« Previous 1 2 3
TCP Stealth hides open ports
TCP Camouflage
Conclusions and Outlook
TCP Stealth looks pretty promising. The project website has comprehensive and useful documentation. Sample programs and prepared patches make it easy to get started. In contrast to alternatives such as SilentKnock, TCP Stealth has far less trouble with Network Address Translation, which makes it more attractive. The integrity check to prevent man-in-the-middle attacks is also something that is not to be sniffed at.
Inquisitive users could also take a look at the Bridge SPA [19] or Knockknock [20] projects. What remains at the end of the day is the limitation to TCP as the transport protocol. The project presented here could take a decisive step forward if it does manage to make it into the Linux kernel.
Infos
- Netcat: http://netcat.sourceforge.net
- Nmap: http://nmap.org
- Port knocking implementations; http://www.portknocking.org/view/implementations
- "Remote Access Security with Single-Packet Port Knocking" by Juliet Kemp, Linux Magazine , June 2008: http://www.linux-magazine.com/Issues/2008/91/Single-Packet-Port-Knocking/(language)/eng-US
- "The Sys Admin's Daily Grind: Knockd" by Charly Kühnast, Linux Magazine , September 2008: http://www.linux-magazine.com/Issues/2008/94/Charly-s-Column/(language)/eng-US
- "The Sys Admin's Daily Grind: Single-Packet Authentication" by Charly Kühnast, Linux Magazine , October 2008: http://www.linux-magazine.com/Issues/2008/95/KEY-EXPERIENCE/(language)/eng-US
- Project Knockd: http://www.zeroflux.org/projects/knock
- Stealth draft: http://tools.ietf.org/html/draft-kirsch-ietf-tcp-stealth-00
- IETF: http://www.ietf.org
- TU Munich: http://www.tum.de/en/homepage/
- TCP Stealth project website: http://gnunet.org/knock
- Julian Kirsch master's thesis: http://gnunet.org/sites/default/files/ma_kirsch_2014_0.pdf
- SilentKnock: http://www-users.cs.umn.edu/~hopper/silentknock_esorics.pdf
- Covert channels: http://firstmonday.org/ojs/index.php/fm/article/view/528/449
- MD5: http://tools.ietf.org/html/rfc1321
- Discussion on the kernel mailing list: http://lkml.org/lkml/2013/12/10/1155
- New program version: http://github.com/useidel/knock
- TCP Stealth and OpenSSH: http://www.youtube.com/watch?v=7CadOVTNxr4
- Bridge SPA: http://www.cypherpunks.ca/~iang/pubs/bridgespa-wpes.pdf
- Knockknock: http://www.thoughtcrime.org/software/knockknock
« Previous 1 2 3
Buy this article as PDF
(incl. VAT)