Abstract <p>Methods of protection against memory-based covert channels in the TLS protocol, which use the Random and SessionID service fields of the ClientHello message, are proposed. Protection tools implementing the proposed methods are developed: a module for the Suricata IDS/IPS that filters TLS packets depending on the contents of the SessionID service field, and a proxy server that reformats packets transmitted into the communication environment. A comparative analysis of the implemented security tools is carried out in terms of their impact on the communication channel throughput and their effectiveness in countering the transmission of confidential information. The developed protection tools can be implemented into existing systems for protection against network covert channels. Recommendations are provided for the application of the proposed protection mechanisms, depending on the desired level of security.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Memory-Based Covert Channels in the TLS Protocol

  • M. A. Finoshin,
  • I. D. Ivanova,
  • I. Yu. Zhukov,
  • A. V. Zuikov

摘要

Abstract

Methods of protection against memory-based covert channels in the TLS protocol, which use the Random and SessionID service fields of the ClientHello message, are proposed. Protection tools implementing the proposed methods are developed: a module for the Suricata IDS/IPS that filters TLS packets depending on the contents of the SessionID service field, and a proxy server that reformats packets transmitted into the communication environment. A comparative analysis of the implemented security tools is carried out in terms of their impact on the communication channel throughput and their effectiveness in countering the transmission of confidential information. The developed protection tools can be implemented into existing systems for protection against network covert channels. Recommendations are provided for the application of the proposed protection mechanisms, depending on the desired level of security.