{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,30]],"date-time":"2025-12-30T23:50:57Z","timestamp":1767138657975,"version":"build-2238731810"},"publisher-location":"Berlin, Heidelberg","reference-count":31,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"value":"9783662447871","type":"print"},{"value":"9783662447888","type":"electronic"}],"license":[{"start":{"date-parts":[[2014,1,1]],"date-time":"2014-01-01T00:00:00Z","timestamp":1388534400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2014,1,1]],"date-time":"2014-01-01T00:00:00Z","timestamp":1388534400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2014]]},"DOI":"10.1007\/978-3-662-44788-8_13","type":"book-chapter","created":{"date-parts":[[2014,9,27]],"date-time":"2014-09-27T01:09:51Z","timestamp":1411780191000},"page":"209-225","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["InCC: Evading Interception and Inspection by Mimicking Traffic in Network Flows"],"prefix":"10.1007","author":[{"given":"Luis Campo","family":"Giralte","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Isaac Martin","family":"de Diego","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Cristina","family":"Conde","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Enrique","family":"Cabello","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2014,9,28]]},"reference":[{"key":"13_CR1","unstructured":"5200.28-STD, D.: Trusted Computer System Evaluation Criteria. Dod Computer Security Center (1985)"},{"key":"13_CR2","unstructured":"Llamas, D., Miller, A., Allison, C.: An evaluation framework for the analysis of covert channels in the tcp\/ip protocol suite. In: ECIW, pp. 205\u2013214. Academic Conferences Limited, Reading (2005)"},{"key":"13_CR3","doi-asserted-by":"publisher","first-page":"44","DOI":"10.1109\/COMST.2007.4317620","volume":"9","author":"S Zander","year":"2007","unstructured":"Zander, S., Armitage, G.J., Branch, P.: A survey of covert channels and countermeasures in computer network protocols. IEEE Commun. Surv. Tutorials 9, 44\u201357 (2007)","journal-title":"IEEE Commun. Surv. Tutorials"},{"key":"13_CR4","doi-asserted-by":"crossref","unstructured":"Sellke, S.H., Wang, C.C., Bagchi, S., Shroff, N.B.: Tcp\/ip timing channels: theory to implementation. In: INFOCOM, pp. 2204\u20132212. IEEE (2009)","DOI":"10.1109\/INFCOM.2009.5062145"},{"key":"13_CR5","series-title":"IFIP Advances in Information and Communication Technology","doi-asserted-by":"publisher","first-page":"51","DOI":"10.1007\/978-3-642-01244-0_5","volume-title":"Emerging Challenges for Security, Privacy and Trust","author":"L Nussbaum","year":"2009","unstructured":"Nussbaum, L., Neyron, P., Richard, O.: On robust covert channels inside DNS. In: Gritzalis, D., Lopez, J. (eds.) SEC 2009. IFIP AICT, vol. 297, pp. 51\u201362. Springer, Heidelberg (2009)"},{"key":"13_CR6","series-title":"IFIP Advances in Information and Communication Technology","doi-asserted-by":"publisher","first-page":"162","DOI":"10.1007\/978-3-642-30436-1_14","volume-title":"Information Security and Privacy Research","author":"R Rios","year":"2012","unstructured":"Rios, R., Onieva, J.A., Lopez, J.: HIDE_DHCP: covert communications through network configuration messages. In: Gritzalis, D., Furnell, S., Theoharidou, M. (eds.) SEC 2012. IFIP AICT, vol. 376, pp. 162\u2013173. Springer, Heidelberg (2012)"},{"key":"13_CR7","doi-asserted-by":"publisher","first-page":"53","DOI":"10.1007\/s10922-009-9120-x","volume":"17","author":"EP Freire","year":"2009","unstructured":"Freire, E.P., Ziviani, A., Salles, R.M.: On metrics to distinguish skype flows from http traffic. J. Netw. Syst. Manage. 17, 53\u201372 (2009)","journal-title":"J. Netw. Syst. Manage."},{"key":"13_CR8","doi-asserted-by":"crossref","unstructured":"Dittmann, J., Hesse, D., Hillert, R.: Steganography and steganalysis in voice-over ip scenarios: operational aspects and first experiences with a new steganalysis tool set. In: Delp, E.J., Wong, P.W. (eds.) Security, Steganography, and Watermarking of Multimedia Contents. Proceedings of SPIE, vol. 5681, pp. 607\u2013618. SPIE (2005)","DOI":"10.1117\/12.586579"},{"key":"13_CR9","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"120","DOI":"10.1007\/978-3-642-04444-1_8","volume-title":"Computer Security \u2013 ESORICS 2009","author":"Y Liu","year":"2009","unstructured":"Liu, Y., Ghosal, D., Armknecht, F., Sadeghi, A.