Covert Routing Detection via Latency Perturbation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Covert routing in network systems is difficult to detect and prevent, as it involves secret cooperation between users or devices and covert routers, which can redirect traffic to restricted systems, making it challenging to identify malicious activity and distinguish it from non-malicious activity, especially when packet data is encrypted or inaccessible due to legal or contractual reasons.
Innovation Solution
A filtering device is used to perturb the routing path between local and remote computer systems, utilizing connection-oriented protocol responses to detect covert activity by comparing latency measurements and updating a fraud metric associated with potential malicious activity, and by temporarily changing routing preferences to avoid covert routers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If covert routing is used to redirect traffic, then access to restricted systems is achieved, but detection and prevention become difficult
Solution Approach 1:
The system performs preliminary actions by establishing a baseline routing path and measuring latency before any potential covert routing occurs. This baseline is stored and used for future comparison to detect deviations that indicate covert routing activity
Solution Approach 2:
The system continuously monitors latency measurements and compares them against the baseline, providing feedback when deviations are detected. This feedback mechanism enables real-time detection of covert routing by identifying anomalies in round-trip time measurements
2Reliability
If packet data is encrypted or inaccessible, then privacy and security are maintained, but monitoring and detection capabilities are reduced
Solution Approach 1:
The system uses latency measurements as an intermediary indicator to detect covert routing without needing to access or decrypt packet data. By measuring round-trip time as a proxy metric, the system can identify suspicious routing behavior while maintaining encryption and privacy protections
3Measurement precision
If routing paths are perturbed to detect covert activity, then detection accuracy is improved, but network performance may be affected
Solution Approach 1:
The system applies partial probing actions by sending a limited number of test packets at intervals rather than continuously monitoring all traffic. This approach achieves sufficient detection accuracy while minimizing the impact on network performance and throughput
Data Source
AI summary
A method and apparatus for detecting covert routing is disclosed. In the method and apparatus, data addressed to a remote computer system are forwarded over a first network path, whereby the data is associated with a computer system of a plurality of computer systems. Further, a plurality of first network performance metrics is obtained. A likelihood of covert routing is determined based at least in part on the plurality of first network performance metrics.


