arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

Helol 隧道:对 TLS 可扩展性与隐私特性的隐蔽信道利用

Helol Tunnel: Covert Channel Exploitation of TLS Extensibility & Privacy Features

Reza Soosahabi, Rakesh Seal

arXiv 2610.01009首次发表:更新:

发表机构

Application & Threat Intelligence Research Center Keysight Technologies, Inc.(安捷伦科技应用与威胁智能研究中心)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

针对 TLS 协议中 Client Hello 数据包,提出 Helol 隧道隐蔽信道,通过重排加密信息元素嵌入数据,利用反僵化与隐私特性规避 NGFW,并验证其优于现有隐蔽信道。

AI 中文摘要

利用网络协议进行数据外泄和命令与控制(C2)的隐蔽信道是现代网络攻击的组成部分。为了在互联网结构中寻找一种重要的隐蔽信道,我们针对无处不在的传输层安全(TLS)协议中客户端问候(Client Hello,CHLO)数据包的组合特性进行了研究。所提出的 Helol 隧道是一种新颖的隐蔽方法,用于在 TLS 客户端问候数据包中嵌入信息,该方法涉及对其加密信息元素进行策略性重排。为了维持 TLS 协议的可扩展性,近期反僵化(anti-ossification)TLS 合规措施鼓励交互式中间盒和下一代防火墙(NGFWs)保留客户端问候数据包中的参数配置。此外,为提高用户隐私,流行的互联网应用正在改变其 TLS CHLO 参数配置,以抵抗第三方网络实体的 TLS 指纹识别。我们展示了 Helol 隧道利用这些近期发展来规避具有交互式代理和全面威胁防护的 NGFWs 的能力。我们还通过使用真实流量捕获和公开的 TLS 指纹数据,数值上展示了 Helol 隧道相对于利用 TLS 的最先进隐蔽信道的有效性。

英文摘要

Covert channels exploiting network protocols for data exfiltration and command-and-control (C2) are integral parts of modern cyberattacks. In search of a significant covert channel within the fabric of the Internet, we targeted the combinatorial properties of the Client Hello (CHLO) packets in the ubiquitous Transport Layer Security (TLS) protocol. The proposed Helol tunnel is a novel covert approach to embedding information in TLS Client Hello packets, which involves the strategic rearrangement of their cryptographic information elements. To sustain TLS protocol extensibility, the recent anti-ossification TLS compliance measures encourage the interactive middleboxes and next-generation firewalls (NGFWs) to preserve the parameter configuration in the Client Hello packets. Furthermore, to improve user privacy, popular Internet applications are varying their TLS CHLO parameter configurations to resist TLS fingerprinting by third-party network entities. We demonstrate the strength of the Helol tunnel to exploit these recent developments to evade NGFWs with interactive proxy and comprehensive threat protection. We also numerically show the efficacy of Helol tunneling over state-of-the-art covert channels that exploit TLS through the use of real traffic captures and public TLS fingerprinting data.

CommentsBest Paper Award Recipient at the 6th Silicon Valley Cybersecurity Conference (SVCC 2025). Keywords: covert channel, malware, data exfiltration, middleboxes, TLS fingerprinting, TLS ossification, network security

Journal ref6th Silicon Valley Cybersecurity Conference (SVCC 2025)

DOI:10.1109/SVCC65277.2025.11133623

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