Tobias Schmidbauer

dblp:246/5606 · DBLP profile ↗
← Back
9ranked-venue papers
5as first author
7since 2021 · last 2025
0000-0001-5912-0857ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 9 · 5 first-author · 7 since 2021
YearPublicationVenuePosition
2025 DYST (Did You See That?): An Amplified Covert Channel That Points To Previously Seen Data
abstract
Covert channels are stealthy communication channels that enable manifold adversary and legitimate scenarios, ranging from stealthy malware communications to the exchange of confidential information by journalists. We present DYST, which represents a new class of covert channels we callhistory covert channelsjointly with the new paradigm of covert channelamplification. All covert channels described until now need to craft seemingly legitimate flows or need to modify third-party flows, mimicking unsuspicious behavior. In contrast, history covert channels can communicate bypointingtounaltered legitimatetraffic created by regular network nodes. Only a negligible fraction of the covert communication process requires the transfer of actual covert channel information by the covert channel's sender. This information can be sent through different protocols/channels. Our methodology allows anamplificationof the covert channel's message size, i.e., minimizing the fraction ofactually transferredsecret data by a covert channel's sender in relation to theoverallsecret data being exchanged. Further, we extend the current taxonomy for covert channels to show how history channels can be categorized. We describe multiple scenarios in which history covert channels can be realized, analyze the characteristics of these channels, and show how their configuration can be optimized.
Steffen Wendzel, Tobias Schmidbauer, Sebastian Zillien, Jörg Keller 0001
IEEE Trans. Dependable Secur. Comput.2
2024 A Case Study on the Detection of Hash-Chain-based Covert Channels Using Heuristics and Machine Learning
abstract
Reversible network covert channels restore the original carrier object before forwarding it to the overt receiver, drawing them a security threat hard to detect. Some of these covert channels utilize computational intensive operations, such as the calculation of cryptographic hashes. This paper proposes utilizing shape analysis of packet runtime distributions to detect such computational intensive covert channels. To this end, we simulated the latency of covert channel-modified traffic by adding mock hash-reconstruction delays to runtimes of legitimate ping traffic. After qualitatively observing the changes in the empirical probability distribution between modified and natural traffic, we investigated machine learning algorithms for their ability to detect such covert channels. Our results show that a decision tree-based AdaBoost classifier and a CNN using the investigated statistical measures as input vector are able to classify sets of 50 ping measurements with high accuracy. Our approach is superior over previous work on the detection of computational intensive covert channels as it requires smaller sampling window sizes, achieves significantly higher detection rates, and thus draws detection more reliable with fewer preparation.
Jeff Schymiczek, Tobias Schmidbauer, Steffen Wendzel
ARES2
2024 A Comprehensive Pattern-based Overview of Stegomalware
abstract
In recent years, malware increasingly applies steganography methods to remain undetected as long as possible. Such malware is called stegomalware. Stegomalware not only covers its tracks on the infected system, but also hides its communication with adversary infrastructure. This paper reviews 106 stegomalware cases on the basis of 133 reports, including digital media (audio, video, images), text, and network steganography. For this purpose, the steganography methods used by the malware are categorized and introduced using a pattern-based approach. Our survey reveals that solely a small set of patterns are employed by known malware samples. We also analyzed the commonalities of media-, text-, and network-based stegomalware. We show that only a small variation of network protocols, media types and hiding methods are utilized by stegomalware. For this reason, research may focus on these to counter malicious activities covered by steganography.
Fabian Strachanski, Denis Petrov 0001, Tobias Schmidbauer, Steffen Wendzel
ARES3
2024 Look What's There! Utilizing the Internet's Existing Data for Censorship Circumvention with OPPRESSION
abstract
An ongoing challenge in censorship circumvention is optimizing the stealthiness of communications, enabled by covert channels. Recently, a new variant called history covert channels has been proposed. Instead of modifying or mimicking legitimate data, such channels solely point to observed data matching secret information. This approach reduces the amount of secret data a sender explicitly must transfer and thus limits detectability. However, the only published history channel is only suitable for special scenarios due to severe limitations in terms of bandwidth. We propose a significant performance enhancement of history covert channels that allows their use in real-world scenarios through utilizing the content of online social media and online archives. Our approach, which we call OPPRESSION (Open-knowledge Compression), takes advantage of the massive amounts of textual data on the Internet that can be referenced by short pointer messages. Broadly, OPPRESSION can be considered a novel encoding strategy for censorship circumvention.
