Countering adaptive network covert communication with dynamic wardens

Wojciech Mazurczyk , Steffen Wendzel , Mehdi Chourib , Jörg Keller


Network covert channels are hidden communication channels in computer networks. They influence several factors of the cybersecurity economy. For instance, by improving the stealthiness of botnet communications, they aid and preserve the value of darknet botnet sales. Covert channels can also be used to secretly exfiltrate confidential data out of organizations, potentially resulting in loss of market/research advantage. Considering the above, efforts are needed to develop effective countermeasures against such threats. Thus in this paper, based on the introduced novel warden taxonomy, we present and evaluate a new concept of a dynamic warden. Its main novelty lies in the modification of the warden’s behavior over time, making it difficult for the adaptive covert communication parties to infer its strategy and perform a successful hidden data exchange. Obtained experimental results indicate the effectiveness of the proposed approach.
Author Wojciech Mazurczyk (FEIT / IT)
Wojciech Mazurczyk,,
- The Institute of Telecommunications
, Steffen Wendzel - Worms University of Applied Sciences (HS-Worms) [Fachhochschule Worms]
Steffen Wendzel,,
, Mehdi Chourib - University of Hagen (fernuni-hagen) [FernUniversität in Hagen]
Mehdi Chourib,,
, Jörg Keller - University of Hagen (fernuni-hagen) [FernUniversität in Hagen]
Jörg Keller,,
Journal seriesFuture Generation Computer Systems, ISSN 0167-739X
Issue year2019
NoMay 2019
Publication size in sheets2.45
Keywords in EnglishCovert channel, Active warden, Traffic normalization, Information hiding, Network steganography, Data leakage protection
ASJC Classification1705 Computer Networks and Communications; 1708 Hardware and Architecture; 1712 Software
Languageen angielski
2019 Mazurczyk Wenzel Countering adaptive network covert communication.pdf 3.41 MB
Score (nominal)140
Score sourcejournalList
ScoreMinisterial score = 140.0, 17-06-2020, ArticleFromJournal
Publication indicators WoS Citations = 1; Scopus Citations = 1; Scopus SNIP (Source Normalised Impact per Paper): 2018 = 2.464; WoS Impact Factor: 2018 = 5.768 (2) - 2018=5.67 (5)
Citation count*8 (2020-08-07)
Share Share

Get link to the record

* presented citation count is obtained through Internet information analysis and it is close to the number calculated by the Publish or Perish system.
Are you sure?