Snort.org home  
Got Source? About Snort About Sourcefire Snort FAQ
Sourcefire Network Security - the creators of Snort

Snort Forums Archive

Archive Home » General Security Discussion » Covert Channels

Please note that the categories listed below represent an archived version of our forums pages. To view the current version and be able to post and reply to threads, please register and login here to go to the full forums pages.

[ Notice: Full Version of This Topic ]

Covert Channels


Posted by benRu_x86 on April 10, 2007 01:50:42

Hi there!
I am new in Snort. I would like to know which types of techniques does Snort utilize in order to thwart the use of covert channels in networks protocols. As far as I am concerned it has on default some rules to fight against a type of ICMP covert channels. Is there anything else??

Thanks a lot!!!

Posted by mykol_j on August 13, 2007 06:36:42

Hmm, no answer since April... Bummer. I'm looking at this same topic -- and finding very little on it. It appears to me though that the answer is going to be in a preprocessor. Other than the obvious pattern matching the rules provide, the preprocessors are going to be the ones keeping state, looking for fragments, examining the netflow-like-data, etc. -- all required for the covert detection stuff.

Cheers and Good Luck!