首页 | 官方网站   微博 | 高级检索  
     

SSL协议隐蔽通道的研究与实现
引用本文:杨皓云,王俊峰,刘嘉勇,唐彰国.SSL协议隐蔽通道的研究与实现[J].计算机工程与应用,2020,56(20):67-72.
作者姓名:杨皓云  王俊峰  刘嘉勇  唐彰国
作者单位:1.四川大学 网络空间安全学院,成都 610065 2.四川大学 计算机学院,成都 610065 3.四川师范大学 物理与电子工程学院,成都 610066
摘    要:为提升隐蔽通道的网络穿透能力及抗分析性能,提出了一种基于SSL安全协议的新型隐蔽通道。通过SSL握手报文的随机数字段建立隐蔽域,利用SSL握手协商构建消息通道,采用一包一密进行流量变形伪装,通过访问HTTPS服务实现网络隐蔽通道传输。在多种不同HTTPS环境下的实验验证了该方法的可行性,测试结果表明,相比传统存储型隐蔽通道,该隐蔽信道的容量有大幅度提高,单个报文可携带28 Byte信息,且具有更高的抗隐蔽域估计及抗统计画像能力。

关 键 词:安全套接层(SSL)  隐蔽通道  握手协商  超文本安全传输协议(HTTPS)  

Research and Implementation of Covert Channel of SSL Protocol
YANG Haoyun,WANG Junfeng,LIU Jiayong,TANG Zhangguo.Research and Implementation of Covert Channel of SSL Protocol[J].Computer Engineering and Applications,2020,56(20):67-72.
Authors:YANG Haoyun  WANG Junfeng  LIU Jiayong  TANG Zhangguo
Affiliation:1.College of Cybersecurity, Sichuan University, Chengdu 610065, China 2.College of Computer Science, Sichuan University, Chengdu 610065, China 3.School of Physics and Electronic Engineering, Sichuan Normal University, Chengdu 610066, China
Abstract:In order to improve the network penetration capability and anti-analytic performance of the covert channel, a new covert channel based on SSL security protocol is proposed. The covert field is established through the random number field of the SSL handshake packet, and a message channel is constructed using SSL handshake negotiation. One packet uses one secret key to implement traffic deformation camouflage. The network covert channel transmission is realized by accessing the HTTPS service. Experiments in a variety of different HTTPS environments verify the feasibility of the proposed method. The experimental results show that the capacity of the covert channel is greatly improved compared with the traditional storage covert channel, and a single packet can carry 28 Byte of information. The SSL covert channel has higher anti-hidden domain estimation and anti-statistical image ability.
Keywords:Secure Sockets Layer(SSL)  covert channel  handshake negotiation  Hypertext Transfer Protocol Secure(HTTPS)  
本文献已被 万方数据 等数据库收录!
点击此处可从《计算机工程与应用》浏览原始摘要信息
点击此处可从《计算机工程与应用》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司    京ICP备09084417号-23

京公网安备 11010802026262号