Detecting covert channels within VoIP

Document Type

Conference Proceeding

Publication Date

7-30-2012

Abstract

VoIP (Voice Over IP) was ranked third among the top 11 technologies of the decade in 2011. It is one of the most popular networking services. As it is readily adopted, the VoIP traffic is increasing steadily. The large amount of data transported by VoIP makes it ideal for creating covert channels. Attacks based on covert channels becomes a new challenge for network security. In this paper, possible covert channels via VoIP are analyzed, and an effective countermeasure to detect hidden messages in both SEQ (Sequence Number) and SSRC (Source Identifier) fields in the RTP protocol during conversation phase is proposed. This proposed method creates a new processing space, in which, normal traffic is analyzed and characterized by a proposed statistical model. This model is used in detecting hidden information in SSRCs and SEQs. Simulation results show that 100% detection rate can be realized. As the proposed model requires only a small amount of training data and no illegal traffic is used in the training, the computational complexity is small and can be used for on-line covert channel detection. © 2012 IEEE.

Identifier

84864184012 (Scopus)

ISBN

[9781467314640]

Publication Title

35th IEEE Sarnoff Symposium Sarnoff 2012 Conference Proceedings

External Full Text Location

https://doi.org/10.1109/SARNOF.2012.6222709

This document is currently not available here.

Share

COinS