SANS InfoSec Reading Room - Covert Channels
Most of the computer security white papers in the Reading Room have been written by students seeking GIAC certification to fulfill part of their certification requirements and are provided by SANS as a resource to benefit the security community at large. SANS attempts to ensure the accuracy of information, but papers are published "as is". Errors or inconsistencies may exist or may be introduced over time as material becomes dated. If you suspect a serious error, please contact
webmaster@sans.org.
Featuring 8 papers as of Feb 10, 2010
Covert Data Storage Channel Using IP Packet Headers
- By: Jonathan Thyer (posted on February 7, 2008)
-
A covert data channel is a communications channel that is hidden within the medium of a legitimate communications channel. Covert channels manipulate a communications medium in an unexpected or unconventional way in order to transmit information in an almost undetectable fashion. Otherwise said, a covert data channel transfers arbitrary bytes between two points in a fashion that would appear legitimate to someone scrutinizing the exchange. (Bingham, 2006)
Covert communications: subverting Windows applications
- By: D. Climenti, A. Fontes, A. Menghrajani (posted on September 14, 2007)
-
Inside-Out Vulnerabilities, Reverse Shells
- By: Richard Hammer (posted on November 10, 2006)
-
Keeping data from leaking out of protected networks is becoming increasingly difficult due to the increase of malicious code that sends data from infected systems.
Network Covert Channels: Subversive Secrecy
- By: Ray Sbrusch (posted on October 25, 2006)
-
Steganography is the practice of concealing information in channels that superficially appear benign. The National Institute of Standards and Technology defines a covert channel as any communication channel that can be exploited
Steganography: Why it Matters in a "Post 911" World
- By: Bob Gilbert (posted on October 31, 2003)
-
This paper discusses cryptography attempts that to conceal messages by various translation methods that create new, unrecognizable messages.
A Detailed look at Steganographic Techniques and their use in an Open-Systems Environment
- By: Bret Dunbar (posted on October 31, 2003)
-
This paper's focus is on a relatively new field of study in Information Technology known as Steganography.
A Discussion of Covert Channels and Steganography
- By: Mark Owens (posted on October 31, 2003)
-
Although the current threat of steganographic technology appears to lag its usefulness, the diligent information systems person needs to be mindful of the security ramifications that a covert channel in their enterprise carries.
HTTP Tunnels Though Proxies
- By: Daniel Alman (posted on October 31, 2003)
-
This paper covers the topic of HTTP tunnels, the risks they pose, and discusses how those risks can be limited with proper administration.
It offers a strategic & practical approach to auditing which is not only informative, but inspiring... truly enabling.
-Steve Yuhas, TESSCO Technologies