Bandwidth and detection of packet length covert channels
Dye, Derek J.
Dinolt, George W.
Michael, James Bret
MetadataShow full item record
This thesis explores the detectability and robustness of packet length covert channels. We discovered that packet length covert channels, where a rogue user modulates the length of a Transport Control Protocol packet, can be detected while monitoring traffic of a large network. The bandwidth of these channels can be successfully estimated as well as the channels themselves detected using statistical inference. In addition, we observed that there is an inverse relationship between the volitionality in networks with respect to packet lengths and the detectability of these channels, and between packet length and channel bandwidth. For a large network like a college department, the bandwidth of a covert channel could be in the tens of megabytes over the course of a day.
Approved for public release; distribution is unlimited.
Showing items related by title, author, creator and subject.
Adaptive node capability metric to assess the value of networking in a general command and control wireless communication topology Magalhães, Marcelo Vellozo (Monterey, California. Naval Postgraduate School, 2011-09);In order to quantify any node's capacity to support optimal information flow within a distributed command and control network, a novel node capability value calculation is developed from first principles. The expression ...
Gaver, Donald Paul; Fayolle, Guy; Weiss, Alan (Monterey, California. Naval Postgraduate School, 1985-08); NPS55-85-018In many situations involving data transmission from diverse sources there can be conflict for a limited number of channels or other facilities. Uncoordinated attempts by several sources to use a single facility can result ...
Effects of non-uniform windowing in a Rician-fading channel and simulation of adaptive automatic repeat request protocols Kmiecik, Chris G. (Monterey, California: Naval Postgraduate School, 1990-06);Two aspects of digital communication were investigated. In the first part, a FFT-based, M-ary FSK receiver in a Rician-fading channel was analyzed to determine the benefits of non-uniform windowing of sampled received data. ...