Covert Channel Detection via Protocol Analysis in LAN Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Covert channels in computer networks are difficult to detect as they use illegitimate data transfer mechanisms, making them hard to identify and prevent, which can lead to security threats like Duqu2 malware compromising local area networks by manipulating communication protocols.
Innovation Solution
Implementing a security device within a local area network that intercepts and filters network traffic, using a security server to analyze connections and determine if they involve different transmission protocols, suspending and alerting on potential malicious covert channels.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If covert channels use illegitimate data transfer mechanisms to transfer information, then information transfer capability is improved, but detectability deteriorates making them hard to identify and prevent
Solution Approach 1:
The patent applies the principle of detecting covert channels by monitoring changes in communication patterns and protocols, analogous to detecting color changes. The system identifies covert channels by observing deviations from normal communication behaviors, such as unusual protocol sequences, timing patterns, or data transfer characteristics that differ from legitimate communications.
Solution Approach 2:
The patent introduces an intermediary security device positioned between communicating parties that monitors and analyzes network traffic without blocking legitimate communication. This intermediary detects covert channels by examining communication patterns while allowing normal data transfer to continue, thus maintaining information transfer capability while improving detectability.
2Reliability
If security devices intercept and filter all network traffic to detect covert channels, then security monitoring capability is improved, but network performance deteriorates
Solution Approach 1:
The patent applies partial action by implementing selective monitoring that focuses only on specific communication patterns, protocols, or time periods that are suspicious or relevant to covert channel detection. Instead of analyzing all network traffic in detail, the system applies targeted inspection to reduce processing overhead while maintaining effective security monitoring for potential threats.
Solution Approach 2:
The patent segments network traffic analysis into different layers or types, applying different monitoring intensities to different traffic categories. Legitimate high-volume traffic receives minimal inspection, while suspicious or unusual traffic patterns trigger more detailed analysis. This segmentation allows comprehensive security monitoring without uniformly degrading network performance across all traffic types.
Data Source
AI summary
Aspects of the invention relate to a method for preventing communication through covert channels in a Local Area Network (LAN). The method includes suspending an inbound or an outbound network connection related to a network element for a predetermined period of time, determining if any respective outbound or inbound network connection related to the same or any other network element ceases to transmit for the duration of the time period predetermined, if an outbound or inbound network connection is detected to cease transmission, concluding that the inbound or outbound network connection suspended and the respective outbound or inbound network connections are connected, determining whether the connected network connections use different transmission protocols and if the connected network connections are detected to use different transmission protocols, determining that the connected network connections are related to a malicious covert channel and taking action to prevent the malicious covert channel from working.


