EDBT 2026 Demo / reviewers in the wild / expert
Steffen Wendzel
dblp:53/3957
· DBLP profile ↗
41ranked-venue papers
10as first author
21since 2021 · last 2026
0000-0002-1913-5912ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 34 · 7 first-author · 19 since 2021Computer networks · 4 · 2 first-author · 1 since 2021Systems, architecture and hardware · 2 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | AdullamoT: Using IoT Devices as Relays for Time-decoupled Secret Exchange & Censorship CircumventionabstractExchanging policy-breaking or critical information is becoming increasingly challenging due to the expansion of network-level censorship and surveillance by repressive regimes around the world. While typical end-user traffic is often analyzed or blocked by censorship systems, the Internet of Things (IoT) leaves underexplored room for aiding the exchange of confidential information and circumventing censors. Steffen Wendzel |
IH&MMSec | 1 |
| 2026 | A survey of internet censorship and its measurement: Methodology, trends, and challengesabstractInternet censorship limits the access of nodes residing within a specific network environment to the public Internet, and vice versa. During the last decade, techniques for conducting Internet censorship have been developed further. Consequently, methodology for measuring Internet censorship had been improved as well. In this paper, we firstly provide a survey of network-level Internet censorship techniques. Secondly, we survey censorship measurement methodology. We further cover the censorship of circumvention tools and its measurement, as well as available datasets. In cases where it is beneficial, we bridge the terminology and taxonomy of Internet censorship with related domains, namely traffic obfuscation and information hiding. We further extend the technical perspective with recent trends and challenges, including human aspects of Internet censorship. Steffen Wendzel, Simon Volpert, Sebastian Zillien, Julia Lenz, Philip Rünz, Luca Caviglione |
Comput. Secur. | 1 |
| 2026 | History covert channels with relative timing pointers: Design, error resilience, and detectabilityabstractA Covert Channel (CC) exploits legitimate communication mechanisms to stealthily transmit information, often bypassing traditional security controls. Within this domain, History Covert Channels (HCC) leverage past network events as reference points to embed covert messages. Unlike traditional timing- or storage-based CCs, which directly manipulate traffic patterns or packet contents, HCCs minimize detectability by encoding information through small pointers to historical data. This approach enables them to amplify the size of transmitted covert data by referring to more bits than are actually embedded. Recent research has explored the feasibility of such methods, demonstrating their potential to evade detection by repurposing naturally occurring network behaviors as a covert transmission medium. However, existing timing channels rely heavily on precise absolute timing and centralized clock synchronization, limiting their robustness in real-world distributed environments. In this paper, we introduce the Silent History Protocol (SHP), a robust HCC architecture that utilizes relative pointers to network timing patterns. By referencing time deltas rather than absolute timestamps, SHP minimizes reliance on centralized timekeeping and enhances resilience against network jitter. We present a prototype implementation using ARP signaling and conduct a trace-based feasibility analysis for WAN environments. Furthermore, we explore error correction mechanisms to tailor SHP for noisy channels. Our experiments demonstrate improved bitrate and robustness compared to previous HCC implementations, while maintaining statistical undetectability against standard network monitoring tools. Christoph Weissenborn, Steffen Wendzel |
J. Inf. Secur. Appl. | 2 |
| 2025 | Domainator: Detecting and Identifying DNS-Tunneling Malware Using Metadata SequencesabstractAbstract For a few years, malware with tunneling (or: covert channel) capabilities has been on the rise. While malware research led to several methods and innovations, the detection and differentiation of malware solely based on its DNS tunneling features is still in its infancy. Moreover, no work so far has used the DNS tunneling traffic to gain knowledge over the current actions taken by the malware. In this paper, we present , an approach to detect and differentiate state-of-the-art malware and DNS tunneling tools without relying on trivial (but quickly altered) features such as “magic bytes” that are embedded into subdomains. Instead, we apply an analysis of sequential patterns to identify specific types of malware. We evaluate our approach with 7 real-world malware samples and tunneling tools and can identify the particular malware based on its DNS traffic. We further infer the rough behavior of the particular malware through its DNS tunneling artifacts. Finally, we compare our with related methods. Denis Petrov 0001, Pascal Ruffing, Sebastian Zillien, Steffen Wendzel |
ARES (1) | 4 |
