Skip to main navigation Skip to search Skip to main content

Detection of an Imperceptible HTTP-Based Covert Channel

Research output: Chapter in Book/Report/Conference proceedingChapterpeer-review

Abstract

Rootkits are commonly employed by attackers to gain control over compromised computers. Once deployed, these rootkits necessitate communication with the attacker to receive commands and transmit execution results. Recognizing and obstructing this communication is a crucial strategy employed by organizations to counteract rootkits. Consequently, attackers must establish a covert communication channel with the rootkit that is both reliable and impervious to detection. This paper unveils a rootkit implementation featuring an imperceptible covert channel based on HTTP. The implemented covert channel underwent comprehensive testing and evaluation using state-of-the-art intrusion detection tools. The results indicate that, despite its minimal complexity, the covert channel remains elusive to conventional intrusion detection systems. Additionally, we introduce a detection mechanism for this covert channel, addressing this security vulnerability and advocating for its seamless integration into existing security frameworks.

Original languageEnglish
Title of host publicationStudies in Big Data
PublisherSpringer Science and Business Media Deutschland GmbH
Pages523-534
Number of pages12
DOIs
StatePublished - 2026

Publication series

NameStudies in Big Data
Volume183
ISSN (Print)2197-6503
ISSN (Electronic)2197-6511

Keywords

  • Covert channel
  • Detection
  • HTTP

Fingerprint

Dive into the research topics of 'Detection of an Imperceptible HTTP-Based Covert Channel'. Together they form a unique fingerprint.

Cite this