Author Login Chief Editor Login Reviewer Login Editor Login Remote Office

Computer Engineering ›› 2006, Vol. 32 ›› Issue (3): 140-142.

• Networks and Communications • Previous Articles     Next Articles

Covert Channel Based on IGMPv2

HUA Yuanbin1, JIANG Jianchun2,3, QING Sihan2,3   

  1. 1. Graduate School of Chinese Academy of Sciences, Beijing 100039; 2. Institute of Software, Chinese Academy of Sciences, Beijing 100080;3. Engineering Research Center for Information Security Technology, Chinese Academy of Sciences, Beijing 100080
  • Online:2006-02-05 Published:2006-02-05

基于 IGMPv2 的隐蔽通道

华元彬 1,蒋建春2,3,卿斯汉2,3   

  1. 1. 中国科学院研究生院,北京 100039;2. 中国科学院软件研究所,北京 100080;3. 中国科学院信息安全技术工程研究中心,北京 100080

Abstract: Now IP multicasting is more and more widely used. The protocol that serves for it is IGMP. It has upgraded from version 1 to version 2 and then version 3. It has been more and more perfect and its security is raised. Now IGMPv2 is the most widely used in the three versions. But there are some fields in the IGMPv2 can be used to implement covert channel. For example, there are “Route Alert Option” and “Max Response Time”. The paper discusses how to implement covert channel based on these two fields. First, the paper introduces the concept of covert channel and IGMP. Secondly, it discusses how the covert channel works on IGMP. The third is how to design the software. Finally, the paper analyses the method

Key words: Internet group management protocol (IGMP); Covert channel; Route alert option

摘要: 目前IP 组播技术应用越来越广泛,其应用的协议是IGMP,该协议不断完善,版本不断升级,安全性也得到了提高。但是,在目前应用最广的IGMPv2 中,可以实现隐蔽通道,最明显的是协议包中的“路由器检测选项”字段和“最大响应时间”字段。该文主要针对如何使用这两个字段实现隐蔽通道加以讨论。介绍了隐蔽通道和IGMP 的基本概念,说明了该隐蔽通道的实现原理,描述了软件设计,最后对该方法进行了分析。

关键词: Internet 组管理协议;隐蔽通道;路由器检测选项