| 2025 | DYST (Did You See That?): An Amplified Covert Channel That Points To Previously Seen DataabstractCovert channels are stealthy communication channels that enable manifold adversary and legitimate scenarios, ranging from stealthy malware communications to the exchange of confidential information by journalists. We present DYST, which represents a new class of covert channels we callhistory covert channelsjointly with the new paradigm of covert channelamplification. All covert channels described until now need to craft seemingly legitimate flows or need to modify third-party flows, mimicking unsuspicious behavior. In contrast, history covert channels can communicate bypointingtounaltered legitimatetraffic created by regular network nodes. Only a negligible fraction of the covert communication process requires the transfer of actual covert channel information by the covert channel's sender. This information can be sent through different protocols/channels. Our methodology allows anamplificationof the covert channel's message size, i.e., minimizing the fraction ofactually transferredsecret data by a covert channel's sender in relation to theoverallsecret data being exchanged. Further, we extend the current taxonomy for covert channels to show how history channels can be categorized. We describe multiple scenarios in which history covert channels can be realized, analyze the characteristics of these channels, and show how their configuration can be optimized. Steffen Wendzel, Tobias Schmidbauer, Sebastian Zillien, Jörg Keller 0001 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2024 | Robust and Homomorphic Covert Channels in Streams of Numeric DataabstractA steganographic network storage channel that uses a carrier with a stream of numeric data must consider the possibility that the carrier data is processed before the covert receiver can extract the secret data. A sensor data stream, which we take as an example scenario, may be scaled by multiplication, shifted into a different range by addition, or two streams might be merged by adding their values. This raises the question if the storage channel can be made robust against such carrier modifications. On the other hand, if the pieces of secret data are numeric as well, adding and merging two streams each comprising covert data might be exploited to form a homomorphic covert channel. We investigate both problems as they are related and give positive and negative results. In particular, we present the first homomorphic storage covert channel. Moreover, we show that such type of covert channel is not restricted to sensor data streams, but that very different scenarios are possible. Jörg Keller 0001, Carina Heßeling, Steffen Wendzel |
ARES | 3 |
| 2024 | A Case Study on the Detection of Hash-Chain-based Covert Channels Using Heuristics and Machine LearningabstractReversible network covert channels restore the original carrier object before forwarding it to the overt receiver, drawing them a security threat hard to detect. Some of these covert channels utilize computational intensive operations, such as the calculation of cryptographic hashes. This paper proposes utilizing shape analysis of packet runtime distributions to detect such computational intensive covert channels. To this end, we simulated the latency of covert channel-modified traffic by adding mock hash-reconstruction delays to runtimes of legitimate ping traffic. After qualitatively observing the changes in the empirical probability distribution between modified and natural traffic, we investigated machine learning algorithms for their ability to detect such covert channels. Our results show that a decision tree-based AdaBoost classifier and a CNN using the investigated statistical measures as input vector are able to classify sets of 50 ping measurements with high accuracy. Our approach is superior over previous work on the detection of computational intensive covert channels as it requires smaller sampling window sizes, achieves significantly higher detection rates, and thus draws detection more reliable with fewer preparation. Jeff Schymiczek, Tobias Schmidbauer, Steffen Wendzel |
ARES | 3 |
| 2024 | A Comprehensive Pattern-based Overview of StegomalwareabstractIn recent years, malware increasingly applies steganography methods to remain undetected as long as possible. Such malware is called stegomalware. Stegomalware not only covers its tracks on the infected system, but also hides its communication with adversary infrastructure. This paper reviews 106 stegomalware cases on the basis of 133 reports, including digital media (audio, video, images), text, and network steganography. For this purpose, the steganography methods used by the malware are categorized and introduced using a pattern-based approach. Our survey reveals that solely a small set of patterns are employed by known malware samples. We also analyzed the commonalities of media-, text-, and network-based stegomalware. We show that only a small variation of network protocols, media types and hiding methods are utilized by stegomalware. For this reason, research may focus on these to counter malicious activities covered by steganography. Fabian Strachanski, Denis Petrov 0001, Tobias Schmidbauer, Steffen Wendzel |
ARES | 4 |
