Abstract
Network Covert Channels (NCCs) convey information by modulating traffic packet-level feature, typically packet size and timing, thereby evading monitoring devices for data exfiltration. Detection-guided disruption, a common paradigm to mitigate NCC threat, first identifies NCC traffic and then disrupts its features to prevent the recovery of covert information. However, our evaluation reveals that existing detection methods lack robustness across diverse traffic contexts, including different applications and feature modalities, either incurring high false-positive rates on benign flows or failing to detect certain types of NCCs. The growing computational overhead and reliance on long traffic samples hinder detection from identifying small-capacity NCC leakage. Given the limitations of detection, disruption serves as an essential complement. In real deployment scenarios, a disruption method must be broadly effective across various NCCs while maintaining low overhead on benign flows, yet existing techniques have not achieved both requirements simultaneously. Therefore, this paper proposes Covadis, an adversarial learning-based method for NCC disruption. Covadis integrates an NCC constructor, which continuously generates NCC samples, with a disruptor that adaptively perturbs them to reduce covert information leakage while minimizing overhead. The evaluation shows that Covadis reduces covert mutual information by an average of 67.7% with 40.3% overhead on size-based NCCs, and by 62.1% with 35.7% overhead on timing-based NCCs, outperforming existing disruption methods. Our work advances NCC mitigation in practical systems by identifying key limitations, introducing a unified model, and designing a generic mitigation approach.
| Original language | English |
|---|---|
| Article number | 112466 |
| Journal | Computer Networks |
| Volume | 286 |
| DOIs | |
| Publication status | Published - Aug 2026 |
| Externally published | Yes |
Keywords
- Adversarial learning
- Cyber security
- Information leakage
- Network covert channel mitigation
Fingerprint
Dive into the research topics of 'Evaluating and mitigating network covert channels in diverse traffic contexts'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver