Exploiting the IoT Through Network-based Covert Channels

Abstract

Information leaks are a top concern to industry and government leaders. The IoT is a technology capable of sensing real-world events. A method for exfiltrating data from these devices is by covert channel. This research designs a novel IoT CTC without the need for inter-packet delays to encode data. Instead, it encodes data within preexisting network information, namely ports or addresses. Additionally, the CTC can be implemented in two different modes: Stealth and Bandwidth. Performance is measured using throughput and detectability. The Stealth methods mimic legitimate traffic captures while the Bandwidth methods forgo this approach for maximum throughput. Detection results are presented using shape and regularity-based detection tests. The Stealth results have a throughput of 4.61 bits per second (bps) for TCP /IP and 3.90 bps for ZigBee. They also evade shape and regularity-based detection tests. The Bandwidth methods average 81.7 Kbps for TCP/IP and 9.76 bps for ZigBee, but are evident in detection tests.

Open PDF

Document Details

Document Type
Technical Report
Publication Date
Mar 24, 2022
Accession Number
AD1166896

Entities

People

  • Kyle S. Harris

Organizations

  • Air Force Institute of Technology

Tags

Communities of Interest

  • Cyber
  • Energy and Power Technologies
  • Sensors

DTIC Thesaurus Topics

  • Air Force
  • Cloud Computing
  • Coding
  • Computer Communications
  • Computer Networks
  • Data Analysis
  • Data Links
  • Department Of Defense
  • Detection
  • Engineering
  • Information Science
  • Information Systems
  • Internet Of Things
  • Intrusion Detection
  • Intrusion Detectors
  • Local Area Networks
  • Network Protocols
  • Network Science
  • Personal Area Networks
  • Transport Protocols
  • Wireless Communications

Fields of Study

  • Computer science

Readers

  • Computer Networking
  • Cybersecurity.
  • Radio communications and signal processing.

Technology Areas

  • 5G
  • 5G - Internet of Things