| 2024 | Look What's There! Utilizing the Internet's Existing Data for Censorship Circumvention with OPPRESSIONabstractAn ongoing challenge in censorship circumvention is optimizing the stealthiness of communications, enabled by covert channels. Recently, a new variant called history covert channels has been proposed. Instead of modifying or mimicking legitimate data, such channels solely point to observed data matching secret information. This approach reduces the amount of secret data a sender explicitly must transfer and thus limits detectability. However, the only published history channel is only suitable for special scenarios due to severe limitations in terms of bandwidth. We propose a significant performance enhancement of history covert channels that allows their use in real-world scenarios through utilizing the content of online social media and online archives. Our approach, which we call OPPRESSION (Open-knowledge Compression), takes advantage of the massive amounts of textual data on the Internet that can be referenced by short pointer messages. Broadly, OPPRESSION can be considered a novel encoding strategy for censorship circumvention. Sebastian Zillien, Tobias Schmidbauer, Mario Kubek, Jörg Keller 0001, Steffen Wendzel |
AsiaCCS | 5 |
| 2023 | Why people replace their aging smart devices: A push-pull-mooring perspectiveabstractDuring the last decade, the Internet of Things (IoT) has become a central enabler for technological developments and services, such as ambient assisted living and localization services. Billions of smart devices have been sold, with many aged devices still in use today. In several cases, such aged smart devices do not receive security updates after some time of operation, making them a threat to the privacy of end-users. For this reason, it is crucial to understand driving factors for users to keep older devices as well as factors that lead to device switches, which can be considered as a security measure against cyber threats in this context. In this paper, we analyze what factors people associate with replacing older smart devices with newer ones as a way to mitigate the risks linked to aged smart devices. To achieve this, we apply the push-pull-mooring framework to integrate privacy, adoption and switching theories into a unified framework. To empirically validate the framework, we conducted an online survey among N=513 owners of older smart devices (i.e., purchased more than a year ago) from the UK through the Prolific platform. The results of our study show that perceived usefulness of new devices was strongly associated with switching intention. These results offer only limited support for technology adoption theories, as switching intention was not associated with other adoption constructs (pull factors). Privacy concern regarding improper access to personal information collected by an older smart device and switching costs (a push and a mooring factor, respectively) were also associated with switching costs. The results also indicate support for the moderating role of age of smart device, since the latter associations were not significant for smart devices up to three years old. We also provide some practical implications for manufacturers with a green and sustainable future in mind. Julia Lenz, Zdravko Bozakov, Steffen Wendzel, Simon Vrhovec |
Comput. Secur. | 3 |
| 2023 | Weaknesses of Popular and Recent Covert Channel Detection Methods and a RemedyabstractNetwork covert channels are applied for the secret exfiltration of confidential data, the stealthy operation of malware, and legitimate purposes, such as censorship circumvention. In recent decades, some major detection methods for network covert channels have been developed. In this paper, we investigate two highly cited detection methods for covert timing channels, namely$\epsilon$-similarity and compressibility score from Cabuk et al. (jointly cited by 930 papers and applied by thousands of researchers). We additionally analyze two recent ML-based detection methods:GAS(2022) andSnapCatch(2021). While all these detection methods must be considered valuable for the analysis of typical covert timing channels, we show that these methods are not reliable when a covert channel's behavior is slightly modified. In particular, we demonstrate that when confronted with a simple covert channel that we call$\epsilon$-$\kappa$libur, all detection methods can be circumvented or their performance can be significantly reduced although the covert channel still provides a high bitrate. In comparison to previous timing channels that circumvent these methods,$\epsilon$-$\kappa$libur is much simpler and eliminates the need of altering previously recorded traffic. Moreover, we propose an enhanced$\epsilon$-similarity that can detect the classical covert timing channel as well as$\epsilon$-$\kappa$libur. Sebastian Zillien, Steffen Wendzel |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2022 | Challenging Channels: Encrypted Covert Channels within Challenge-Response AuthenticationabstractChallenge-response authentication is an essential and omnipresent network service. Thus, it is a lucrative target for attackers to transport covert information. We present two covert channels in nonce-based network authentication that allow the encrypted transfer of covert information. Both channels exploit fundamental problems, not contained to the specific implementation or cryptographic mechanisms. We provide implementations and evaluations for hash- and key-based challenge-response authentication. Our implementation achieves hard detectability and acceptable throughput rates. Further, we analyze how the throughput can be maximized by applying compression and codebook techniques. We also describe how the presented approach is suitable for the extraction of sensitive information and performing command-and-control communication, showcased by the exfiltration of three different malware code snippets. Further, we discuss potential countermeasures, that can detect, limit and eliminate the proposed covert channels. Tobias Schmidbauer, Jörg Keller 0001, Steffen Wendzel |
