APCC: Enabling Reliable IPv6 Covert Communication with Aliased Prefixes
Zhaoan Wang, Lin He, Daguo Cheng, Ying Liu · 2025
Covert communication ensures undetectable information exchange between parties while posing risks when exploited for malicious purposes. Existing network covert channels face challenges in reliability, throughput, and stealthiness due to packet loss, limited capacity, and detectable anomalies. This paper proposes APCC, a reliable covert communication system that leverages IPv6 aliased prefixes for the first time, where secret data is embedded in the Interface Identifier field of IPv6 addresses. APCC enhances stealthiness through encryption and camouflage strategies (e.g., traffic blending and rate control). Additionally, it employs a reliable transmission mechanism incorporating sequence numbering, acknowledgment, and retransmission to mitigate packet loss and reordering. It ensures deployment flexibility across ICMPv6, UDP, or TCP protocols. Evaluations in real-world and simulated environments demonstrate that APCC achieves 100% accuracy under high latency ($\mathbf{8 0 0 ~ m s ~ R T T}$) and packet loss (10%), with throughput up to 34.7 Kbps. Detection tests show APCC evades major intrusion detection systems (Snort, Zeek) except for Suricata's TCP alerts. We also propose mitigation measures to reduce APCC's potential negative impact. This work highlights critical vulnerabilities in IPv6 infrastructure while advancing robust covert communication methodologies for high-stakes scenarios.