Repository logo

Air-Gap Covert Channels

dc.contributor.authorCarrara, Brent
dc.contributor.supervisorAdams, Carlisle
dc.date.accessioned2016-09-01T18:16:48Z
dc.date.available2016-09-01T18:16:48Z
dc.date.issued2016
dc.description.abstractA fresh perspective on covert channels is presented in this work. A new class, air-gap covert channels, is defined as an unintentional communication channel established between systems that are physically and electronically isolated from one another. A specific class of air-gap covert channel is studied in depth, out-of-band covert channels (OOB-CCs), which are defined as policy-breaking communication channels established between isolated, physically unmodified systems. It is shown that OOB-CCs can be categorized by the physical channel that they communicate over: acoustic, light, seismic, magnetic, thermal, and radio-frequency, and the hardware that is required at the transmitter and receiver to make covert communication possible. In general, OOB-CCs are not as high-bandwidth as conventional radio-frequency channels; however, they are capable of leaking sensitive information that requires low data rates to communicate (e.g., text, recorded audio, cryptographic key material). The ability for malware to communicate information using a specific type of OOB-CC, the covert-acoustic channel, is also analyzed. It is empirically demonstrated that using physically unmodified, commodity systems (e.g., laptops, desktops, and mobile devices), covert-acoustic channels can be used to communicate at data rates of hundreds of bits per second, without being detected by humans in the environment, and data rates of thousands of bits per second when nobody is around to hear the communication. Defence mechanisms to counter covert-acoustic channels are also proposed and evaluated, and, as a result, best practices for the designers of secure systems and secure facilities are presented. Additionally, the covertness of OOB-CCs, i.e., the amount of data that can be leaked before the channel is detected, is also determined for classical communication channels as well as for covert-acoustic channels.en
dc.identifier.urihttp://hdl.handle.net/10393/35103
dc.identifier.urihttp://dx.doi.org/10.20381/ruor-5209
dc.language.isoenen
dc.publisherUniversité d'Ottawa / University of Ottawaen
dc.subjectcovert channelsen
dc.subjectout-of-band covert channelsen
dc.subjectair-gap covert channelsen
dc.subjectdetectable covert channelsen
dc.subjectundetectable covert channelsen
dc.subjectsecure undetectable covert channelsen
dc.subjectcovert-acoustic channelsen
dc.subjectsteganographic capacityen
dc.titleAir-Gap Covert Channelsen
dc.typeThesisen
thesis.degree.disciplineGénie / Engineeringen
thesis.degree.levelDoctoralen
thesis.degree.namePhDen
uottawa.departmentScience informatique et génie électrique / Electrical Engineering and Computer Scienceen

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail ImageThumbnail Image
Name:
Carrara_Brent_2016_thesis.pdf
Size:
11.67 MB
Format:
Adobe Portable Document Format
Description:
Thesis

License bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail ImageThumbnail Image
Name:
license.txt
Size:
6.65 KB
Format:
Item-specific license agreed upon to submission
Description: