×

Method for identifying and blocking embedded communications

  • US 8,443,101 B1
  • Filed: 04/09/2010
  • Issued: 05/14/2013
  • Est. Priority Date: 05/24/2005
  • Status: Expired due to Fees
First Claim
Patent Images

1. A method for identifying embedded communications in a communication network, the method comprising:

  • establishing a baseline checksum failure rate measurement for packets communicated in accordance with a specified communication protocol in a predetermined route in a transport layer of the communication network;

    monitoring traffic on the predetermined route in the transport layer of the communication network to detect checksum failures of the packets;

    establishing a current checksum failure rate measurement based on the detected checksum failures;

    comparing the current checksum failure rate measurement with the baseline checksum failure rate measurement;

    when the current checksum failure rate measurement is greater than the baseline checksum failure rate measurement, determining an embedded communication of covert data is being communicated in the specified communication protocol; and

    blocking the embedded communication in the transport layer of the communication network by discarding packets having a detected checksum failure.

View all claims
  • 0 Assignments
Timeline View
Assignment View
    ×
    ×