Investigating HTTP Covert Channels Through Fuzz Testing
Kai Hölk, Wojciech Mazurczyk, Marco Zuppelli, Luca Caviglione · 2024
Modern malware increasingly deploys network covert channels to prevent detection or bypass firewalls. Unfortunately, the early discovery of protocol fields and functional behaviors of traffic that can be abused to conceal information is very challenging. In this perspective, fuzz testing could help to face the tight relationship between the used hiding scheme and the targeted protocol trait. Even if fuzzing is a well-established practice to reveal implementation issues, bugs, or unhandled behaviors, it has never been considered to assess the “susceptilibility” of protocols to covert communications.