ICMP Error Message Covert Data Storage and Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing communication protocols, such as TCP/IP, lack effective mechanisms for covertly storing data within a network without revealing the origin or existence of the data, and detecting such covert storage techniques.
Innovation Solution
The system employs a 'blind host' that generates ICMP error messages to store and transmit data payloads, utilizing a ring of confederate hosts to extend storage duration indefinitely while maintaining the covert nature of the data, and monitors for patterns of digital behavior to detect and eliminate covertly stored packets.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If TCP/IP protocols are used for data transmission, then reliable communication between network devices is achieved, but the protocols lack mechanisms for covertly storing data without revealing origin or existence
Solution Approach 1:
The patent introduces an intermediary mechanism using ICMP error messages as a carrier for covert data transmission. The ICMP protocol serves as a mediator that allows data to be embedded within error message packets, enabling covert storage while using standard TCP/IP infrastructure. This resolves the contradiction by adding adaptability through the intermediary ICMP channel without compromising TCP/IP communication reliability.
Solution Approach 2:
The patent changes the parameter of data embedding by storing payload data within ICMP error message fields rather than using traditional data transmission channels. This parameter change allows the same network infrastructure to serve dual purposes: reliable TCP/IP communication and covert data storage, thereby resolving the contradiction between reliability and adaptability.
2Difficulty of detecting and measuring
If data is covertly stored using ICMP error messages, then data origin and existence become difficult to detect, but detection mechanisms are needed to identify and eliminate such covert storage
Solution Approach 1:
The patent implements a feedback mechanism where monitoring systems detect patterns of ICMP error messages that indicate covert storage, and this detection information feeds back to security systems for analysis and response. This resolves the contradiction by providing controlled detectability through feedback loops that maintain covert operation while enabling security monitoring when anomalies are detected.
Solution Approach 2:
The patent applies preliminary anti-action by establishing detection mechanisms that proactively identify covert storage attempts before they can cause security breaches. The monitoring system continuously analyzes ICMP traffic patterns and takes preliminary action to detect and eliminate covert storage, thereby preventing potential security threats while maintaining the covert nature of legitimate operations.
3Duration of action of stationary object
If a ring of confederate hosts is used to extend storage duration indefinitely, then long-term covert storage is achieved, but the system complexity increases
Solution Approach 1:
The patent segments the covert storage function across multiple confederate hosts arranged in a ring topology, where each host maintains a portion of the storage responsibility. This segmentation allows indefinite storage duration by distributing data across the ring while managing complexity through modular architecture, as each host operates independently with standardized protocols.
Solution Approach 2:
The confederate hosts in the ring serve multiple functions: they act as both storage nodes and forwarding relays, and can dynamically assume different roles based on network conditions. This multi-functionality reduces overall system complexity by eliminating the need for dedicated storage and management infrastructure, as standard network hosts can participate in the covert storage ring.
Data Source
AI summary
System and methods for detecting covert payloads of data within an IP network are provided. Activity of at least a portion of the IP network is monitored for datagrams comprising error messages. A selection of the datagrams including the error messages occurring with a regularity above a predetermined threshold are identified.


