Partial memory traffic normalization as a method for reducing the throughput of covert channels
摘要
This article presents partial memory traffic normalization as an effective method for reducing the throughput of covert channels that exploit modifications to the lengths of transmitted packets. The approach focuses on limiting the set of allowable packet lengths and enhancing this technique with dummy traffic generation. Together, these measures reduce the variability of network traffic, making it significantly more challenging for covert channels to operate and thereby decreasing the risk of information leakage. The effectiveness of the method is illustrated though simulations, including a binary channel example, where only two packet lengths are used, as well as scenarios involving random packet length increases combined with dummy traffic. Results confirm that the proposed measures substantially reduce the residual capacity of covert channels while maintaining acceptable levels of data transmission efficiency in IPv4- and IPv6-based networks. The article concludes with practical recommendations for selecting countermeasure parameters, highlighting the potential of this method for integration into information security systems. By striking a balance between security and performance, this approach demonstrates promise as a robust solution for mitigating channel threats.