×

IP Time to Live (TTL) field used as a covert channel

  • US 7,415,018 B2
  • Filed: 09/17/2003
  • Issued: 08/19/2008
  • Est. Priority Date: 09/17/2003
  • Status: Active Grant
First Claim
Patent Images

1. A method of determining, in a communications network, an upstream station, among several other candidates, traversed by a packet having a time-to-live (TTL) field arriving at a downstream station, comprising the steps of:

  • a) marking the TTL field of the packet flow arriving at the upstream station, in a manner that uniquely identifies the upstream station among all the other concurrently marking upstream stations;

    b) receiving and identifying at the downstream station a marked packet flow; and

    c) determining, depending upon the TTL field of the marked packet flow received, that said packet flow traversed the upstream station;

    wherein the TTL field of the marked packet is identified by looking for constant shifts in statistical parameters and in the distributed TTL value with marking turned on and turned off.

View all claims
  • 12 Assignments
Timeline View
Assignment View
    ×
    ×