{"id":{"repo_id":"uiuc","oai_identifier":"oai:www.ideals.illinois.edu:2142/89281"},"canonical_url":"https://search.dev.ndltd.org/etd/uiuc/oai:www.ideals.illinois.edu:2142/89281","repository":{"repo_id":"uiuc","name":"University of Illinois - Urbana-Champaign","base_url":"https://www.ideals.illinois.edu/oai-pmh"},"display":{"title":"Sneak-peek: high speed covert channels in data center networks","abstract":"With the advent of big data, modern businesses face an increasing need to store and process large volumes of sensitive customer information on the cloud. In these environments, resources are shared across a multitude of mutually untrusting tenants increasing propensity for data leakage. With the recent spate of high-profile data exfiltration attacks and the emergence of critical vulnerabilities such as Heartbleed and Shellshock, coupled with increasing use of clouds in all aspects of our daily lives, this problem stands to grow further in severity. In this thesis, we present a novel network-based covert channel that can arise in the context of shared network resources in data-center environments even in the presence of network monitors regulating flow destinations with NAC policies and VLAN-based isolation mechanisms. Through a series of experiments on diverse network hardware (including SDNs) and commercial clouds such as EC2 and Azure, we demonstrate that our network-based channel achieves orders of magnitude greater bit rates than reported in any recent literature. Furthermore, we present an information-theoretic framework to model and study the channel. Using this model we derive an upper bound on the information rate of the channel and propose a coding scheme that nearly achieves this upper bound. Additionally we introduce some techniques to make the covert channel robust to noise, and empirically study its performance in the presence of realistic cross-traffic. Finally, we discuss several avenues for mitigation, and demonstrate the effectiveness of our schemes both empirically and mathematically.","abstract_html":"With the advent of big data, modern businesses face an increasing need to store and process large volumes of sensitive customer information on the cloud. In these environments, resources are shared across a multitude of mutually untrusting tenants increasing propensity for data leakage. With the recent spate of high-profile data exfiltration attacks and the emergence of critical vulnerabilities such as Heartbleed and Shellshock, coupled with increasing use of clouds in all aspects of our daily lives, this problem stands to grow further in severity. In this thesis, we present a novel network-based covert channel that can arise in the context of shared network resources in data-center environments even in the presence of network monitors regulating flow destinations with NAC policies and VLAN-based isolation mechanisms. Through a series of experiments on diverse network hardware (including SDNs) and commercial clouds such as EC2 and Azure, we demonstrate that our network-based channel achieves orders of magnitude greater bit rates than reported in any recent literature. Furthermore, we present an information-theoretic framework to model and study the channel. Using this model we derive an upper bound on the information rate of the channel and propose a coding scheme that nearly achieves this upper bound. Additionally we introduce some techniques to make the covert channel robust to noise, and empirically study its performance in the presence of realistic cross-traffic. Finally, we discuss several avenues for mitigation, and demonstrate the effectiveness of our schemes both empirically and mathematically.","abstract_has_math":false,"creators":["Tahir, Rashid"],"institution":"University of Illinois at Urbana-Champaign","degree_name":"M.S.","degree_level":"Thesis","degree_discipline":"Computer Science","degree_department":null,"school":null,"contributors":["Caesar, Matthew C."],"advisors":[],"committee_chairs":[],"committee_members":[],"year":2016,"date_issued":"2016-03-08T17:21:50Z","date_published":"2016-03-08T17:21:50Z","updated_at":"2026-07-22T22:26:32Z","subjects":["Covert Channels","Data Center Networks","Clouds","Software Defined Networking (SDN)"],"languages":["en"],"rights":["Copyright 2015 Rashid Tahir"],"rights_urls":[],"identifier_entries":[]},"links":{"outbound_url":"http://hdl.handle.net/2142/89281","outbound_label":"Handle","outbound_source":"dc:identifier"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor","label":"Contributor","values":["Caesar, Matthew C."]},{"key":"dc:creator","label":"Author","values":["Tahir, Rashid"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date","label":"Dc Date","values":["2016-03-08T17:21:50Z","2018-03-09T10:15:25Z","2015-10-29","2015-12"]},{"key":"dc:type","label":"Dc Type","values":["text"]},{"key":"thesis:degree_discipline","label":"Discipline","values":["Computer Science"]},{"key":"thesis:degree_level","label":"Degree Level","values":["Thesis"]},{"key":"thesis:degree_name","label":"Degree Name","values":["M.S."]