{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,6]],"date-time":"2026-04-06T14:47:48Z","timestamp":1775486868071,"version":"3.50.1"},"reference-count":39,"publisher":"MDPI AG","issue":"18","license":[{"start":{"date-parts":[[2021,9,18]],"date-time":"2021-09-18T00:00:00Z","timestamp":1631923200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Sensors"],"abstract":"<jats:p>The proposed StegoFrameOrder (SFO) method enables the transmission of covert data in wireless computer networks exploiting non-deterministic algorithms of medium access (such as the distributed coordination function), especially in IEEE 802.11 networks. Such a covert channel enables the possibility of leaking crucial information outside secured network in a manner that is difficult to detect. The SFO method embeds hidden bits of information in the relative order of frames transmitted by wireless terminals operating on the same radio channel. The paper presents an idea of this covert channel, its implementation, and possible variants. The paper also discusses implementing the SFO method in a real environment and the experiments performed in the real-world scenario.<\/jats:p>","DOI":"10.3390\/s21186268","type":"journal-article","created":{"date-parts":[[2021,9,21]],"date-time":"2021-09-21T22:35:20Z","timestamp":1632263720000},"page":"6268","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":11,"title":["StegoFrameOrder\u2014MAC Layer Covert Network Channel for Wireless IEEE 802.11 Networks"],"prefix":"10.3390","volume":"21","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-1368-3854","authenticated-orcid":false,"given":"Krzysztof","family":"Sawicki","sequence":"first","affiliation":[{"name":"Institute of Optoelectronics, Military University of Technology, 00-908 Warsaw, Poland"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8048-2609","authenticated-orcid":false,"given":"Grzegorz","family":"Bieszczad","sequence":"additional","affiliation":[{"name":"Institute of Optoelectronics, Military University of Technology, 00-908 Warsaw, Poland"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3556-0297","authenticated-orcid":false,"given":"Zbigniew","family":"Piotrowski","sequence":"additional","affiliation":[{"name":"Faculty of Electronics, Military University of Technology, 00-908 Warsaw, Poland"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2021,9,18]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","unstructured":"Cox, I., Miller, M., Bloom, J., Fridrich, J., and Kalker, T. (2007). Digital Watermarking and Steganography, Morgan Kaufmann.","DOI":"10.1016\/B978-012372585-1.50015-2"},{"key":"ref_2","doi-asserted-by":"crossref","unstructured":"Mishra, R., and Bhanodiya, P. (2015, January 19\u201320). A review on steganography and cryptography. Proceedings of the 2015 International Conference on Advances in Computer Engineering and Applications, Ghaziabad, India.","DOI":"10.1109\/ICACEA.2015.7164679"},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"225","DOI":"10.1109\/MCOM.2014.6815916","article-title":"Principles and overview of network steganography","volume":"52","author":"Lubacz","year":"2014","journal-title":"IEEE Commun. Mag."},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"1229","DOI":"10.1109\/JPROC.2014.2334493","article-title":"Hardware Trojan Attacks: Threat Analysis and Countermeasures","volume":"102","author":"Bhunia","year":"2014","journal-title":"Proc. IEEE"},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"115","DOI":"10.1016\/j.future.2020.08.045","article-title":"Magneto: Covert channel between air-gapped systems and nearby smartphones via cpu-generated magnetic fields","volume":"115","author":"Guri","year":"2021","journal-title":"Future Gener. Comput. Syst."},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"69","DOI":"10.1016\/j.future.2021.03.025","article-title":"Exfiltrating data from air-gapped computers via ViBrAtIoNs","volume":"122","author":"Guri","year":"2021","journal-title":"Future Gener. Comput. Syst."},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"31","DOI":"10.1109\/MITP.2018.032501746","article-title":"The new threats of information hiding: The road ahead","volume":"20","author":"Cabaj","year":"2018","journal-title":"IT Prof."