A recent report on botnet threats (Dhamballa, 2010) provides a sobering
read for any security professional. According to its authors, the
number of computers that fell victim to botnets grew at the rate of
8%/week in 2010, which translates to more than a six-fold increase over
the course of the year.
A covert data channel is a communications channel that is hidden within
the medium of a legitimate communications channel. Covert channels
manipulate a communications medium in an unexpected or unconventional
way in order to transmit information in an almost undetectable fashion.
Otherwise said, a covert data channel transfers arbitrary bytes between
two points in a fashion that would appear legitimate to someone
scrutinizing the exchange. (Bingham, 2006)
Keeping data from leaking out of protected networks is becoming
increasingly difficult due to the increase of malicious code that sends
data from infected systems.
Steganography is the practice of concealing information in channels
that superficially appear benign. The National Institute of Standards
and Technology defines a covert channel as any communication channel
that can be exploited
Although the current threat of steganographic technology appears to lag
its usefulness, the diligent information systems person needs to be
mindful of the security ramifications that a covert channel in their
enterprise carries.