},{"key":"thesis:institution_name","label":"Thesis Institution Name","values":["University of Illinois at Urbana-Champaign"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["Covert Channels","Data Center Networks","Clouds","Software Defined Networking (SDN)"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language","label":"Dc Language","values":["en"]},{"key":"dc:rights","label":"Dc Rights","values":["Copyright 2015 Rashid Tahir"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier","label":"Identifier","values":["http://hdl.handle.net/2142/89281"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description","label":"Description","values":["With the advent of big data, modern businesses face an increasing need to store and process large volumes of sensitive customer information on the cloud. In these environments, resources are shared across a multitude of mutually untrusting tenants increasing propensity for data leakage. With the recent spate of high-profile data exfiltration attacks and the emergence of critical vulnerabilities such as Heartbleed and Shellshock, coupled with increasing use of clouds in all aspects of our daily lives, this problem stands to grow further in severity. In this thesis, we present a novel network-based covert channel that can arise in the context of shared network resources in data-center environments even in the presence of network monitors regulating flow destinations with NAC policies and VLAN-based isolation mechanisms. Through a series of experiments on diverse network hardware (including SDNs) and commercial clouds such as EC2 and Azure, we demonstrate that our network-based channel achieves orders of magnitude greater bit rates than reported in any recent literature. Furthermore, we present an information-theoretic framework to model and study the channel. Using this model we derive an upper bound on the information rate of the channel and propose a coding scheme that nearly achieves this upper bound. Additionally we introduce some techniques to make the covert channel robust to noise, and empirically study its performance in the presence of realistic cross-traffic. Finally, we discuss several avenues for mitigation, and demonstrate the effectiveness of our schemes both empirically and mathematically.","Submission published under a 24 month embargo labeled 'U of I Access', the embargo will last until 2017-12-01","The student, Rashid Tahir, accepted the attached license on 2015-10-28 at 16:53.","The student, Rashid Tahir, submitted this Thesis for approval on 2015-10-28 at 17:01.","This Thesis was approved for publication on 2015-10-29 at 10:00.","DSpace SAF Submission Ingestion Package generated from Vireo submission #8747 on 2016-03-08 at 11:05:13","Made available in DSpace on 2016-03-08T17:21:50Z (GMT). No. of bitstreams: 2 TAHIR-THESIS-2015.pdf: 1410971 bytes, checksum: fd9d6285abd3126905a9862e9f1c2fd1 (MD5) LICENSE.txt: 4209 bytes, checksum: 9f918b1564aa8871f45c237f791f6431 (MD5) Previous issue date: 2015-10-29","Embargo set by: Seth Robbins for item 91492 Lift date: 2018-03-08T17:22:13Z Reason: Author requested U of Illinois access only (OA after 2yrs) in Vireo ETD system","U of I Only Restriction Lifted for Item 91492 on 2018-03-09T10:15:25Z."]},{"key":"dc:format","label":"Dc Format","values":["application/pdf"]},{"key":"dc:title","label":"Title","values":["Sneak-peek: high speed covert channels in data center networks"]}]}],"canonical_facts":{"dc:contributor":["Caesar, Matthew C."],"dc:creator":["Tahir, Rashid"],"dc:date":["2016-03-08T17:21:50Z","2018-03-09T10:15:25Z","2015-10-29","2015-12"],"dc:description":["With the advent of big data, modern businesses face an increasing need to store and process large volumes of sensitive customer information on the cloud. In these environments, resources are shared across a multitude of mutually untrusting tenants increasing propensity for data leakage. With the recent spate of high-profile data exfiltration attacks and the emergence of critical vulnerabilities such as Heartbleed and Shellshock, coupled with increasing use of clouds in all aspects of our daily lives, this problem stands to grow further in severity. In this thesis, we present a novel network-based covert channel that can arise in the context of shared network resources in data-center environments even in the presence of network monitors regulating flow destinations with NAC policies and VLAN-based isolation mechanisms. Through a series of experiments on diverse network hardware (including SDNs) and commercial clouds such as EC2 and Azure, we demonstrate that our network-based channel achieves orders of magnitude greater bit rates than reported in any recent literature. Furthermore, we present an information-theoretic framework to model and study the channel. Using this model we derive an upper bound on the information rate of the channel and propose a coding scheme that nearly achieves this upper bound. Additionally we introduce some techniques to make the covert channel robust to noise, and empirically study its performance in the presence of realistic cross-traffic. Finally, we discuss several avenues for mitigation, and demonstrate the effectiveness of our schemes both empirically and mathematically.","Submission published under a 24 month embargo labeled 'U of I Access', the embargo will last until 2017-12-01","The student, Rashid Tahir, accepted the attached license on 2015-10-28 at 16:53.","The student, Rashid Tahir, submitted this Thesis for approval on 2015-10-28 at 17:01.","This Thesis was approved for publication on 2015-10-29 at 10:00.","DSpace SAF Submission Ingestion Package generated from Vireo submission #8747 on 2016-03-08 at 11:05:13","Made available in DSpace on 2016-03-08T17:21:50Z (GMT). No. of bitstreams: 2 TAHIR-THESIS-2015.pdf: 1410971 bytes, checksum: fd9d6285abd3126905a9862e9f1c2fd1 (MD5) LICENSE.txt: 4209 bytes, checksum: 9f918b1564aa8871f45c237f791f6431 (MD5) Previous issue date: 2015-10-29","Embargo set by: Seth Robbins for item 91492 Lift date: 2018-03-08T17:22:13Z Reason: Author requested U of Illinois access only (OA after 2yrs) in Vireo ETD system","U of I Only Restriction Lifted for Item 91492 on 2018-03-09T10:15:25Z."],"dc:format":["application/pdf"],"dc:identifier":["http://hdl.handle.net/2142/89281"],"dc:language":["en"],"dc:rights":["Copyright 2015 Rashid Tahir"],"dc:subject":["Covert Channels","Data Center Networks","Clouds","Software Defined Networking (SDN)"],"dc:title":["Sneak-peek: high speed covert channels in data center networks"],"dc:type":["text"],"thesis:degree_discipline":["Computer Science"],"thesis:degree_level":["Thesis"],"thesis:degree_name":["M.S."],"thesis:institution_name":["University of Illinois at Urbana-Champaign"]},"updated_at":"2026-07-22T22:26:32Z"}