ARES | 3 |
| 2022 | SoK: A Survey Of Indirect Network-level Covert ChannelsabstractWithin the last few years, indirect network-level covert channels have experienced a renaissance with new ideas and evolving concepts. Logical network separation may now be crossed and the sending and receiving activities can be performed with temporal distance between sending and receiving operations. Despite these new developments, all indirect network covert channels share certain basic principles that allow a categorization. So far, the concepts of indirect network-level covert channels have never been systematized. In this paper, we introduce a taxonomy containing indirect covert channel patterns that allow a differentiated analysis of all known indirect network-level covert channels. We introduce additional definitions to unify the understanding of the domain and further identify crucial features of indirect covert channels to make them comparable and describable. We further discuss application scenarios as well as potential and already evaluated countermeasures against indirect covert channels. Further, we discuss observable trends and anticipated future developments in the research area of indirect network-level covert channels. Tobias Schmidbauer, Steffen Wendzel |
AsiaCCS | 2 |
| 2022 | Emerging topics in defending networked systems
Steffen Wendzel, Wojciech Mazurczyk, Luca Caviglione, Amir Houmansadr |
Future Gener. Comput. Syst. | 1 |
| 2021 | Risks and Opportunities for Information Hiding in DICOM StandardabstractThe increasing application of ICT technologies to medicine opens new usage patterns. Among the various standards, the Digital Imaging and COmmunication in Medicine (DICOM) has been gaining momentum, mainly due to its complete coverage of the diagnostic pipeline, including key applications such as CT, MRI and ultrasound scanners. However, owing to its complex and multifaceted nature, DICOM is prone to many risks especially due to the vast and complex attack surface characterizing the composite interplay of services, formats and technologies at the basis of the standard. Luckily, DICOM exhibits some room for improving its security. Specifically, information hiding and steganography can be used in a twofold manner. On one hand, they can help to watermark diagnostic images to improve their resistance against tampering and alterations. On the other hand, the digital infrastructure at the basis of DICOM can lead to data leaks or malicious manipulations via artificial intelligence techniques. Therefore, in this work we introduce risks and opportunities when applying information-hiding-based techniques to the DICOM standard. Our investigation highlights some opportunities as well as introduces possibilities of exploiting DICOM images to set up covert channels, i.e., hidden communication paths that can be used to exfiltrate data or launch attacks. To prove the effectiveness of our vision, this paper also showcases the performance evaluation of a covert channel built by applying text steganography principles on realistic DICOM images. Aleksandra Mileva, Luca Caviglione, Aleksandar Velinov, Steffen Wendzel, Vesna Dimitrova |
ARES | 4 |
| 2021 | Hunting Shadows: Towards Packet Runtime-based Detection Of Computational Intensive Reversible Covert ChannelsabstractThe appearance of novel ideas for network covert channels leads to an urge for developing new detection approaches. One of these new ideas are reversible network covert channels that are able to restore the original overt information without leaving any direct evidence of their appearance. Some of these reversible covert channels are based upon computational intensive operations, like for example encoding hidden information in the authentication hashes of a hash chain based one-time password. For such a covert channel implementation, the hash function has to be called repeatedly to extract the hidden message and to restore the original information. Tobias Schmidbauer, Steffen Wendzel |
ARES | 2 |
| 2021 | Crème de la Crème: Lessons from Papers in Security PublicationsabstractThe number of citations attracted by publications is a key criteria for measuring their success. To avoid discriminating newer research, such a metric is usually measured in average yearly citations. Understanding and characterizing how citations behave have been prime research topics, yet investigations targeting the cybersecurity domain seem to be particularly scarce. In this perspective, the paper aims at filling this gap by analyzing average yearly citations for 6,693 papers published in top-tier conferences and journals in cybersecurity. Results indicate the existence of three clusters, i.e., general security conferences, general security journals, and cryptography-centered publications. The analysis also suggests that the amount of conference-to-conference citations stands out compared to journal-to-journal and conference-to-journal citations. Besides, papers published at top conferences attract more citations although a direct comparison against other venues is not straightforward. To better quantify the impact of works dealing with cybersecurity aspects, the paper introduces two new metrics, namely the number of main words in the title, and the combined number of unique main words in title, abstract and keywords. Collected results show that they can be associated with average yearly citations (together with the number of cited references). Finally, the paper draws some ideas to take advantage from such findings. Simon Vrhovec, Luca Caviglione, Steffen Wendzel |