},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"86","DOI":"10.1145\/2566590.2566610","article-title":"Trends in steganography","volume":"57","author":"Mazurczyk","year":"2014","journal-title":"Commun. ACM"},{"key":"ref_9","doi-asserted-by":"crossref","unstructured":"Wendzel, S., Mazurczyk, W., Caviglione, L., and Meier, M. (2014). Hidden and uncontrolled\u2013on the emergence of network steganographic threats. ISSE 2014 Securing Electronic Business Processes, Springer.","DOI":"10.1007\/978-3-658-06708-3_9"},{"key":"ref_10","doi-asserted-by":"crossref","unstructured":"Tanwar, R., Malhotra, S., and Singh, K. (2019). Future of Data Hiding: A Walk Through Conventional to Network Steganography. International Conference on Recent Developments in Science, Engineering and Technology, Springer.","DOI":"10.1007\/978-981-15-5830-6_11"},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"Venkatraman, S., Abraham, A., and Paprzycki, M. (2004, January 5\u20137). Significance of steganography on data security. Proceedings of the International Conference on Information Technology: Coding and Computing, 2004, Proceedings, ITCC 2004, Las Vegas, NV, USA.","DOI":"10.1109\/ITCC.2004.1286660"},{"key":"ref_12","first-page":"4634","article-title":"Steganography and its Applications in Security","volume":"2","author":"Doshi","year":"2012","journal-title":"Int. J. Mod. Eng. Res. (IJMER)"},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"283","DOI":"10.1016\/j.comnet.2018.11.025","article-title":"Current research on Internet of Things (IoT) security: A survey","volume":"148","author":"Hassan","year":"2019","journal-title":"Comput. Netw."},{"key":"ref_14","first-page":"1","article-title":"AI-empowered IoT security for smart cities","volume":"21","author":"Lv","year":"2021","journal-title":"ACM Trans. Internet Technol."},{"key":"ref_15","doi-asserted-by":"crossref","first-page":"17","DOI":"10.1109\/MCE.2019.2953740","article-title":"Consumer IoT: Security vulnerability case studies and solutions","volume":"9","author":"Alladi","year":"2020","journal-title":"IEEE Consum. Electron. Mag."},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Xu, L., Zhou, X., Tao, Y., Liu, L., Yu, X., and Kumar, N. (2021). Intelligent Security Performance Prediction for IoT-Enabled Healthcare Networks Using Improved CNN. IEEE Trans. Ind. Inform.","DOI":"10.1109\/TII.2021.3082907"},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"495","DOI":"10.1016\/j.comcom.2020.01.016","article-title":"Deep learning and big data technologies for IoT security","volume":"151","author":"Amanullah","year":"2020","journal-title":"Comput. Commun."},{"key":"ref_18","unstructured":"(2021, July 05). McAfee Labs Threats Report. Available online: Http:\/\/mcafee.ly\/2sXowrq."},{"key":"ref_19","unstructured":"Securelist (2021, July 07). Steganography in Contemporary Cyberattacks. Available online: https:\/\/securelist.com\/steganography-in-contemporary-cyberattacks\/79276\/."},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/2684195","article-title":"Pattern-based survey and categorization of network covert channel techniques","volume":"47","author":"Wendzel","year":"2015","journal-title":"ACM Comput. Surv. (CSUR)"},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Qiao, G., Zhao, Y., Liu, S., and Bilal, M. (2017). Dolphin sounds-inspired covert underwater acoustic communication and micro-modem. Sensors, 17.","DOI":"10.3390\/s17112447"},{"key":"ref_22","doi-asserted-by":"crossref","first-page":"610","DOI":"10.1016\/j.procs.2016.02.107","article-title":"Secure localisation of wireless devices with application to sensor networks using steganography","volume":"78","author":"Tondwalkar","year":"2016","journal-title":"Procedia Comput. Sci."},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Murdoch, S.J., and Lewis, S. (2005). Embedding covert channels into TCP\/IP. International Workshop on Information Hiding, Springer.","DOI":"10.1007\/11558859_19"},{"key":"ref_24","doi-asserted-by":"crossref","unstructured":"Rowland, C.H. (2021, July 25). Covert Channels in the TCP\/IP Protocol Suite 1997. Available online: https:\/\/firstmonday.org\/ojs\/index.php\/fm\/article\/download\/528\/449.","DOI":"10.5210\/fm.v2i5.528"},{"key":"ref_25","unstructured":"Ahsan, K., and Kundur, D. (2002, January 6). Practical data hiding in TCP\/IP. Proceedings of the Workshop on Multimedia Security at ACM Multimedia, Juan-les-Pins, France."},{"key":"ref_26","unstructured":"Piotrowski, Z., Sawicki, K., Bednarczyk, M., and Gajewski, P. (2010, January 15\u201317). New hidden and secure data transmission method proposal for military IEEE 802.11 networks. Proceedings of the 2010 Sixth International Conference on Intelligent Information Hiding and Multimedia Signal Processing, Darmstadt, Germany."