Journal on Communications ›› 2014, Vol. 35 ›› Issue (11): 96-106.doi: 10.11959/j.issn.1000-436x.2014.11.011

• network security • Previous Articles     Next Articles

Network isolation communication scheme to resist against covert channel

Feng-hua LI1,Miao-miao TAN2,Kai FAN,Kui GENG1,2,Fu ZHAO3   

  1. 1 State Key Laboratory of Information Security,Institute of Information Engineering,Chinese Academy of Science,Beijing 100093
    2 School of Telecommunication Engineering,Xidian University,Xi’an 710071,China
    3 Beijing Aerospace Numerical Control System Co.,Ltd,Beijing 100854,China
  • Online:2014-11-25 Published:2017-06-20
  • Supported by:
    The National Natural Science Foundation of China;The National High-Tech R&D Program of China (863 Program);The National High-Tech R&D Program of China (863 Program);The Major Science and Technology Project of Press and Publication-Research and Development

Abstract:

With the rapid development of network technologies,real-time information exchanging between heterogeneous networks becomes more frequently.To effectively guarantee the secure and real-time information exchanging crossing different networks,a network isolation communication scheme (NICS) is proposed to resist against covert channel.A newly theoretical model of NICS is designed and proved based on the information theory,and followed with a specific solution.Security analysis indicates that the NICS is able to effectively solve problems of the potential packet lengths’ covert channel (PLCC) and the status covert channel (SCC) in most of the existing work; and,given similar amount of information for exchanging,the NICS can achieve equivalent security degree with the physical isolation in terms of resisting against the covert channel.

Key words: network isolation, covert channel, length of the data packet, status information

No Suggested Reading articles found!