ARES | 3 |
| 2021 | A Revised Taxonomy of Steganography Embedding PatternsabstractSteganography embraces several hiding techniques which spawn across multiple domains. However, the related terminology is not unified among the different domains, such as digital media steganography, text steganography, cyber-physical systems steganography, network steganography (network covert channels), local covert channels, and out-of-band covert channels. To cope with this, a prime attempt has been done in 2015, with the introduction of the so-called hiding patterns, which allow to describe hiding techniques in a more abstract manner. Despite significant enhancements, the main limitation of such a taxonomy is that it only considers the case of network steganography. Steffen Wendzel, Luca Caviglione, Wojciech Mazurczyk, Aleksandra Mileva, Jana Dittmann, Christian Krätzer, Kevin Lamshöft, Claus Vielhauer, Laura Hartmann, Jörg Keller 0001, Tom Neubert |
ARES | 1 |
| 2021 | Adaptive Warden Strategy for Countering Network Covert Storage ChannelsabstractThe detection and elimination of covert channels are performed by a network node, known as a warden. Especially if faced with adaptive covert communication parties, a regular warden equipped with a static set of normalization rules is ineffective compared to a dynamic warden. However, dynamic wardens rely on periodically changing rule sets and have their own limitations, since they do not consider traffic specifics. We propose a novel adaptive warden strategy, capable of selecting active normalization rules by taking into account the characteristics of the observed network traffic. Our goal is to disturb the covert channel and provoke the covert peers to expose themselves more by increasing the number of packets required to perform a successful covert data transfer. Our evaluation revealed that the adaptive warden has better efficiency and effectiveness when compared to the dynamic warden because of its adaptive selection of normalization rules. Mehdi Chourib, Steffen Wendzel, Wojciech Mazurczyk |
LCN | 2 |
| 2021 | Reconnection-Based Covert Channels in Wireless Networks
Sebastian Zillien, Steffen Wendzel |
SEC | 2 |
| 2021 | Comprehensive analysis of MQTT 5.0 susceptibility to network covert channelsabstractMessage Queuing Telemetry Transport (MQTT) is a publish-subscribe protocol which is currently popular in Internet of Things (IoT) applications. Recently its 5.0 version has been introduced and ensuring that it is capable of providing services in a secure manner is of great importance. It must be noted that holistic security analysis should also evaluate protocol’s susceptibility to network covert channels. That is why in this paper we present a systematic overview of potential data hiding techniques that can be applied to MQTT 5.0. We are especially focusing on network covert channels that, in order to exchange secrets, exploit characteristic features of this MQTT version. Finally, we develop proof-of-concept implementations of the chosen data hiding techniques and conduct their performance evaluation in order to assess their feasibility in practical setups. Aleksandra Mileva, Aleksandar Velinov, Laura Hartmann, Steffen Wendzel, Wojciech Mazurczyk |
Comput. Secur. | 4 |
| 2020 | Covert storage caches using the NTP protocolabstractRecently, new methods were discovered to secretly store information in network protocol caches by exploiting functionalities of ARP and SNMP. Such a covert storage cache is referred to as a "Dead Drop". In our present research, we demonstrate that hidden information can also be stored on systems with an active NTP service. We present one method based upon ephemeral associations and one method based upon the most recently used (MRU) list and measure their storage duration and capacity. Our approach improves over the previous approach with ARP as it allows to transport hidden information across the internet and thus outside of local area networks. The preliminary results for both Dead Drops indicate that more than 100 entries with secret data can persist for several hours. Finally, we discuss the detectability and countermeasures of the proposed methods as well as their limitations. Tobias Schmidbauer, Steffen Wendzel |
ARES | 2 |
| 2020 | Design and performance evaluation of reversible network covert channelsabstractCovert channels nested within network traffic are important tools for allowing malware to act unnoticed or to stealthily exchange and exfiltrate information. Thus, understanding how to detect or mitigate their utilization is of paramount importance, especially to counteract the rise of increasingly sophisticated threats. In this perspective, the literature proposed various approaches, including distributed wardens, which can be used to collect traffic in different portions of the network and compare the samples to check for discrepancies revealing hidden communications. However, the use of some form of reversibility, i.e., being able to restore the exploited network carrier to its original form before the injection, can challenge such a detection scheme. Therefore, in this work we introduce and evaluate the performances of different techniques used to endow network covert channels with reversibility. Results indicate the feasibility of achieving reversibility but the used protocol plays a major role. Przemyslaw Szary, Wojciech Mazurczyk, Steffen Wendzel, Luca Caviglione |
