Helol Tunnel: Covert Channel Exploitation of TLS Extensibility & Privacy Features
Reza Soosahabi, Rakesh Seal
Abstract
Covert channels exploiting network protocols for data exfiltration and command-and-control (C2) are integral parts of modern cyberattacks. In search of a significant covert channel within the fabric of the Internet, we targeted the combinatorial properties of the Client Hello (CHLO) packets in the ubiquitous Transport Layer Security (TLS) protocol. The proposed Helol tunnel is a novel covert approach to embedding information in TLS Client Hello packets, which involves the strategic rearrangement of their cryptographic information elements. To sustain TLS protocol extensibility, the recent anti-ossification TLS compliance measures encourage the interactive middleboxes and next-generation firewalls (NGFWs) to preserve the parameter configuration in the Client Hello packets. Furthermore, to improve user privacy, popular Internet applications are varying their TLS CHLO parameter configurations to resist TLS fingerprinting by third-party network entities. We demonstrate the strength of the Helol tunnel to exploit these recent developments to evade NGFWs with interactive proxy and comprehensive threat protection. We also numerically show the efficacy of Helol tunneling over state-of-the-art covert channels that exploit TLS through the use of real traffic captures and public TLS fingerprinting data.
Create a lesson
Related papers
System-Level Optimization Beyond Cryptographic Kernels: An ML-KEM Case Study on Arm Cortex-M7
Mahmoud Abdelhafeez Sayed, Mostafa Taha, Gurp Nijjer
A Hybrid Approach to Malware Detection: Integrating Few-Shot Model-Agnostic Meta-Learning with Autoencoders
Emmanuela Andam, Yasir Abbas Zaidi, Abdelali Hadir et al.
Detection and Resolution of Periodic Artifacts in OpenDP's Discrete Laplace Sampler
Cesare Gerolimetto Fabrello, Valeria Rossi, Alberto Trombetta et al.
A Structured State Space Sequence Model for Multi-Class Classification of Malware
Emmanuela Andam, Rana Shaaban, Emanuel Grant et al.
From Network Intrusion Detection to Blockchain-Backed Endpoint Detection and Response: Mapping the Landscape of Decentralized Detection-and-Response Architectures
Yahya Shahsavari, Sara Rouhani, Kaiwen Zhang
Walking the Embedding Space: Datastore Extraction from Multimodal RAG
Maria Carmen Jica, Ali Satvaty, Suzan Verberne et al.