摘要: 現(xiàn)有存儲(chǔ)型網(wǎng)絡(luò)隱蔽信道的研究主要根據(jù)不同協(xié)議中不同字段來(lái)隱藏信息。在眾多協(xié)議中,例如TCP、UDP協(xié)議,對(duì)其研究較多,而OSFP使用廣泛卻在國(guó)內(nèi)研究較少。針對(duì)OSPF協(xié)議下的Hello報(bào)文進(jìn)行分析可以構(gòu)建網(wǎng)絡(luò)隱蔽信道的字段。從所有可能字段中選擇Authentication、Router Dead Interval和Neighbor三個(gè)字段分別使用隨機(jī)值模式、值調(diào)制模型和序列模式進(jìn)行構(gòu)建三種隱蔽信道,利用微協(xié)議技術(shù)優(yōu)化信道,并將三種隱蔽信道組合成一個(gè)傳輸速率更高的隱蔽信道模型。經(jīng)過(guò)驗(yàn)證,該模型具有一定的可行性和隱蔽性,可為存儲(chǔ)型網(wǎng)絡(luò)隱蔽信道構(gòu)建技術(shù)提供一定的理論支持和技術(shù)支撐。
Research on construction of covert channels based on OSPF protocol Hello packet
Zhao Ziqiang1, Li Qiang2, Guo Tao1
1 School of Electronic Information, Anhui Jianzhu University, Hefei 230022, China; 2 Southwest Jiaotong University Shenzhen Research Institute,Xi′an 710000, China
Abstract: The existing network covert channels in the storage category mainly rely on the characteristics of different fields in different protocols. Although many protocols such as TCP and UDP have been extensively studied, OSFP is widely used but less researched in China. This paper analyzes the Hello message under the OSPF protocol to construct the fields of network covert channels. Three covert channels are constructed using three fields selected from all possible fields, namely Authentication, RouterDeadInterval, and Neighbor, respectively, by adopting random value pattern, value modulation model, and sequence pattern. Channel optimization is achieved by applying microprotocol technology. Finally, the three covert channels are combined into a higher transmission rate covert channel model. Verification shows that this model has certain feasibility and concealment, can provide theoretical support and technical support for the construction of storagetype network covert channels.