On the design of network-based covert communication systems
Ronald W. Smith · 2007
Designing a system to effectively exploit a covert channel is in many ways similar to designing a general-purpose communication system. Through study of the physical and statistical nature of a communication channel an appropriate encoder/decoder pair is designed to maximize channel capacity (usage) while minimizing the probability of receiver error. An additional criterion for the design of a covert system is the requirement to remain undetectable. This thesis presents a predictable and quantifiable approach to designing a covert communication system capable of effectively exploiting covert channels found in the various layers of network protocols. Three system metrics are developed that characterize the overall system. A measure of probability of detection is derived using statistical inference techniques. A system efficiency measure is developed based upon the noiseless capacity of the covert channel. A measure of reliability is developed as the bit error rate of the combined noisy channel and an appropriate error-correcting code. A family of error-correcting codes are developed that handle the high symbol insertion rates found in these covert channels. A system design methodology is presented that involves three distinct steps: selection and characterization of the network exploit, characterization of the resultant channel, and selection of an appropriate coding scheme. The system metrics of prob ability of detection, efficiency, and reliability are each shown to be a function of the covert channel signal-to-noise ratio, and as such the three can be combined to form a constraint triangle permitting system level design trade-offs. Validation of the system methodology is provided by means of an experiment using real network traffic data. Keywords: network-based covert channels, probability of detection, symbol insertion errors, error-correcting codes