CYPRESS: Transferring Secrets in the Shadow of Visible Packets
Sirus Shahini, Robert Ricci

TL;DR
CYPRESS introduces a practical, reliable covert communication framework that leverages regular network packets to transmit secret data at high speeds, bypassing security measures and evading detection.
Contribution
The paper presents CYPRESS, a novel decentralized framework for covert channels that dynamically manages multiple protocol-specific hidden communication methods.
Findings
Achieves up to 1.6MB/s secret bandwidth.
Demonstrates robustness in real-world security-sensitive scenarios.
Effectively bypasses security measures and hides attack sources.
Abstract
Network steganography and covert communication channels have been studied extensively in the past. However, prior works offer minimal practical use for their proposed techniques and are limited to specific use cases and network protocols. In this paper, we show that covert channels in networking have a much greater potential for practical secret communication than what has been discussed before. We present a covert channel framework, CYPRESS, that creates a reliable hidden communication channel by mounting packets from secret network entities on regular packets that flow through the network, effectively transmitting a separate network traffic without generating new packets for it. CYPRESS establishes a consolidated decentralized framework in which different covert channels for various protocols are defined with their custom handler code that are plugged into the system and updated…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsInternet Traffic Analysis and Secure E-voting · Network Security and Intrusion Detection · Advanced Steganography and Watermarking Techniques
