A Method for Constructing a Two-Dimensional Covert Channel Based on TCP
A two-dimensional covert channel model integrating time and storage channels with feedback, RS coding, and spread spectrum techniques addresses the limitations of single-dimensional channels, enhancing robustness and transmission efficiency in network communication.
Patent Information
- Application Number
- CN202210246892.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-03-06
- Publication Date
- 2025-07-15
- Estimated Expiration
- 2042-03-06
AI Technical Summary
Traditional single-dimensional hidden channels have problems such as poor concealment, poor robustness and low channel capacity, and are easily attacked.
The two-dimensional hidden channel model based on the TCP protocol is adopted, combining time-type and storage-type hidden channels, and adaptive selection through channel feedback, RS encoding, spread spectrum code and interleaving technology are used to optimize channel performance.
In network environments with different packet loss rates, channel robustness and transmission rate are better than single-dimensional channels, effectively protecting network security.
Smart Images

Figure CN114666111B_ABST
Abstract
Description
Technical Field:
[0001] This patent mainly relates to the security problem of network information transmission, that is, the problem of ensuring the concealment and correctness of information transmission by applying covert channel technology. Background Art:
[0002] A network covert channel is a communication channel that violates communication restriction rules for covert information transmission in a network environment. It uses the characteristic patterns of the carrier characteristics of network information carriers for covert information transmission to prevent the information from being discovered. Due to its characteristic of covert communication, it is applied by more and more people to ensure the security and privacy of normal communication information transmitted through the network.
[0003] With the emergence of quantum computers, the computing power of computers has been continuously improved. At the same time, there are also attacks on encryption algorithms. Traditional encryption technologies for protecting the security and privacy of data transmission are facing increasing challenges. Encryption technology prevents third parties from reading data by making the information unreadable, while network covert channel technology prevents the information itself from being discovered. As a new communication method and communication strategy, it can strongly complement traditional encrypted communication. Due to the two aspects of application of network covert channels in network information transmission security, it is very necessary to study network covert channels.
[0004] In the 1970s, Lampson first clearly defined the meaning of a covert channel, pointing out that using a normal channel for communication purposes other than the channel design forms a covert channel. In 1985, the Trusted Computer Security Evaluation Criteria published by the DOD stated that the meaning of a covert channel is "a way of information transmission that is inconsistent with the built-in secure communication mechanism in the operating system". The description of the covert channel: "For a certain secure communication mechanism M and its instance I(M) in a computer system, when the communication between the sender S i and the receiver S j does not conform to the secure communication protocol of M, the communication between the sender S i and the receiver S j in I(M) belongs to covert communication" is widely accepted. In 1987, Girling elaborated on three types of covert channels existing in local area networks, which initiated the research on covert channels in the field of computer networks. With the popularization of computer networks and informatization, computer networks have become increasingly important and have become the target of network malicious destroyers. The significance of researching covert channels in computer networks is far greater than that of researching covert channels in computer stand-alone systems.
[0005] The evaluation metrics of network covert channels include three aspects: concealment, robustness, and transmission efficiency. Concealment refers to the ability of a network covert channel not to be detected. Robustness refers to the ability of a network covert channel to resist interference and accurately transmit data. Transmission efficiency refers to the ability of a network covert channel to transmit data volume per unit time. Summary of the Invention:
[0006] Technical Problem to be Solved:
[0007] There are still limitations in single-dimensional covert channels. In recent years, a large number of single-dimensional covert channels have emerged. However, storage-type network covert channels still face the problem of how to make up for the poor concealment when only using a single storage attribute as the carrier of covert information. And time-type covert channels face the problems of how to make up for the low information-carrying ability and the low channel capacity and poor robustness brought by the time attribute that can only communicate serially. At the same time, one-dimensional covert channels are easily targeted by the censorship party. For one-dimensional storage-type covert channels, the TN method can effectively standardize the fields in various protocols, achieving the purpose of almost eliminating the carrier of covert information. By adding noise, the transmission rate of such channels can also be effectively reduced. For one-dimensional time-type covert channels, by adding time delay, the accuracy of the receiver of the channel decoding covert information can be reduced. To solve these problems, the inventor hopes to propose a method for constructing a two-dimensional covert channel model based on the TCP protocol.
[0008] Technical Means:
[0009] To solve the problem that traditional single-dimensional covert channels still have limitations, the inventor draws on methods such as coding and spread spectrum in communication, and combines time-type covert channels and storage-type covert channels to avoid the limitations of single-dimensional covert channels.
[0010] The inventor intends to propose a method for constructing a two-dimensional covert channel. By introducing channel feedback, the channel is adaptively selected. At the same time, RS coding, spread spectrum codes, and interleaving techniques are applied to optimize the two-dimensional covert channel, improve the channel performance, and ensure that the concealment, robustness, and transmission efficiency of the two-dimensional covert channel are all better than those of traditional one-dimensional covert channels. The method includes optimization methods for time-type covert channels and storage-type covert channels respectively. It is worth noting that in the optimization method for time-type covert channels, it also includes a solution to the problem that it is difficult to balance the complexity and randomness of spread spectrum codes, which is also helpful for improving the optimization idea of time-type covert channels.
[0011] Advantageous Effects:
[0012] Through experimental comparison, the channel robustness of this method is better than that of a certain single-dimensional channel in network environments with different packet loss rates. At the same time, under the same average time interval, the transmission rate is also better than that of the above single-dimensional covert channel. Ensure the safety and effectiveness of the solution.
[0013] After testing, it is found that the technical solution proposed by the inventor can effectively transmit covert information in the network. Even if the network fluctuates or is attacked by the enemy, it can protect network security. Description of the Drawings:
[0014] Figure 1 Model of two-dimensional covert channel
[0015] Figure 2 Interference response mode of two-dimensional covert channel
[0016] Figure 3 Gold-code generation diagram
[0017] Figure 4 Packet interleaving scheme
[0018] Figure 5 Adaptive model of storage-type covert channel
[0019] Figure 6 Adaptive model of time-type covert channel Detailed implementation manners:
[0020] The method for constructing a two-dimensional covert channel includes an overall architecture, an optimization scheme for a storage-type covert channel, and an optimization scheme for a time-type covert channel.
[0021] Overall architecture:
[0022] Figure 1 The model of the two-dimensional covert channel designed in this paper is given. This model is based on the time dimension and space dimension in the TCP protocol transmission process, and constructs and optimizes a TCP-based time-type covert channel and a TCP-based storage-type covert channel respectively. When the sender sends covert information, it first transmits through the storage-type covert channel with a larger transmission rate. During the transmission process, according to the channel feedback, the transmission channel is adaptively changed to ensure that the transmission process of the covert information is not interfered and the information can reach the receiver accurately. Then the receiver decrypts it.
[0023] For two different one-dimensional covert channels, the examiner mostly uses different specific technologies for interference and elimination. For the storage-type covert channel, various attributes of fields in the protocol are mainly used to transmit covert information. The TN method can effectively standardize the fields in various protocols, achieving the purpose of almost eliminating the carrier of covert information. The transmission rate of such channels can also be effectively reduced by adding noise. For the time-type covert channel, the IPD or the delay of accessing caches and shared components in non-local systems is used as the carrier of covert information. By adding delays, the length of the IPD or access delay can be changed, thereby reducing the accuracy of the receiver of the channel to decode the covert information. In the face of this situation, the two-dimensional covert channel can detect the signal-to-noise ratio and delay jitter in the channel, judge the interference situation of the channel, select the optimal transmission method, and ensure that the covert information can be received completely and correctly by the receiver. Adaptive response to interference patterns such as Figure 2 as shown
[0024] Technologies such as RS coding, PN codes, and interleaving are applied in the construction method
[0025] ●RS coding scheme
[0026] The RS code designed in this paper uses the standard (7,3) RS code, with a total of 7 fields, 3 original data bits, and 4 error correction code bits. In the original data sent by the sender, every 3 fields will be combined with 4 error correction code fields to form an RS code segment. Each RS code segment can correct 2 errors that occur during transmission
[0027] ●PN code scheme
[0028] In this paper, the Gold code is selected as the PN code for spreading spectrum. The Gold code is another sequence generated by the M code. The M code is the abbreviation of the longest linear feedback shift register sequence. It is a sequence with the longest period generated by a shift register with linear feedback and is a typical pseudo-random sequence. The higher the autocorrelation of the sequence, the higher the randomness of the generated PN code. The Gold code has better autocorrelation and worse cross-correlation than the M code, with higher robustness and concealment, and is suitable as the spreading spectrum code for covert communication. A Gold code is obtained by performing a parallel operation on a pair of preferred M codes with the same period and rate. The code length is 2 k -1, where k is the number of bits of the generating register. The Gold code generation diagram is as Figure 3 shown
[0029] ●Interleaving scheme
[0030] In this paper, block interleaving is selected to interleave the covert information. Block interleaving fills the encoded sequence into a C×D matrix in column order, where C is the number of rows of the matrix and D is the number of columns of the matrix. After the matrix is completely filled, it is output row by row. At the receiving end, the deinterleaver performs the same operation. The symbols from the extraction module enter the C×D matrix in column order and are shifted out to the decoder in row order. In this way, any consecutive channel symbol errors less than D can be converted into independent errors at the output of the deinterleaver. The block interleaving scheme is shown in Figure 4 。
[0031] Storage covert channel communication scheme:
[0032] Figure 5 An adaptive model of the storage covert channel is given. The specific steps for transmitting covert information using the storage covert channel are as follows:
[0033] Step 1: The sender transmits the covert information to be sent to the sending end.
[0034] Step 2: Encode the covert information through an encoder. Among them, the encoding for the storage covert channel adopts a 32 - base encoding method. Since the covert information to be transmitted may contain English letters, it can be represented by 32 - base characters. The 32 - base information is converted into binary and stored in the TCP protocol header. The covert information to be transmitted is thus converted into a binary message. This process is shown in formula (1):
[0035] f: string i → byte i (1)
[0036] where, string i is the original information, and byte i is the encoded binary information.
[0037] Step 3: Hide the covert information by placing it into the 32 - bit sequence number of the TCP protocol header and then transmit it. Relying on the reliability of the TCP protocol, the robustness of the covert channel itself is also greatly improved.
[0038] Step 4: After receiving the message, the receiver decodes the covert information through a decoder, and at the same time monitors the network signal - to - noise ratio and packet delay, and feeds back the data to the sender through the feedback channel. The sender can rely on the feedback data to dynamically adjust the sending method to adapt to different situations. The decoding is shown in formula (2):
[0039] f: byte i → string i (2)
[0040] Step 5: The receiver obtains the covert information from the receiving end.
[0041] Timing Covert Channel Communication Scheme:
[0042] Figure 6 An adaptive model of the timing covert channel is given. The specific steps for transmitting covert information using the timing covert channel are as follows:
[0043] Step 1: The sender transmits the covert information to be sent into the sender side.
[0044] Step 2: Encode the covert information through an encoder. Among them, the encoding for the timing covert channel adopts an encoding method based on RS encoding carried out in the finite field GF(2 n ). In the GF(2 n ) field, each element is defined by a polynomial. 2 n is called the order of the field, and there are 2 n elements in the field. The element definition is shown in formula (3):
[0045] f(x) = p0 + p1x + p2x 2 ++ p n-1 x n-1 (3)
[0046] where n is the value of n in the finite field GF(2 n ), and p i is a random number with a value from 0 to 1.
[0047] For all data points (x i , f(x i )) in formula (3), there is:
[0048]
[0049] where m is the amount of transmitted data. Formula (4) can be transformed to get:
[0050]
[0051] where y is another expression of f(x). Formula (5) can be transformed again to get:
[0052]
[0053] Denote the left matrix in formula (6) as matrix B. Then the unique solution is:
[0054]
[0055] Step 3: Assume the transmitted data is A(a1 a2 … a m ), and construct matrix F according to the above derivation:
[0056]
[0057] It can be seen that the F matrix is composed of the B matrix and the identity matrix, where E is the identity matrix.
[0058] Step 4: Obtain the matrix R through formula (9). The matrix R is the matrix transmitted over the channel. At the same time, synchronize the matrix F to the receiving end. Where (c1 c2 … c m ) is the specific product.
[0059]
[0060] Step 5: Select an 8-bit Gold code G through the PN code multiplier and perform an exclusive OR operation with the encoded hidden information bit by bit.
[0061] Step 6: Group-interleave the encoded sequence through the interleaver and fill it into a C×D matrix in column order, where C is the number of rows of the matrix and D is the number of columns of the matrix. When the matrix is completely filled, output it by row.
[0062] Step 7: Transmit the hidden information through the data packet time interval, set the time slice. If the receiving party receives a data packet within the time slice, it is "1", and if the receiving party does not receive a data packet within the time slice, it is "0".
[0063] Step 8: After the receiving party receives the message, de-interleave the hidden information. The code elements from the extraction module enter the C×D matrix in column order and are shifted out to the multiplication reduction unit in row order. At the same time, monitor the network signal-to-noise ratio and data packet delay, and feedback the data to the sender through the feedback channel. The sender can rely on the feedback data to dynamically adjust the sending method to adapt to different situations.
[0064] Step 9: Re-perform an exclusive OR operation on each column of the de-interleaved data with the selected Gold code G through the multiplication reduction unit. If 4 or more of the 8-bit results are "1", then restore the 8-bit information to "1", otherwise restore it to "0".
[0065] Step 10: The restored data is called the matrix R′. After the decoder receives the R′ matrix, perform error correction. If it is found that the data in a certain row is incorrect, remove the data in the row where the error is located, and then multiply the inverse of the F matrix after removing the row by the R′ matrix to obtain the original data A.
[0066] Step 11: The receiver obtains the hidden information from the receiving end.
[0067] PN code optimization scheme:
[0068] As the length of the Gold code increases, the randomness of the PN code becomes stronger, but at the same time the algorithm complexity also increases. This paper selects the Gold code generated by an 8-bit register as the PN code used for spread spectrum, with a repetition period of less than 1 minute.
[0069] The optimization solutions for the above situation are as follows:
[0070] Step 1: The algorithm randomly generates 100 pairs of preferred M codes and calculates the corresponding 100 Gold codes. A maximum time T is set. When the count reaches T, all generated M codes and Gold codes are cleared and the same number of sequences are regenerated.
[0071] Step 2: Each time a PN code is selected, the sender and receiver simultaneously generate a random positive integer N (0 <N<100)。
[0072] Step 3: Combine the random number N, the channel signal-to-noise ratio and delay jitter data detected in the feedback channel, and jointly generate the random number M i , as shown in formula (10).
[0073]
[0074] Where t is the transmission delay, M i To select the sequence number of the PN code, M0=1, and N is a random positive integer from 0 to 100.
[0075] Step 4: Select the corresponding sequence from the currently generated 100 Gold codes as the PN code for the current transmission. If it has been used, the next set of PN codes will be used. The selected PN code is the 8-bit Gold code G used in the PN code multiplier.
[0076] According to calculations, when the covert channel packet transmission interval is 20ms, the Gold code generated in the current period will be completely consumed after 17 minutes. Considering that the overall randomness decreases due to the consumption of Gold codes in the later period of each time period, in this scenario, T can be set to 10 minutes to ensure the randomness of the PN code.