Sebastian Zillien, Tobias Schmidbauer, Mario Kubek, Jörg Keller 0001, Steffen Wendzel
AsiaCCS2
2022 Challenging Channels: Encrypted Covert Channels within Challenge-Response Authentication
abstract
Challenge-response authentication is an essential and omnipresent network service. Thus, it is a lucrative target for attackers to transport covert information. We present two covert channels in nonce-based network authentication that allow the encrypted transfer of covert information. Both channels exploit fundamental problems, not contained to the specific implementation or cryptographic mechanisms. We provide implementations and evaluations for hash- and key-based challenge-response authentication. Our implementation achieves hard detectability and acceptable throughput rates. Further, we analyze how the throughput can be maximized by applying compression and codebook techniques. We also describe how the presented approach is suitable for the extraction of sensitive information and performing command-and-control communication, showcased by the exfiltration of three different malware code snippets. Further, we discuss potential countermeasures, that can detect, limit and eliminate the proposed covert channels.
Tobias Schmidbauer, Jörg Keller 0001, Steffen Wendzel
ARES1
2022 SoK: A Survey Of Indirect Network-level Covert Channels
abstract
Within the last few years, indirect network-level covert channels have experienced a renaissance with new ideas and evolving concepts. Logical network separation may now be crossed and the sending and receiving activities can be performed with temporal distance between sending and receiving operations. Despite these new developments, all indirect network covert channels share certain basic principles that allow a categorization. So far, the concepts of indirect network-level covert channels have never been systematized. In this paper, we introduce a taxonomy containing indirect covert channel patterns that allow a differentiated analysis of all known indirect network-level covert channels. We introduce additional definitions to unify the understanding of the domain and further identify crucial features of indirect covert channels to make them comparable and describable. We further discuss application scenarios as well as potential and already evaluated countermeasures against indirect covert channels. Further, we discuss observable trends and anticipated future developments in the research area of indirect network-level covert channels.
Tobias Schmidbauer, Steffen Wendzel
AsiaCCS1
2021 Hunting Shadows: Towards Packet Runtime-based Detection Of Computational Intensive Reversible Covert Channels
abstract
The appearance of novel ideas for network covert channels leads to an urge for developing new detection approaches. One of these new ideas are reversible network covert channels that are able to restore the original overt information without leaving any direct evidence of their appearance. Some of these reversible covert channels are based upon computational intensive operations, like for example encoding hidden information in the authentication hashes of a hash chain based one-time password. For such a covert channel implementation, the hash function has to be called repeatedly to extract the hidden message and to restore the original information.
Tobias Schmidbauer, Steffen Wendzel
ARES1
2020 Covert storage caches using the NTP protocol
abstract
Recently, new methods were discovered to secretly store information in network protocol caches by exploiting functionalities of ARP and SNMP. Such a covert storage cache is referred to as a "Dead Drop". In our present research, we demonstrate that hidden information can also be stored on systems with an active NTP service. We present one method based upon ephemeral associations and one method based upon the most recently used (MRU) list and measure their storage duration and capacity. Our approach improves over the previous approach with ARP as it allows to transport hidden information across the internet and thus outside of local area networks. The preliminary results for both Dead Drops indicate that more than 100 entries with secret data can persist for several hours. Finally, we discuss the detectability and countermeasures of the proposed methods as well as their limitations.
Tobias Schmidbauer, Steffen Wendzel
ARES1
2019 Introducing Dead Drops to Network Steganography using ARP-Caches and SNMP-Walks
abstract
Network covert channels enable various secret data exchange scenarios among two or more secret parties via a communication network. The diversity of the existing network covert channel techniques has rapidly increased due to research during the last couple of years and most of them share the same characteristics, i.e., they require a direct communication between the participating partners. However, it is sometimes simply not possible or it can raise suspicions to communicate directly. That is why, in this paper we introduce a new concept we call "dead drop", i.e., a covert network storage which does not depend on the direct network traffic exchange between covert communication sides. Instead, the covert sender stores secret information in the ARP (Address Resolution Protocol) cache of an unaware host that is not involved in the hidden data exchange. Thus, the ARP cache is used as a covert network storage and the accumulated information can then be extracted by the covert receiver using SNMP (Simple Network Management Protocol).
Tobias Schmidbauer, Steffen Wendzel, Aleksandra Mileva, Wojciech Mazurczyk
ARES1