Netinfo Security ›› 2020, Vol. 20 ›› Issue (6): 57-64.doi: 10.3969/j.issn.1671-1122.2020.06.007

Previous Articles     Next Articles

Research on Covert Channel Construction Method Based on HTTP Protocol Combination

CHEN Cheng1, LUO Senlin1, WU Qian2(), YANG Peng2   

  1. 1. Information System & Security and Countermeasures Experiments Center, Beijing Institute of Technology, Beijing 100081, China
    2. National Computer Network Emergency Response Technical Team Coordination Center of China, Beijing 100094, China
  • Received:2019-07-01 Online:2020-06-10 Published:2020-10-21
  • Contact: WU Qian E-mail:wuqian@cert.org.cn

Abstract:

Aiming at the problem that the existing covert storage channel has a low concealment, and the covert timing channel has a high bit error rate and a low transmission rate, a covert channel construction method combining HTTP protocol behaviors is proposed. In the method, HTTP requests are sent by simulating a browser application and allocated dynamically among different browsers, the concealed information is embedded by means of mathematical combination. The access object, the packet time interval and the packet length are also dynamically adjusted to improve the concealment of channel. At the same time, the channel is based on the reliable transmission of TCP protocol, so that it is not affected by the network jitter, thus ensuring the reliability of the channel. The experimental results show that the proposed method can resist the application signature based detection method, protocol fingerprint detection method and combined model detection method, and has strong concealment. It can adjust the concealment and channel capacity according to the application scenario.

Key words: covert channel, mathematical combination coding, HTTP protocol

CLC Number: