Covert Channel Detection via Protocol Analysis in LAN Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Covert channels in computer networks are difficult to detect as they use illegitimate data transfer mechanisms, making them hard to identify and prevent, which can lead to security threats like Duqu2 malware compromising local area networks by manipulating communication protocols.

Innovation Solution

Implementing a security device within a local area network that intercepts and filters network traffic, using a security server to analyze connections and determine if they involve different transmission protocols, suspending and alerting on potential malicious covert channels.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If covert channels use illegitimate data transfer mechanisms to transfer information, then information transfer capability is improved, but detectability deteriorates making them hard to identify and prevent

Engineering Contradiction:
Improveinformation transfer capabilityVSAvoiddetectability
Core Design Contradiction:
Loss of informationVSDifficulty of detecting and measuring

Solution Approach 1:

The patent applies the principle of detecting covert channels by monitoring changes in communication patterns and protocols, analogous to detecting color changes. The system identifies covert channels by observing deviations from normal communication behaviors, such as unusual protocol sequences, timing patterns, or data transfer characteristics that differ from legitimate communications.

Inventive Principle:
Principle #32Color changes

Solution Approach 2:

The patent introduces an intermediary security device positioned between communicating parties that monitors and analyzes network traffic without blocking legitimate communication. This intermediary detects covert channels by examining communication patterns while allowing normal data transfer to continue, thus maintaining information transfer capability while improving detectability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security devices intercept and filter all network traffic to detect covert channels, then security monitoring capability is improved, but network performance deteriorates

Engineering Contradiction:
Improvesecurity monitoring capabilityVSAvoidnetwork performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies partial action by implementing selective monitoring that focuses only on specific communication patterns, protocols, or time periods that are suspicious or relevant to covert channel detection. Instead of analyzing all network traffic in detail, the system applies targeted inspection to reduce processing overhead while maintaining effective security monitoring for potential threats.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent segments network traffic analysis into different layers or types, applying different monitoring intensities to different traffic categories. Legitimate high-volume traffic receives minimal inspection, while suspicious or unusual traffic patterns trigger more detailed analysis. This segmentation allows comprehensive security monitoring without uniformly degrading network performance across all traffic types.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10447724B2Preventing security threats in a computer network
Publication Date: 2019.10.15 F SECURE CORP
  • US10447724B2 patent drawing
  • US10447724B2 patent drawing
  • US10447724B2 patent drawing

AI summary

Aspects of the invention relate to a method for preventing communication through covert channels in a Local Area Network (LAN). The method includes suspending an inbound or an outbound network connection related to a network element for a predetermined period of time, determining if any respective outbound or inbound network connection related to the same or any other network element ceases to transmit for the duration of the time period predetermined, if an outbound or inbound network connection is detected to cease transmission, concluding that the inbound or outbound network connection suspended and the respective outbound or inbound network connections are connected, determining whether the connected network connections use different transmission protocols and if the connected network connections are detected to use different transmission protocols, determining that the connected network connections are related to a malicious covert channel and taking action to prevent the malicious covert channel from working.