login

Practical Data Hiding in TCP/IP

Published 1 January 2002
Kamran Ahsan, Deepa Kundur
Citations226

TL;DR

By passing supplementary information through IPv4 headers it is demonstrated how security mechanisms can be enhanced in routers, firewalls, and for services such as authentication, audit and logging without considerable additions to software or hardware.

Abstract

This work relates the areas of steganography, network protocols and security for practical data hiding in communication networks employing TCP/IP. Two approaches are proposed based on packet header manipulation and packet ordering within the IPSec framework. For the former the Internet protocol IPv4 header is analyzed to identify covert channels by exploiting redundancy and multiple interpretations of protocol strategies; by passing supplementary information through IPv4 headers we demonstrate how security mechanisms can be enhanced in routers, firewalls, and for services such as authentication, audit and logging without considerable additions to software or hardware. For the latter approach, we show the use of packet sorting for steganographic embedding with IPSec can allow for enhanced network security.

Keywords

Computer Science