Skip to Main Content (Press Enter)

Logo CNR
  • ×
  • Home
  • Persone
  • Pubblicazioni
  • Strutture
  • Competenze

UNI-FIND
Logo CNR

|

UNI-FIND

cnr.it
  • ×
  • Home
  • Persone
  • Pubblicazioni
  • Strutture
  • Competenze
  1. Pubblicazioni

Code Augmentation for Detecting Covert Channels Targeting the IPv6 Flow Label

Contributo in Atti di convegno
Data di Pubblicazione:
2021
Abstract:
Information hiding is at the basis of a new-wave of malware able to elude common detection mechanisms or remain unnoticed for long periods. To this aim, a key approach exploits network covert channels, i.e., abusive communication paths nested within a legitimate traffic flow. The increasing diffusion of IPv6 makes it attractive for an attacker, especially for the presence of the Flow Label field, which can be manipulated to contain up to 20 secret bits per packet. Unfortunately, gathering data to implement a standalone detection mechanism or to support third-party security tools is a poorly generalizable process and often leads to scalability issues. This paper showcases how to take advantage of code augmentation features (i.e., the extended Berkeley Packet Filter) to detect covert channels targeting the IPv6 Flow Label. To prove its effectiveness, the proposed approach has been tested against Internet-wide traffic traces collected in the wild. Results indicate that it is possible to spot the channel while mitigating the memory footprint and the computational burden (e.g., the processed traffic is further delayed of only few nanoseconds).
Tipologia CRIS:
04.01 Contributo in Atti di convegno
Keywords:
security; information hiding; covert channels; code augmentation; network security
Elenco autori:
Zuppelli, Marco; Caviglione, Luca; Repetto, Matteo
Autori di Ateneo:
CAVIGLIONE LUCA
REPETTO MATTEO
ZUPPELLI MARCO
Link alla scheda completa:
https://iris.cnr.it/handle/20.500.14243/396234
Titolo del libro:
2021 IEEE 7th International Conference on Network Softwarization (NetSoft)
  • Dati Generali

Dati Generali

URL

https://ieeexplore.ieee.org/abstract/document/9492661/
  • Utilizzo dei cookie

Realizzato con VIVO | Designed by Cineca | 26.5.0.0 | Sorgente dati: PREPROD (Ribaltamento disabilitato)