New Approach towards Covert Communication using TCP-SQN Reference Model

##plugins.themes.academic_pro.article.main##

Dhananjay M. Dakhane
Dr. Prashant R. Deshmukh

Abstract

Covert channel stands for transfer of unintended information. It allows the attacker to send as well as receive the secrete message without being identified or detected by the Network administrator or the warden in the network. There are several ways to implement such covert channels; one of them is storage covert channel where data is sent through certain header field of TCP, IP protocol stack. However there is always some possibility of these covert channels being identified. Here, we propose a new covert channel technique, ‘TCP-SQN Reference Model'. In this technique a new covert channel is created in Linux kernel, using TCP Sequence Number as a reference for sending the covert information. The idea of our proposed model is, sender is not actually embedding the secrete message into the TCP-SQN filed; instead the sender uses it as a reference, to convey the secret message to the receiver. As sender is not actually modifying the TCP-SQN filed, the sequence number is observed as a normal packet distribution, which is created by any Linux or BSD Kernel. So it is difficult to distinguish overt and covert packet in the network.

##plugins.themes.academic_pro.article.details##