Covert Data Storage via ICMP Error Messages

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network communication protocols, such as TCP/IP, do not provide a method for covertly storing data within a network without revealing the existence or origin of the data, limiting the ability to maintain long-term storage while maintaining network integrity.

Innovation Solution

The system employs a 'blind host' that generates ICMP error messages when reassembling fragmented datagrams, allowing data to be stored temporarily and then propagated through a ring of confederate hosts, masking the data's origin and existence by using standard protocol behaviors.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Difficulty of detecting and measuring

If data is stored covertly within a network using blind hosts and ICMP error messages, then the data's origin and existence remain undetectable, but the storage duration is limited by network protocol timeouts and reassembly requirements

Engineering Contradiction:
Improvedetectability of data origin and existenceVSAvoidstorage duration
Core Design Contradiction:
Difficulty of detecting and measuringVSDuration of action of moving object

Solution Approach 1:

The data is fragmented into multiple IP datagram fragments that are reassembled by blind hosts. Each fragment is embedded within ICMP error messages, creating a segmented storage mechanism that extends storage duration while maintaining covert characteristics. The fragmentation allows data to be distributed across multiple hosts and messages, preventing detection while enabling longer retention through sequential reassembly and forwarding.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Blind hosts serve as intermediaries that receive, store, and forward fragmented data without detecting its true nature. These hosts process ICMP error messages containing embedded data fragments, temporarily storing them in memory before forwarding to the next host in the chain. The intermediary hosts mask the data's origin and existence while extending storage duration through their participation in the covert storage network.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If standard TCP/IP protocols are used for data transmission, then network compatibility and communication reliability are maintained, but no covert storage capability is provided

Engineering Contradiction:
Improvenetwork protocol compatibilityVSAvoidcovert storage capability
Core Design Contradiction:
Adaptability or versatilityVSDifficulty of detecting and measuring

Solution Approach 1:

Standard TCP/IP protocols and ICMP error messages are used to perform multiple functions: normal error reporting and covert data transmission simultaneously. The same protocol infrastructure that provides universal network compatibility also enables hidden storage capabilities through clever embedding of data within legitimate protocol messages, achieving both compatibility and secrecy without requiring alternative protocols.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent converts the potentially harmful or unwanted ICMP error messages into beneficial covert storage vehicles. Instead of treating error messages as noise or disturbances to be filtered, the system embeds valuable data within them, transforming what could be considered protocol overhead or error handling into a useful storage mechanism that maintains compatibility while providing hidden capabilities.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

3Difficulty of detecting and measuring

If data is stored in blind hosts waiting for reassembly, then covert storage is achieved, but network bandwidth is consumed and hosts experience increased memory usage

Engineering Contradiction:
Improvecovert storageVSAvoidnetwork bandwidth and host memory resources
Core Design Contradiction:
Difficulty of detecting and measuringVSQuantity of substance

Solution Approach 1:

The system uses periodic ICMP error messages to transmit fragmented data through the network. Each error message represents a periodic transmission event that carries a portion of the stored data. This periodic action allows blind hosts to forward fragments sequentially, managing memory resources by processing and forwarding data in discrete time intervals rather than holding entire datasets in memory simultaneously.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

Data is divided into small fragments embedded within individual ICMP error messages, reducing the memory burden on each blind host. Each host only needs to store and process one fragment at a time rather than entire datasets, minimizing memory usage while still achieving covert storage. The segmentation also reduces network bandwidth consumption per message, as each carries only a portion of the total data.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11055166B2Covertly storing a payload of data within a network
Publication Date: 2021.07.06 RANKIN LABS LLC
  • US11055166B2 patent drawing
  • US11055166B2 patent drawing

AI summary

Systems and methods for storing a covert payload of data within a network are provided. A datagram is generated at an origin host comprising the covert payload of data, a more fragments flag indicating that the datagram is part of a larger transmission, a source address for a confederate host, and a destination address for a blind host. The datagram is transmitted from the origin host to the blind host. When no further datagrams are received, the blind host sends an error message with the covert payload of data to the confederate host. This may be repeated across a number of blind and confederate hosts to form a ring.