pith. sign in

arxiv: 1703.02201 · v1 · pith:ZP6T4JHTnew · submitted 2017-03-07 · 💻 cs.CR

A Covert Data Transport Protocol

classification 💻 cs.CR
keywords datadomainnamesencryptedinformationsourcetransportalgorithm
0
0 comments X
read the original abstract

Both enterprise and national firewalls filter network connections. For data forensics and botnet removal applications, it is important to establish the information source. In this paper, we describe a data transport layer which allows a client to transfer encrypted data that provides no discernible information regarding the data source. We use a domain generation algorithm (DGA) to encode AES encrypted data into domain names that current tools are unable to reliably differentiate from valid domain names. The domain names are registered using (free) dynamic DNS services. The data transmission format is not vulnerable to Deep Packet Inspection (DPI).

This paper has not been read by Pith yet.

discussion (0)

Sign in with ORCID, Apple, or X to comment. Anyone can read and Pith papers without signing in.