Memory-Based Covert Channels in the TLS Protocol
摘要
Methods of protection against memory-based covert channels in the TLS protocol, which use the Random and SessionID service fields of the ClientHello message, are proposed. Protection tools implementing the proposed methods are developed: a module for the Suricata IDS/IPS that filters TLS packets depending on the contents of the SessionID service field, and a proxy server that reformats packets transmitted into the communication environment. A comparative analysis of the implemented security tools is carried out in terms of their impact on the communication channel throughput and their effectiveness in countering the transmission of confidential information. The developed protection tools can be implemented into existing systems for protection against network covert channels. Recommendations are provided for the application of the proposed protection mechanisms, depending on the desired level of security.