تخطي إلى التنقل الرئيسي تخطي إلى البحث تخطي إلى المحتوى الرئيسي

Revealing Kernel Mode Covert Channels Using Virtualization

نتاج البحث: فصل من :كتاب / تقرير / مؤتمرفصلمراجعة النظراء

ملخص

In modern cyber-attacks, after breaching the victim’s infrastructure, the attacker must establish communication with the malware installed at the victim’s premises. The attackers try to hide their communication using covert channel techniques to avoid being revealed by intrusion detection systems. Packet reordering and timing control are popular techniques for constructing covert channels, that can be applied to any protocol that employs the notion of a sequence number, e.g., TCP, RTP, SCTP, etc. Unlike modifying the packet timing or order in a particular stream, we would like to introduce and investigate the reordering of packets over multiple distinguished streams. Using multiple streams to decode information makes it harder for detection tools to identify since the impact over each stream is minimal and the covert channel is achieved by the combination of the two streams. The presented covert channel technique is protocol agnostic and can be easily implemented using kernel mode or User mode applications. Nevertheless, we introduce a technique to detect such covert channels under strict restrictions of the detection tool which makes it feasible to implement and integrate to existing systems.

اللغة الأصليةالإنجليزيّة
عنوان منشور المضيفStudies in Big Data
ناشرSpringer Science and Business Media Deutschland GmbH
الصفحات503-521
عدد الصفحات19
المعرِّفات الرقمية للأشياء
حالة النشرنُشِر - 2026

سلسلة المنشورات

الاسمStudies in Big Data
مستوى الصوت183
رقم المعيار الدولي للدوريات (المطبوع)2197-6503
رقم المعيار الدولي للدوريات (الإلكتروني)2197-6511

بصمة

أدرس بدقة موضوعات البحث “Revealing Kernel Mode Covert Channels Using Virtualization'. فهما يشكلان معًا بصمة فريدة.

قم بذكر هذا