| Literature DB >> 32344534 |
Shorouq Al-Eidi1, Omar Darwish2, Yuanzhu Chen1.
Abstract
Covert timing channels are an important alternative for transmitting information in the world of the Internet of Things (IoT). In covert timing channels data are encoded in inter-arrival times between consecutive packets based on modifying the transmission time of legitimate traffic. Typically, the modification of time takes place by delaying the transmitted packets on the sender side. A key aspect in covert timing channels is to find the threshold of packet delay that can accurately distinguish covert traffic from legitimate traffic. Based on that we can assess the level of dangerous of security threats or the quality of transferred sensitive information secretly. In this paper, we study the inter-arrival time behavior of covert timing channels in two different network configurations based on statistical metrics, in addition we investigate the packet delaying threshold value. Our experiments show that the threshold is approximately equal to or greater than double the mean of legitimate inter-arrival times. In this case covert timing channels become detectable as strong anomalies.Entities:
Keywords: Internet of Things; computer networks; covert timing channels; information security; inter-arrival times
Year: 2020 PMID: 32344534 PMCID: PMC7219501 DOI: 10.3390/s20082417
Source DB: PubMed Journal: Sensors (Basel) ISSN: 1424-8220 Impact factor: 3.576
Figure 1Scheme of encoding binary symbols to the inter arrival time.
Devices properties.
| PC 1 (Sender) | PC 2 (Receiver) | |
|---|---|---|
| Processor | Intel(R) Core(TM) i5-4210U | Intel(R) Core(TM) i7-6500U |
| CPU speed | 1.70 GHz 2.40 GHz | 2.50 GHz 2.60 GHz |
| RAM | 6.00 GB | 8.00 GB |
| System type | 64-bits | 64-bits |
| Adapter type | Ethernet 802.3 | Ethernet 802.3 |
Network configuration characteristics.
| Network Configuration 1 (Private) | Network Configuration 2 (Public) | |
|---|---|---|
| Internet speed | 52.1 mbps download 15.9 mbps upload | 42.8 mbps download 47.1 mbps upload |
| Latency | 55 ms | 58 ms |
| Router type | Home hub 3000 | D-link |
| Number of hops | 1 | 1 |
| Geographical location | Personal use network | Research lab at Memorial University |
Figure 2Representation of binary symbols in the packet inter-arrival times.
Binary covert packet delays.
| Network Configuration1 | Network Configuration 2 | ||||
|---|---|---|---|---|---|
|
| Zero Delays | One Delays | Zero Delays | Zero Delays | |
|
| 0.025 |
|
|
|
|
|
| 0.500 |
|
|
|
|
|
| 10.00 |
|
|
|
|
|
| 20.00 |
|
|
|
|
|
| 30.00 |
|
|
|
|
Time ranges of binary covert packets in network configuration 1.
|
| Binary Symbol | Binary Delays (Seconds) | Time Range (Seconds) | Probabilities |
|---|---|---|---|---|
|
|
|
|
|
|
|
|
|
|
| |
|
|
|
|
|
|
|
|
|
|
| |
|
|
|
|
|
|
|
|
|
|
| |
|
|
|
|
|
|
|
|
|
|
| |
|
|
|
|
|
|
|
|
|
|
|
Time ranges of binary covert traffic in network configuration 2.
|
| Binary Symbol | Binary Delays (Seconds) | Time Range (Seconds) | Probabilities |
|---|---|---|---|---|
|
|
|
|
|
|
|
|
|
|
| |
|
|
|
|
|
|
|
|
|
|
| |
|
|
|
|
|
|
|
|
|
|
| |
|
|
|
|
|
|
|
|
|
|
| |
|
|
|
|
|
|
|
|
|
|
|
Figure 3Accuracy of distinguishing covert traffic from legitimate traffic.
Figure 4Percentage of data loss at different time windows.
Figure 5Transmitted bit rates of network configuration 1 (left) and network configuration 2 (right).