Covert Data Storage via ICMP Error Messages
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network communication protocols, such as TCP/IP, do not provide a method for covertly storing data within a network without revealing the existence or origin of the data, limiting the ability to maintain long-term storage while maintaining network integrity.
Innovation Solution
The system employs a 'blind host' that generates ICMP error messages when reassembling fragmented datagrams, allowing data to be stored temporarily and then propagated through a ring of confederate hosts, masking the data's origin and existence by using standard protocol behaviors.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Difficulty of detecting and measuring
If data is stored covertly within a network using blind hosts and ICMP error messages, then the data's origin and existence remain undetectable, but the storage duration is limited by network protocol timeouts and reassembly requirements
Solution Approach 1:
The data is fragmented into multiple IP datagram fragments that are reassembled by blind hosts. Each fragment is embedded within ICMP error messages, creating a segmented storage mechanism that extends storage duration while maintaining covert characteristics. The fragmentation allows data to be distributed across multiple hosts and messages, preventing detection while enabling longer retention through sequential reassembly and forwarding.
Solution Approach 2:
Blind hosts serve as intermediaries that receive, store, and forward fragmented data without detecting its true nature. These hosts process ICMP error messages containing embedded data fragments, temporarily storing them in memory before forwarding to the next host in the chain. The intermediary hosts mask the data's origin and existence while extending storage duration through their participation in the covert storage network.
2Adaptability or versatility
If standard TCP/IP protocols are used for data transmission, then network compatibility and communication reliability are maintained, but no covert storage capability is provided
Solution Approach 1:
Standard TCP/IP protocols and ICMP error messages are used to perform multiple functions: normal error reporting and covert data transmission simultaneously. The same protocol infrastructure that provides universal network compatibility also enables hidden storage capabilities through clever embedding of data within legitimate protocol messages, achieving both compatibility and secrecy without requiring alternative protocols.
Solution Approach 2:
The patent converts the potentially harmful or unwanted ICMP error messages into beneficial covert storage vehicles. Instead of treating error messages as noise or disturbances to be filtered, the system embeds valuable data within them, transforming what could be considered protocol overhead or error handling into a useful storage mechanism that maintains compatibility while providing hidden capabilities.
3Difficulty of detecting and measuring
If data is stored in blind hosts waiting for reassembly, then covert storage is achieved, but network bandwidth is consumed and hosts experience increased memory usage
Solution Approach 1:
The system uses periodic ICMP error messages to transmit fragmented data through the network. Each error message represents a periodic transmission event that carries a portion of the stored data. This periodic action allows blind hosts to forward fragments sequentially, managing memory resources by processing and forwarding data in discrete time intervals rather than holding entire datasets in memory simultaneously.
Solution Approach 2:
Data is divided into small fragments embedded within individual ICMP error messages, reducing the memory burden on each blind host. Each host only needs to store and process one fragment at a time rather than entire datasets, minimizing memory usage while still achieving covert storage. The segmentation also reduces network bandwidth consumption per message, as each carries only a portion of the total data.
Data Source
AI summary
Systems and methods for storing a covert payload of data within a network are provided. A datagram is generated at an origin host comprising the covert payload of data, a more fragments flag indicating that the datagram is part of a larger transmission, a source address for a confederate host, and a destination address for a blind host. The datagram is transmitted from the origin host to the blind host. When no further datagrams are received, the blind host sends an error message with the covert payload of data to the confederate host. This may be repeated across a number of blind and confederate hosts to form a ring.

