Detection method and device for carrying out covert channel communication based on ICMP protocol
A covert channel and detection method technology, applied in the field of communication, can solve the problems of ICMP communication not strictly complying with ICMP protocol specifications and RFC standards, difficulty in troubleshooting network communication, and high performance consumption, so as to achieve normal operation, good detection performance, The effect of high detection efficiency
- Summary
- Abstract
- Description
- Claims
- Application Information
AI Technical Summary
Problems solved by technology
Method used
Image
Examples
Embodiment 1
[0054] An embodiment of the present invention provides a detection method for covert channel communication based on the ICMP protocol, which is applied to the detection field of covert channels and executed by electronic equipment in the corresponding field. The electronic equipment may be, for example, a detection device or a controller of the detection device.
[0055] Such as figure 1 As shown, the method includes:
[0056] Step S102, analyzing the acquired ICMP flow message to obtain the transmission identifier and transmission content;
[0057] Step S104, judging whether the transmission content is messy;
[0058] Step S106, if the transmission content is messy, determine whether the request content corresponding to the target transmission identifier is the same as the response content;
[0059] Step S108, if the request content corresponding to the target transmission identifier is different from the response content, determine the covert channel communication behavior...
Embodiment 2
[0137] Such as Figure 4 As shown, the embodiment of the present invention provides a detection device for covert channel communication based on the ICMP protocol, the device includes:
[0138] The flow analysis module 400 is used to analyze the obtained ICMP flow message to obtain the transmission identification and transmission content;
[0139] The first judging module 500 is used to judge whether the transmission content is messy;
[0140] The second judging module 600 is configured to judge whether the request content corresponding to the target transmission identifier is the same as the response content if the transmission content is messy;
[0141] The channel determination module 700 is configured to determine a covert channel communication behavior based on the target transmission identifier if the request content corresponding to the target transmission identifier is different from the response content.
[0142]Further, the first judging module 500 is used to group...
PUM
Abstract
Description
Claims
Application Information
- R&D Engineer
- R&D Manager
- IP Professional
- Industry Leading Data Capabilities
- Powerful AI technology
- Patent DNA Extraction
Browse by: Latest US Patents, China's latest patents, Technical Efficacy Thesaurus, Application Domain, Technology Topic, Popular Technical Reports.
© 2024 PatSnap. All rights reserved.Legal|Privacy policy|Modern Slavery Act Transparency Statement|Sitemap|About US| Contact US: help@patsnap.com