论文标题

一个轻巧的适应性DNS渠道,用于隐秘数据传输

A Lightweight Adaptable DNS Channel for Covert Data Transmission

论文作者

Nazari, Mahboubeh, Tarahomi, Sousan, Aliabady, Sobhan

论文摘要

由于安全在在线通信中的重要作用以及攻击者正在开发其工具的事实,因此对安全工具进行现代化是必不可少的。多年后,加密系统的效率已得到证明,但是人们可能需要在不引起关注的情况下进行交流,尤其是在传输秘密数据(例如钥匙)时。秘密渠道是合适的工具,用于通过使用隐志原则来掩盖除最终通信方以外的数据的存在。他们可以默默无闻进行安全的交流。偷偷摸摸的工作并提供可接受的吞吐量是设计秘密渠道的问题。 DNS协议属性类似于其运行应用程序的必要性,并且可用性可以很好地提供上述问题。在本文中,我们提出了一个使用DNS协议作为传输数据的媒体的存储秘密通道。关键功能包括连接建立,具有网络环境的适应性,意味着轻巧的混淆方法和HMAC以满足机密性和完整性。实验结果表明,提出的通道统计数据非常适合正常运输。该通道的平均容量为2.65字节,每个数据包的数据。

Due to the vital role of security in online communications and this fact that attackers are developing their tools, modernizing the security tools is an essential. The efficiency of crypto systems has been proven after years, however one may need to communicate stealthy without drawing attention especially in transferring secret data such as keys. Covert channels are suitable tools that used to conceal the existence of data besides end communication parties by employing principles of steganography. They can make secure communications with obscurity. Working stealthy and providing an acceptable throughput are issues in designing covert channels. The DNS protocol properties like its necessity for running applications and the availability can provide aforementioned issues decently. In this paper, we proposed a storage covert channel which uses DNS protocol as a media for transferring data. The key features include connection establishment, adaptability with network environment, implying a lightweight obfuscation method and HMAC to meet confidentiality and integrity. Experimental results show the proposed channel statistics are well adapted with normal traffics. The channel has an average capacity of 2.65 bytes of data per packet.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源