  • Home
  • People
  • Outputs
  • Organizations
  • Expertise & Skills

UNI-FIND
Logo CNR

|

UNI-FIND

cnr.it
  • ×
  • Home
  • People
  • Outputs
  • Organizations
  • Expertise & Skills
  1. Outputs

pcapStego: A Tool for Generating Traffic Traces for Experimenting with Network Covert Channels

Conference Paper
Publication Date:
2021
abstract:
The increasing diffusion of malware endowed with steganographic and cloaking capabilities requires tools and techniques for conducting research activities, testing real deployments and elaborating mitigation mechanisms. To investigate attacks targeting network and appliances, a core requirement concerns the availability of suitable traffic traces, which can be used to derive mathematical models for simulation or to develop machine-learning-based countermeasures. Unfortunately, the young nature of threats injecting secrets or cloaking their presence within network traffic, the high protocol- dependent nature of the various embedding processes, and privacy issues, prevent the vast diffusion of datasets to perform research. Therefore, in this paper we present pcapStego, a tool for creating network covert channels within .pcap files. This approach has two major advantages: it allows to prepare large datasets starting from real network traces, and it generates "replayable" conversations useful for both emulating attacks or conduct pentesting campaigns. To prove the effectiveness of the tool, we showcase the generation of network covert channels targeting IPv6 traffic, which is gaining momentum and it is expected to be a major target for future attacks.
Iris type:
04.01 Contributo in Atti di convegno
Keywords:
covert channels; information hiding; cybersecurity; traffic generation
List of contributors:
Zuppelli, Marco; Caviglione, Luca
Authors of the University:
CAVIGLIONE LUCA
ZUPPELLI MARCO
Handle:
https://iris.cnr.it/handle/20.500.14243/396902
  • Overview

Overview

URL

https://dl.acm.org/doi/abs/10.1145/3465481.3470067
  • Use of cookies

Powered by VIVO | Designed by Cineca | 26.5.0.0 | Sorgente dati: PREPROD (Ribaltamento disabilitato)