TY - GEN
T1 - Design, implementation and evaluation of covert channel attacks
AU - Okhravi, Hamed
AU - Bak, Stanley
AU - King, Samuel T.
PY - 2010
Y1 - 2010
N2 - Covert channel attacks pose a threat to the security of critical infrastructure and key resources (CIKR). To design defenses and countermeasures against this threat, we must understand all classes of covert channel attacks along with their properties. Network-based covert channels have been studied in great detail in previous work, although several other classes of covert channels (hardware-based and operating system-based) are largely unexplored. One of our contributions is investigating these classes by designing, implementing, and experimentally evaluating several specific covert channel attacks. We implement and evaluate hardware-based and operating system-based attacks and show significant differences in their properties and mechanisms. We also present channel capacity differences among the various attacks, which span three orders of magnitude. Furthermore, we present the concept of hybrid covert channel attacks which use two or more communication categories to transport data. Hybrid covert channels can be qualitatively harder to detect and counter than traditional covert channels. Finally, we summarize the lessons learned through covert channel attack design and implementation, which have important implications for critical asset protection and risk analysis. The study also facilitates the development of countermeasures to protect CIKR systems against covert channel attacks.
AB - Covert channel attacks pose a threat to the security of critical infrastructure and key resources (CIKR). To design defenses and countermeasures against this threat, we must understand all classes of covert channel attacks along with their properties. Network-based covert channels have been studied in great detail in previous work, although several other classes of covert channels (hardware-based and operating system-based) are largely unexplored. One of our contributions is investigating these classes by designing, implementing, and experimentally evaluating several specific covert channel attacks. We implement and evaluate hardware-based and operating system-based attacks and show significant differences in their properties and mechanisms. We also present channel capacity differences among the various attacks, which span three orders of magnitude. Furthermore, we present the concept of hybrid covert channel attacks which use two or more communication categories to transport data. Hybrid covert channels can be qualitatively harder to detect and counter than traditional covert channels. Finally, we summarize the lessons learned through covert channel attack design and implementation, which have important implications for critical asset protection and risk analysis. The study also facilitates the development of countermeasures to protect CIKR systems against covert channel attacks.
UR - https://www.scopus.com/pages/publications/78651485846
U2 - 10.1109/THS.2010.5654967
DO - 10.1109/THS.2010.5654967
M3 - Conference contribution
AN - SCOPUS:78651485846
SN - 9781424460472
T3 - 2010 IEEE International Conference on Technologies for Homeland Security, HST 2010
SP - 481
EP - 487
BT - 2010 IEEE International Conference on Technologies for Homeland Security, HST 2010
T2 - 2010 10th IEEE International Conference on Technologies for Homeland Security, HST 2010
Y2 - 8 November 2010 through 10 November 2010
ER -