Claims
1. A method for constructing a two-dimensional covert channel based on TCP, characterized in that: Includes the overall architecture, optimization solutions for storage-based covert channels, and optimization solutions for time-based covert channels; Based on the time dimension and space dimension in the TCP protocol transmission process, a TCP-based time-type covert channel and a TCP-based storage-type covert channel are constructed and optimized respectively; when the sender sends covert information, it is first transmitted through the storage-type covert channel. During the transmission process, according to the channel feedback, the transmission channel is adaptively changed to ensure that the covert information transmission process is not disturbed, and then the receiver decrypts it; Storage-based covert channel communication scheme: The specific steps of using storage-type covert channels for covert information transmission are as follows: Step 1: The sender transmits the hidden information to be sent to the sending end; Step 2: Encode the covert information through an encoder; a 32-based encoding method is used for encoding the storage-type covert channel; convert the 32-bit information into binary and store it in the TCP protocol header; the covert information to be transmitted is converted into a binary message; this process is shown in formula (1): f: string i → byte i (1) Among them, string i is the original information, byte i is the encoded binary information; Step 3: Place the covert information into the 32-bit sequence number of the TCP protocol header to hide and transmit; relying on the reliability of the TCP protocol, the robustness of the covert channel itself has also been greatly improved; Step 4: After receiving the message, the receiver decodes the hidden information through the decoder, monitors the network signal-to-noise ratio and packet delay, and feeds back the data to the sender through the feedback channel. The sender dynamically adjusts the sending mode based on the feedback data to adapt to different situations; the decoding is shown in formula (2): f: byte i → string i (2) Step 5: The receiver obtains the hidden information from the receiving end; Time-based covert channel communication scheme: The specific steps of using time-based covert channels for covert information transmission are as follows: Step 1: The sender transmits the hidden information to be sent to the sending end; Step 2: Encode the covert information through an encoder; among them, the encoding for the time-based covert channel adopts an encoding method based on RS encoding carried out in the finite field of GF(2 n ); in the field of GF(2 n ), each element is defined by a polynomial; 2 n is called the order of the field, and there are 2 n elements in the field; the element definition is shown in formula (3): f(x) = p0 + p1x + p2x 2 + … + p n-1 x n-1 (3) where n is the value of n in the finite field GF(2 n ), and p i is a random number with values from 0 to 1; For all data points (x i , f(x i )) in formula (3), there is: Where m is the amount of data transmitted; formula (4) is transformed into: Where y is another expression of f(x); Formula (5) can be transformed again to obtain: Let the matrix on the left side of formula (6) be matrix B; then the unique solution is: Step 3: Let the transmitted data be A(a1a2…a m ), and construct matrix F according to the above derivation: The F matrix is composed of the B matrix and the identity matrix, where E is the identity matrix; Step 4: Obtain matrix R through formula (9); matrix R is the matrix transmitted over the channel; at the same time, synchronize matrix F to the receiving end; where (c1c2…c m ) is the specific product; Step 5: Select 8-bit Gold code through PN code multiplier and perform bitwise XOR with the encoded hidden information; Step 6: The coded sequence is interleaved by the interleaver in groups and filled into a C×D matrix in column order, where C is the number of rows and D is the number of columns. When the matrix is completely filled, it is output row by row. Step 7: The hidden information is transmitted through the time interval of the data packet, and the time slice is set. If the receiver receives the data packet within the time slice, it is "1", and if the receiver does not receive the data packet within the time slice, it is "0"; Step 8: After receiving the message, the receiver deinterleaves the hidden information, enters the code elements from the extraction module into the C×D matrix in the order of columns, and moves them out to the multiplication restorer in the order of rows; at the same time, the network signal-to-noise ratio and data packet delay are monitored, and the data is fed back to the sender through the feedback channel. The sender dynamically adjusts the sending mode based on the feedback data to adapt to different situations; Step 9: XOR each column of deinterleaved data with the selected Gold code again through the multiplication restorer. If 4 or more bits of the 8-bit result are "1", the 8-bit information is restored to "1", otherwise it is restored to "0"; Step 10: The restored data is called matrix R'; after receiving the R' matrix, the decoder performs error correction. If a row of data is found to be wrong, the data in the row where the error is located is removed, and then the inverse of the F matrix after the row is removed is multiplied with the R' matrix to obtain the original data A; Step 11: The receiver obtains the hidden information from the receiving end.
2. The method according to claim 1, characterized in that: Select the Gold code generated by the 8-bit register as the PN code used for spread spectrum, with a repetition period of less than 1 minute; The optimization solutions for the above situation are as follows: Step 1: The algorithm randomly generates 100 pairs of M codes and calculates the corresponding 100 Gold codes. It also sets a maximum time T. When the count reaches T, it clears all generated M codes and Gold codes and regenerates the same number of sequences. Step 2: Each time a PN code is selected, the sender and receiver simultaneously generate a random positive integer N, 0 <N<100; Step 3: Combine the random number N, the channel signal-to-noise ratio detected in the feedback channel, and the delay jitter data to jointly generate a random number M i , as shown in formula (10); where t is the transmission delay, M i is the serial number for selecting the PN code, M0 = 1, and i is a random positive integer from 0 to 100; Step 4: Select the corresponding sequence from the 100 Gold codes currently generated as the PN code for the current transmission. If it has been used, the next set of PN codes will be used. The 8-bit Gold code is used in the PN code multiplier.