Investigating HTTP Covert Channels Through Fuzz Testing

Kai Hölk, Wojciech Mazurczyk, Marco Zuppelli, Luca Caviglione · 2024

Modern malware increasingly deploys network covert channels to prevent detection or bypass firewalls. Unfortunately, the early discovery of protocol fields and functional behaviors of traffic that can be abused to conceal information is very challenging. In this perspective, fuzz testing could help to face the tight relationship between the used hiding scheme and the targeted protocol trait. Even if fuzzing is a well-established practice to reveal implementation issues, bugs, or unhandled behaviors, it has never been considered to assess the “susceptilibility” of protocols to covert communications.

Read the paper · More papers on PaperTik