Ordinal synchronization mark sequence and its steganography for a multi-link network covert channel.

A multi-link network covert channel (MLCC) such as Cloak exhibits a high capacity and robustness and can achieve lossless modulation of the protocol data units. However, the mechanism of Cloak involving an arrangement of packets over the links (APL) is limited by its passive synchronization schemes,...

Descripción completa

Guardado en:
Detalles Bibliográficos
Autores principales: Songyin Fu, Rangding Wang, Li Dong, Diqun Yan
Formato: article
Lenguaje:EN
Publicado: Public Library of Science (PLoS) 2021
Materias:
R
Q
Acceso en línea:https://doaj.org/article/cc03bdc45a194d819407c00e1aba0d29
Etiquetas: Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
id oai:doaj.org-article:cc03bdc45a194d819407c00e1aba0d29
record_format dspace
spelling oai:doaj.org-article:cc03bdc45a194d819407c00e1aba0d292021-12-02T20:07:15ZOrdinal synchronization mark sequence and its steganography for a multi-link network covert channel.1932-620310.1371/journal.pone.0252813https://doaj.org/article/cc03bdc45a194d819407c00e1aba0d292021-01-01T00:00:00Zhttps://doi.org/10.1371/journal.pone.0252813https://doaj.org/toc/1932-6203A multi-link network covert channel (MLCC) such as Cloak exhibits a high capacity and robustness and can achieve lossless modulation of the protocol data units. However, the mechanism of Cloak involving an arrangement of packets over the links (APL) is limited by its passive synchronization schemes, which results in intermittent obstructions in transmitting APL packets and anomalous link switching patterns. In this work, we propose a novel ordinal synchronization mark sequence (OSMS) for a Cloak framework based MLCC to ensure that the marked APL packets are orderly distinguishable. Specifically, a unidirectional function is used to generate the OSMS randomly before realizing covert modulation. Subsequently, we formulate the generation relation of the marks according to their order and embed each mark into the APL packets by using a one-way hash function such that the mark cannot be cracked during the transmission of the APL packet. Finally, we set up a retrieval function of the finite set at the covert receiver to extract the marks and determine their orders, and the APL packets are reorganized to realize covert demodulation. The results of experiments performed on real traffic indicated that the MLCC embedded with OSMS could avoid the passive synchronization schemes and exhibited superior performance in terms of reliability, throughput, and undetectability compared with the renowned Cloak method, especially under a malicious network interference scenario. Furthermore, our approach could effectively resist the inter-link correlation test, which are highly effective in testing the Cloak framework.Songyin FuRangding WangLi DongDiqun YanPublic Library of Science (PLoS)articleMedicineRScienceQENPLoS ONE, Vol 16, Iss 6, p e0252813 (2021)
institution DOAJ
collection DOAJ
language EN
topic Medicine
R
Science
Q
spellingShingle Medicine
R
Science
Q
Songyin Fu
Rangding Wang
Li Dong
Diqun Yan
Ordinal synchronization mark sequence and its steganography for a multi-link network covert channel.
description A multi-link network covert channel (MLCC) such as Cloak exhibits a high capacity and robustness and can achieve lossless modulation of the protocol data units. However, the mechanism of Cloak involving an arrangement of packets over the links (APL) is limited by its passive synchronization schemes, which results in intermittent obstructions in transmitting APL packets and anomalous link switching patterns. In this work, we propose a novel ordinal synchronization mark sequence (OSMS) for a Cloak framework based MLCC to ensure that the marked APL packets are orderly distinguishable. Specifically, a unidirectional function is used to generate the OSMS randomly before realizing covert modulation. Subsequently, we formulate the generation relation of the marks according to their order and embed each mark into the APL packets by using a one-way hash function such that the mark cannot be cracked during the transmission of the APL packet. Finally, we set up a retrieval function of the finite set at the covert receiver to extract the marks and determine their orders, and the APL packets are reorganized to realize covert demodulation. The results of experiments performed on real traffic indicated that the MLCC embedded with OSMS could avoid the passive synchronization schemes and exhibited superior performance in terms of reliability, throughput, and undetectability compared with the renowned Cloak method, especially under a malicious network interference scenario. Furthermore, our approach could effectively resist the inter-link correlation test, which are highly effective in testing the Cloak framework.
format article
author Songyin Fu
Rangding Wang
Li Dong
Diqun Yan
author_facet Songyin Fu
Rangding Wang
Li Dong
Diqun Yan
author_sort Songyin Fu
title Ordinal synchronization mark sequence and its steganography for a multi-link network covert channel.
title_short Ordinal synchronization mark sequence and its steganography for a multi-link network covert channel.
title_full Ordinal synchronization mark sequence and its steganography for a multi-link network covert channel.
title_fullStr Ordinal synchronization mark sequence and its steganography for a multi-link network covert channel.
title_full_unstemmed Ordinal synchronization mark sequence and its steganography for a multi-link network covert channel.
title_sort ordinal synchronization mark sequence and its steganography for a multi-link network covert channel.
publisher Public Library of Science (PLoS)
publishDate 2021
url https://doaj.org/article/cc03bdc45a194d819407c00e1aba0d29
work_keys_str_mv AT songyinfu ordinalsynchronizationmarksequenceanditssteganographyforamultilinknetworkcovertchannel
AT rangdingwang ordinalsynchronizationmarksequenceanditssteganographyforamultilinknetworkcovertchannel
AT lidong ordinalsynchronizationmarksequenceanditssteganographyforamultilinknetworkcovertchannel
AT diqunyan ordinalsynchronizationmarksequenceanditssteganographyforamultilinknetworkcovertchannel
_version_ 1718375328919846912