ARES | 3 |
| 2019 | Towards Reversible Storage Network Covert ChannelsabstractThe use of network covert channels to improve privacy or support security threats has been widely discussed in the literature. As today, the totality of works mainly focuses on how to not disrupt the overt traffic flow and the performance of the covert channels in terms of undetectability and capacity. To not void the stealthiness of the channel, an important feature is the ability of restoring the carrier embedding the secret information into its original form. However, the development of such techniques mainly targets the domain of digital media steganography. Therefore, this paper applies the concept of reversible data hiding to storage network covert channels. To prove the effectiveness of our idea, a prototypical implementation of a channel exploiting IPv4 flows is presented along with its performance evaluation. Wojciech Mazurczyk, Przemyslaw Szary, Steffen Wendzel, Luca Caviglione |
ARES | 3 |
| 2019 | Introducing Dead Drops to Network Steganography using ARP-Caches and SNMP-WalksabstractNetwork covert channels enable various secret data exchange scenarios among two or more secret parties via a communication network. The diversity of the existing network covert channel techniques has rapidly increased due to research during the last couple of years and most of them share the same characteristics, i.e., they require a direct communication between the participating partners. However, it is sometimes simply not possible or it can raise suspicions to communicate directly. That is why, in this paper we introduce a new concept we call "dead drop", i.e., a covert network storage which does not depend on the direct network traffic exchange between covert communication sides. Instead, the covert sender stores secret information in the ARP (Address Resolution Protocol) cache of an unaware host that is not involved in the hidden data exchange. Thus, the ARP cache is used as a covert network storage and the accumulated information can then be extracted by the covert receiver using SNMP (Simple Network Management Protocol). Tobias Schmidbauer, Steffen Wendzel, Aleksandra Mileva, Wojciech Mazurczyk |
ARES | 2 |
| 2019 | Protocol-independent Detection of "Messaging Ordering" Network Covert ChannelsabstractDetection methods are available for several known covert channels. However, a type of covert channel that received little attention within the last decade is the "message ordering" channel. Such a covert channel changes the order of PDUs (protocol data units, i.e. packets) transferred over the network to encode hidden information. The advantage of these channels is that they cannot be blocked easily as they do not modify header content but instead mimic typical network behavior such as TCP segments that arrive in a different order than they were sent. Steffen Wendzel |
ARES | 1 |
| 2019 | Countering adaptive network covert communication with dynamic wardens
Wojciech Mazurczyk, Steffen Wendzel, Mehdi Chourib, Jörg Keller 0001 |
Future Gener. Comput. Syst. | 2 |
| 2019 | Guest Editorial: Recent Advances in Cyber-Physical Security in Industrial Environmentsabstract“Smart” has gradually infiltrating all areas of people's daily life and the environments where we lead our life. The term of “Smart Industrial Environment” can be used to refer to each aspect of the industrial environments focused on the future, being smart vehicles, smart systems of transportation, smart devices (wearables and smartphones), smart services (such as just-in-time production pipelines adjusted to the requirements of the supply-chain), smart grids, smart factories and smart plants management utilizing information technology. It includes the inter-connection of all the smart technologies, involving every type of political and technological borders besides being a term that involves all the aspects. Zhihan Lyu, Wojciech Mazurczyk, Steffen Wendzel, Houbing Song |
IEEE Trans. Ind. Informatics | 3 |
| 2018 | Towards Deriving Insights into Data Hiding Methods Using Pattern-based ApproachabstractIn network information hiding, hiding patterns are used to describe hiding methods and their taxonomy. In this paper, we analyze the current state of hiding patterns and we further improve their taxonomy. In order to more thoroughly characterize and understand data hiding methods applied to communication networks we propose to distinguish between sender-side and receiver-side patterns. Additionally, we show how information hiding patterns can be utilized to conveniently describe the realization of the distributed network covert channels. Wojciech Mazurczyk, Steffen Wendzel, Krzysztof Cabaj |
ARES | 2 |
| 2018 | Get Me Cited, Scotty!: Analysis of Citations in Covert Channel/Steganography ResearchabstractThe understanding of the inner workings of a research community is essential for the success of an author's academic publications. One of the key metrics for the evaluation of researchers is the number of citations that their publications receive. To understand citation behavior of an academic community, existing publication's citations can be studied. Steffen Wendzel |
