Wireless technology has become a main player in communication through its desirable mobility characteristic. However, like many technologies, there are ways that it can be exploited. One of these ways is through side-channel communication, whereby secret messages are passed along by the purposeful corruption of frames. These side channels can be established by intentionally corrupting the Frame Check Sequence (FCS) field by using a Cyclic Redundancy Check (CRC) polynomial that is different from the standard CRC polynomial. Malicious nodes can exploit the fact that normal unsuspecting nodes will drop these frames since they appear as naturally corrupted frames. This paper presents a CRC Hamming distance metric as a feature for the detection of this type of side-channel communication. We previously proposed the use of Hamming distance as a metric to compare CRC values that are generated by different CRC polynomials. The hypothesis is that the mean Hamming distance between two CRC values generated by two different CRC polynomials would be significantly far apart than the mean Hamming distance of a CRC value of a frame that was naturally corrupted but was generated by the same CRC polynomial. Previously, to test that hypothesis, we used F-Scores on real data experiments under varying noisy conditions and side-channel throughput to show that there is a consistent and significant difference between the mean Hamming values of naturally corrupted frames to those that use the Koopman polynomial to calculate the CRC for side-channel communications. In the present work we evaluate the Hamming distance using Perceptron Learning and the Pocket Algorithm to classify packets as side-channel or otherwise.
Wireless technology has become a main player in communication through its desirable mobility characteristic. However, like many technologies, there are ways that it can be exploited. One of these ways is through side-channel communication, whereby secret messages are passed along by the purposeful corruption of frames. These side channels can be established by intentionally corrupting the Frame Check Sequence (FCS) field by using a Cyclic Redundancy Check (CRC) polynomial that is different from the standard CRC polynomial. Malicious nodes can exploit the fact that normal unsuspecting nodes will drop these frames since they appear as naturally corrupted frames. This paper presents a CRC Hamming distance metric as a feature for the detection of this type of side-channel communication. The proposed detection method applies the Hamming distance measure to compare CRC values that are generated by different CRC polynomials. The hypothesis is that the mean Hamming distance between two CRC values generated by two different CRC polynomials would be significantly far apart than the mean Hamming distance of a CRC value of a frame that was naturally corrupted but was generated by the same CRC polynomial. The results of our real data experiments show that the there is a consistent and significant difference between the mean Hamming values of naturally corrupted frames to those that use the Koopman polynomial to calculate the CRC for side-channel communications. The analysis of the results also demonstrate that the difference of the CRC values that have the the maximum F-Score vary between 10-14 under varying noisy conditions and side-channel throughput.
In this paper, we present the necessary methods and techniques for simulating a wide-band multi-hop side-channel between two distant peer nodes in a Mobile Ad hoc Network (MANET). Simulating such a side-channel is helpful in understanding its potential and experimenting with its cyber warfare benefits, and for discovering effective ways to detect it. Implementing a content-bearing side-channel in which the full frame payload is used for messaging requires the ability to access the full communication stack in the simulator. We have implemented a fully functional multi-hop side-channel on the EXata/Cyber (QualNet) simulation tool to a level of detail where it could potentially be used in-line with applications such as voice or video for real-time, real-life emulations. We provide the details of our implementation and evidence of the benefits of such a side-channel via test scenarios. Such simulations may be used to facilitate military personnel's understanding of the effects cyber tools may have on their operations, in particular, Adaptive Dispersed Operations where military units are mobile.