Detecting covert data channels?



It is reasonably trivial to encode data within packet headers, and
even encrypt said data as most are probably aware. There are past
examples where control information has been sent within ICMP and other
packets using header fields.

My question surrounds detection; given that IDS tends to be payload
focused, if a covert channel exists that has encrypted data in a
packet header, how do we go about detecting it?

My initial thought leans toward the fact that encrypted data blocks
are statistically flat over time. Given say 'snort', how can we use
this idea? I am not a snort expert by any means, so please no
flames!

I would be happy to summarize opinions.

-Joff Thyer

------------------------------------------------------------------------
Test Your IDS

Is your IDS deployed correctly?
Find out quickly and easily by testing it with real-world attacks from CORE IMPACT.
Go to http://www.coresecurity.com/index.php5?module=Form&action=impact&campaign=intro_sfw to learn more.
------------------------------------------------------------------------



Relevant Pages

  • Re: Is md5 collision free for 128bit messages?
    ... The anonymization has to be unique, ... IDs have to be mapped to two different anon codes. ... simply encrypt the user data. ... since AES is a permutation, ...
    (sci.crypt)
  • Re: Detecting covert data channels?
    ... even encrypt said data as most are probably aware. ... packets using header fields. ... given that IDS tends to be payload ... not so much in the packets themselves. ...
    (Focus-IDS)
  • RE: ssh and ids
    ... > communications traffic is encrypted in normal channels how can an IDS ... connection to the original destination. ... as the SSH server, extract the data, analyze it and encrypt it again ... with another SSH connection until reaching the final destination. ...
    (Focus-IDS)
  • Re: Detecting covert data channels?
    ... even encrypt said data as most are probably aware. ... if a covert channel exists that has encrypted data in a ... If you want to know more about detecting covert channels read papers ... Test Your IDS ...
    (Focus-IDS)