ARES | 1 |
| 2018 | Emerging and Unconventional: New Attacks and Innovative Detection TechniquesabstractArt. 9672523, 1 S. Luca Caviglione, Wojciech Mazurczyk, Steffen Wendzel, Sebastian Zander |
Secur. Commun. Networks | 3 |
| 2017 | Inter-Protocol Steganography for Real-Time Services and Its Detection Using Traffic Coloring ApproachabstractDue to improvements in defensive systems, network threats are becoming increasingly sophisticated and complex as cybercriminals are using various methods to cloak their actions. This, among others, includes the application of network steganography e.g. to hide the communication between an infected host and a malicious control server by embedding commands into innocent-looking traffic. Currently, a new subtype of such methods called inter-protocol steganography emerged. It utilizes relationships between two or more overt protocols to hide data. In this paper, we present new inter-protocol hiding techniques which are suitable for real-time services. Afterwards, we introduce and present preliminary results of a novel steganography detection approach which relies on network traffic coloring. Florian Lehner, Wojciech Mazurczyk, Jörg Keller 0001, Steffen Wendzel |
LCN | 4 |
| 2016 | POSTER: An Educational Network Protocol for Covert Channel Analysis Using PatternsabstractThe utilization of information hiding is on the rise among cybercriminals, e.g. to cloak the communication of malicious software as well as by ordinary users for privacy-enhancing purposes. A recent trend is to use network traffic in form of covert channels to convey secrets. In result, security expert training is incomplete if these aspects are not covered. This paper fills this gap by providing a method for teaching covert channel analysis of network protocols. We define a sample protocol called Covert Channel Educational Analysis Protocol (CCEAP) that can be used in didactic environments. Compared to previous works we lower the barrier for understanding network covert channels by eliminating the requirement for students to understand several network protocols in advance and by focusing on so-called hiding patterns. Steffen Wendzel, Wojciech Mazurczyk |
CCS | 1 |
| 2016 | Covert channel-internal control protocols: attacks and defenseabstractAbstract Network covert channels have become a sophisticated means for transferring hidden information over the network. Covert channel‐internal control protocols, also called micro protocols, have been introduced in the recent years to enhance capabilities of the network covert channels. Micro protocols are usually placed within the hidden bits of a covert channel's payload and enable features such as reliable data transfer, session management, and dynamic routing for network covert channels. These features provide adaptive and stealthy covert communication channels. Some of the micro protocol based tools exhibit vulnerabilities and are susceptible to attacks. In this paper, we demonstrate some possible attacks on micro protocols, which are capable of breaking the sophisticated covert channel communication or jeopardizing the identity of peers in such a network. These attacks are based on the attacker's interaction with the micro protocol. We also present the defense techniques to safeguard micro protocols against such attacks. By using these techniques, micro protocol‐based tools can become immune to certain attacks and lead to robust covert communication. We present our results for two micro protocol‐based tools: Ping Tunnel and smart covert channel tool. Copyright © 2016 John Wiley & Sons, Ltd. Steffen Wendzel, Omar Eissa, Jernej Tonejc, Michael Meier 0001 |
Secur. Commun. Networks | 2 |
| 2016 | On importance of steganographic cost for network steganographyabstractNetwork steganography encompasses the information hiding techniques that can be applied in communication network environments and that utilize hidden data carriers for this purpose. In this paper we introduce a characteristic called steganographic cost which is an indicator for the degradation or distortion of the carrier caused by the application of the steganographic method. Based on exemplary cases for single- and multi-method steganographic cost analyses we observe that it can be an important characteristic that allows to express hidden data carrier degradation - similarly as MSE (Mean-Square Error) or PSNR (Peak Signal-to-Noise Ratio) are utilized for digital media steganography. Steganographic cost can moreover be helpful to analyse the relationships between two or more steganographic methods applied to the same hidden data carrier. Wojciech Mazurczyk, Steffen Wendzel, Ignacio Azagra Villares, Krzysztof Szczypiorski |
Secur. Commun. Networks | 2 |
| 2016 | Micro protocol engineering for unstructured carriers: on the embedding of steganographic control protocols into audio transmissionsabstractAbstract Network steganography conceals the transfer of sensitive information within unobtrusive data in computer networks. So‐called micro protocols are communication protocols placed within the payload of a network steganographic transfer. They enrich this transfer with features such as reliability, dynamic overlay routing, or performance optimization — just to mention a few. We present different design approaches for the embedding of hidden channels with micro protocols in digitized audio signals under consideration of different requirements. On the basis of experimental results, our design approaches are compared and introduced into a protocol engineering approach for micro protocols. Copyright © 2016 John Wiley & Sons, Ltd. Matthias Naumann, Steffen Wendzel, Wojciech Mazurczyk, Jörg Keller 0001 |
Secur. Commun. Networks | 2 |
| 2015 | Countermeasures for Covert Channel-Internal Control ProtocolsabstractNetwork covert channels have become a sophisticated means for transferring hidden information over the network, and thereby breaking the security policy of a system. Covert channel-internal control protocols, called micro protocols, have been introduced in the recent years to enhance capabilities of network covert channels. Micro protocols are usually placed within the hidden bits of a covert channel's payload and enable features such as reliable data transfer, session management, and dynamic routing for network covert channels. These features provide adaptive and stealthy communication channels for malware, especially bot nets. Although many techniques are available to counter network covert channels, these techniques are insufficient for countering micro protocols. In this paper, we present the first work to categorize and implement possible countermeasures for micro protocols that can ultimately break sophisticated covert channel communication. The key aspect of proposing these countermeasures is based on the interaction with the micro protocol. We implemented the countermeasures for two micro protocol-based tools: Ping Tunnel and Smart Covert Channel Tool. The results show that our techniques are able to counter micro protocols in an effective manner compared to current mechanisms, which do not target micro protocol-specific behavior. Steffen Wendzel, Michael Meier 0001 |
ARES | 2 |
| 2015 | Securing BACnet's Pitfalls
Jernej Tonejc, Steffen Wendzel, Michael Meier 0001 |
SEC | 3 |
| 2013 | Hiding Privacy Leaks in Android Applications Using Low-Attention Raising Covert ChannelsabstractCovert channels enable a policy-breaking communication not foreseen by a system's design. Recently, covert channels in Android were presented and it was shown that these channels can be used by malware to leak confidential information (e.g., contacts) between applications and to the Internet. Performance aspects as well as means to counter these covert channels were evaluated. In this paper, we present novel covert channel techniques linked to a minimized footprint to achieve a high covertness. Therefore, we developed a malware that slowly leaks collected private information and sends it synchronously based on four covert channel techniques. We show that some of our covert channels do not require any extra permission and escape well know detection techniques like TaintDroid. Experimental results confirm that the obtained throughput is correlated to the user interaction and show that these new covert channels have a low energy consumption - both aspects contribute to the stealthiness of the channels. Finally, we discuss concepts for novel means capable to counter our covert channels and we also discuss the adaption of network covert channel features to Android-based covert channels. Jean-François Lalande, Steffen Wendzel |
ARES | 2 |
| 2012 | Covert and side channels in buildings and the prototype of a building-aware active wardenabstractCovert channels and side channels are barely discussed topics in the area of building automation. We define a building in the context of multilevel security (MLS) and show that covert channels and side channels exist in building automation. Additionally, we present a system called the building-aware active warden to eliminate covert/side storage channels in building automation systems (BAS). Active wardens aim to remove malicious (covert) elements in communications and are a well-known means from the area of network covert channels and steganography. Within the last years, new models, such as the network-aware active warden, were developed. The presented building-aware active warden is an adoption of the concept of a network-aware active warden to building automation. Building-aware active wardens modify or drop building automation commands as well as building information requests from users based on their security levels to enhance a building's security. We extended an interoperable system for building automation supporting hardware from two vendors for the purpose of a building-aware active warden and for providing an unified application programming interface. Steffen Wendzel |
ICC | 1 |
| 2012 | Detecting protocol switching covert channelsabstractNetwork covert channels enable hidden communication and can be used to break security policies. Within the last years, new techniques for such covert channels arose, including protocol switching covert channels (PSCCs). PSCCs transfer hidden information by sending network packets with different selected network protocols. In this paper we present the first detection methods for PSCCs. We show that the number of packets between network protocol switches and the time between switches can be monitored to detect PSCCs with 98-99% accuracy for bit rates of 4 bits/second or higher. Steffen Wendzel, Sebastian Zander |
LCN | 1 |