Applying network address encryption to anonymity and preventing data exfiltration

Jonathan T. Trostle · 2008

Two existing network security problems are ensuring anonymous communications and preventing data exfiltration through network covert channels. We present a new concept in network addressing: one-time encrypted network addresses. We describe a particular instantiation: one-time CPP addresses. We then show how one-time encrypted addresses can prevent intersection and other traffic analysis attacks that can undermine low-latency anonymous communications. We show how one-time encrypted addresses can also be used, with certain assumptions, to greatly reduce network covert channels. Thus one-time encrypted network addresses, when combined with other network security countermeasures, are able to provide a back-up defense against malicious software on hosts that attempt to ldquophone homerdquo in order to leak confidential information, including location information. We describe how these techniques can be used to protect confidential data in a MANET.

Read the paper · More papers on PaperTik