-R., Schulz, S., Katzenbeisser, S.: Hide and seek in time \u2014 robust covert timing channels. In: Backes, M., Ning, P. (eds.) ESORICS 2009. LNCS, vol. 5789, pp. 120\u2013135. Springer, Heidelberg (2009)"},{"key":"13_CR10","doi-asserted-by":"crossref","unstructured":"Zhang, D., Askarov, A., Myers, A.C.: Predictive mitigation of timing channels in interactive systems. In: Proceedings of the 18th ACM Conference on Computer and Communications Security, CCS \u201911, pp. 563\u2013574. ACM, New York (2011)","DOI":"10.1145\/2046707.2046772"},{"key":"13_CR11","doi-asserted-by":"crossref","unstructured":"Zander, S., Armitage, G.J., Branch, P.: An empirical evaluation of ip time to live covert channels. In: ICON, pp. 42\u201347. IEEE (2007)","DOI":"10.1109\/ISCIT.2007.4392082"},{"key":"13_CR12","doi-asserted-by":"crossref","unstructured":"Luo, X., Chan, E.W.W., Chang, R.K.C.: Clack: a network covert channel based on partial acknowledgment encoding. In: ICC, pp. 1\u20135. IEEE (2009)","DOI":"10.1109\/ICC.2009.5198826"},{"key":"13_CR13","doi-asserted-by":"crossref","unstructured":"Wendzel, S., Zander, S.: Detecting protocol switching covert channels. In: 37th Annual IEEE Conference on Local Computer Networks, pp. 280\u2013283 (2012)","DOI":"10.1109\/LCN.2012.6423628"},{"key":"13_CR14","doi-asserted-by":"crossref","unstructured":"Mazurczyk, W., Szczypiorski, K.: Steganography in handling oversized ip packets. CoRR abs\/0907.0313 (2009)","DOI":"10.1109\/MINES.2009.246"},{"key":"13_CR15","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"164","DOI":"10.1007\/978-3-540-30114-1_12","volume-title":"Information Hiding","author":"NB Lucena","year":"2004","unstructured":"Lucena, N.B., Pease, J., Yadollahpour, P., Chapin, S.J.: Syntax and semantics-preserving application-layer protocol steganography. In: Fridrich, J. (ed.) IH 2004. LNCS, vol. 3200, pp. 164\u2013179. Springer, Heidelberg (2004)"},{"key":"13_CR16","unstructured":"Fu, X., Guan, Y., Graham, B., Bettati, R., Zhao, W.: Using parasite flows to camouflage flow traffic. In: Proceedings of the 2002 IEEE Workshop on Information Assurance (2002)"},{"key":"13_CR17","unstructured":"Burnett, S., Feamster, N., Vempala, S.: Chipping away at censorship firewalls with user-generated content. In: Proceedings of the 19th USENIX Conference on Security, USENIX Security\u201910, pp. 29\u201329. USENIX Association, Berkeley (2010)"},{"key":"13_CR18","unstructured":"Miklosovic, S.: Pa018 - term project - port knocking enhancements (2011). http:\/\/www.portknocking.org\/view\/resources"},{"key":"13_CR19","unstructured":"Degraaf, R., Aycock, J., Jacobson, M.: Improved port knocking with strong authentication. In: Proceedings of the 21st Annual Computer Security Applications Conference (ACSAC 2005), pp. 409\u2013418. Springer (2005)"},{"key":"13_CR20","unstructured":"Tariq, M., Baig, M.S., Saeed, M.T.: Associating the authentication and connection-establishment phases in passive authorization techniques (2008)"},{"key":"13_CR21","unstructured":"Rcf4557: The rc4-hmac kerberos encryption types used by microsoft windows (2006). http:\/\/www.ietf.org\/rfc\/rfc4757.txt"},{"key":"13_CR22","unstructured":"Snort: Snort (2013). http:\/\/www.snort.org\/"},{"key":"13_CR23","unstructured":"OpenDPI: Opendpi (2013). http:\/\/www.opendpi.org\/opendpi.org\/index.html"},{"key":"13_CR24","unstructured":"Rfc2246: The tls protocol (1999). http:\/\/www.ietf.org\/rfc\/rfc2246.txt"},{"key":"13_CR25","unstructured":"BitTorrent: The bittorrent protocol specification, version 11031 (2013). http:\/\/bittorrent.org\/beps\/bep_0003.html"},{"key":"13_CR26","doi-asserted-by":"publisher","first-page":"269","DOI":"10.1007\/s10623-008-9206-6","volume":"48","author":"A Klein","year":"2008","unstructured":"Klein, A.: Attacks on the rc4 stream cipher. Des. Codes Crypt. 48, 269\u2013286 (2008)","journal-title":"Des. Codes Crypt."},{"key":"13_CR27","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"491","DOI":"10.1007\/11426639_29","volume-title":"Advances in Cryptology \u2013 EUROCRYPT 2005","author":"I Mantin","year":"2005","unstructured":"Mantin, I.: Predicting and distinguishing attacks on RC4 keystream generator. In: Cramer, R. (ed.) EUROCRYPT 2005. LNCS, vol. 3494, pp. 491\u2013506. Springer, Heidelberg (2005)"},{"key":"13_CR28","doi-asserted-by":"crossref","unstructured":"Paul, S., Preneel, B.: A new weakness in the rc4 keystream generator and an approach to improve the security of the cipher, pp. 245\u2013259 (2004)","DOI":"10.1007\/978-3-540-25937-4_16"},{"key":"13_CR29","unstructured":"Tcpdump: Tcpdump (2013). http:\/\/www.tcpdump.org\/"},{"key":"13_CR30","unstructured":"Hippie: Hi-performance protocol identification engine (2013). http:\/\/sourceforge.net\/projects\/hippie\/"},{"key":"13_CR31","unstructured":"Battlefield: Battlefield (2013). http:\/\/www.battlefield.com\/"}],"container-title":["Communications in Computer and Information Science","E-Business and Telecommunications"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-662-44788-8_13","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,4,2]],"date-time":"2024-04-02T12:31:31Z","timestamp":1712061091000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-662-44788-8_13"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2014]]},"ISBN":["9783662447871","9783662447888"],"references-count":31,"aliases":["10.1007\/978-3-662-45945-4_13"],"URL":"https:\/\/doi.org\/10.1007\/978-3-662-44788-8_13","relation":{},"ISSN":["1865-0929","1865-0937"],"issn-type":[{"value":"1865-0929","type":"print"},{"value":"1865-0937","type":"electronic"}],"subject":[],"published":{"date-parts":[[2014]]},"assertion":[{"value":"28 September 2014","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}}]}}