},{"key":"ref_27","unstructured":"Jones, E., Le Moigne, O., and Robert, J.M. (2008). IP Time to Live (TTL) Field Used as a Covert Channel. (7,415,018), U.S. Patent."},{"key":"ref_28","unstructured":"Zander, S., Armitage, G., and Branch, P. (2021, July 15). Covert Channels in the IP Time to Live Field. Available online: https:\/\/researchrepository.murdoch.edu.au\/id\/eprint\/35012\/1\/covert%20channels.pdf."},{"key":"ref_29","doi-asserted-by":"crossref","unstructured":"Sawicki, K., and Piotrowski, Z. (2012, January 21\u201323). The proposal of IEEE 802.11 network access point authentication mechanism using a covert channel. Proceedings of the 2012 19th International Conference on Microwaves, Radar & Wireless Communications, Warsaw, Poland.","DOI":"10.1109\/MIKON.2012.6233587"},{"key":"ref_30","doi-asserted-by":"crossref","unstructured":"Frikha, L., Trabelsi, Z., and El-Hajj, W. (2008, January 6\u20138). Implementation of a Covert Channel in the 802.11 Header. Proceedings of the 2008 International Wireless Communications and Mobile Computing Conference, Crete, Greece.","DOI":"10.1109\/IWCMC.2008.103"},{"key":"ref_31","doi-asserted-by":"crossref","unstructured":"Nair, A.S., Kumar, A., Sur, A., and Nandi, S. (2011, January 27\u201329). Length based network steganography using UDP protocol. Proceedings of the 2011 IEEE 3rd International Conference on Communication Software and Networks, Xi\u2019an, China.","DOI":"10.1109\/ICCSN.2011.6014994"},{"key":"ref_32","unstructured":"Szczypiorski, K. (2003, January 22\u201324). HICCUPS: Hidden communication system for corrupted networks. Proceedings of the International Multi-Conference on Advanced Computer Systems, Mi\u0119dzyzdroje, Poland."},{"key":"ref_33","doi-asserted-by":"crossref","first-page":"135","DOI":"10.1016\/j.adhoc.2009.04.006","article-title":"Covert channels in ad-hoc wireless networks","volume":"8","author":"Li","year":"2010","journal-title":"Ad Hoc Netw."},{"key":"ref_34","doi-asserted-by":"crossref","unstructured":"Holloway, R., and Beyah, R. (2011, January 17\u201322). Covert DCF: A DCF-based covert timing channel in 802.11 networks. Proceedings of the 2011 IEEE Eighth International Conference on Mobile Ad-Hoc and Sensor Systems, Valencia, Spain.","DOI":"10.1109\/MASS.2011.60"},{"key":"ref_35","doi-asserted-by":"crossref","unstructured":"Sellke, S.H., Wang, C.C., Bagchi, S., and Shroff, N. (2009, January 19\u201325). TCP\/IP timing channels: Theory to implementation. Proceedings of the IEEE INFOCOM 2009, Rio de Janeiro, Brazil.","DOI":"10.1109\/INFCOM.2009.5062145"},{"key":"ref_36","doi-asserted-by":"crossref","first-page":"3388","DOI":"10.1002\/sec.1545","article-title":"Adaptive ternary timing covert channel in IEEE 802.11","volume":"9","author":"Tahmasbi","year":"2016","journal-title":"Secur. Commun. Netw."},{"key":"ref_37","doi-asserted-by":"crossref","unstructured":"Mohamed, E.E., Mnaouer, A.B., and Barka, E. (2016, January 7\u201310). PSCAN: A Port Scanning Network Covert Channel. Proceedings of the 2016 IEEE 41st Conference on Local Computer Networks (LCN), Dubai, United Arab Emirates.","DOI":"10.1109\/LCN.2016.109"},{"key":"ref_38","doi-asserted-by":"crossref","first-page":"564","DOI":"10.1109\/PROC.1980.11696","article-title":"The technology of error-correcting codes","volume":"68","author":"Berlekamp","year":"1980","journal-title":"Proc. IEEE"},{"key":"ref_39","doi-asserted-by":"crossref","unstructured":"Van Wonterghem, J., Alloum, A., Boutros, J.J., and Moeneclaey, M. (2016, January 22\u201322). Performance comparison of short-length error-correcting codes. Proceedings of the 2016 Symposium on Communications and Vehicular Technologies (SCVT), Mons, Belgium.","DOI":"10.1109\/SCVT.2016.7797660"}],"container-title":["Sensors"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1424-8220\/21\/18\/6268\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T07:01:54Z","timestamp":1760166114000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1424-8220\/21\/18\/6268"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,9,18]]},"references-count":39,"journal-issue":{"issue":"18","published-online":{"date-parts":[[2021,9]]}},"alternative-id":["s21186268"],"URL":"https:\/\/doi.org\/10.3390\/s21186268","relation":{},"ISSN":["1424-8220"],"issn-type":[{"value":"1424-8220","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021,9,18]]}}}