<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.3 20210610//EN" "https://jats.nlm.nih.gov/publishing/1.3/JATS-journalpublishing1-3.dtd">
<article article-type="research-article" dtd-version="1.3" xml:lang="en">
  <front xmlns:xlink="http://www.w3.org/1999/xlink">
    <journal-meta>
      <journal-id journal-id-type="elibrary">9004</journal-id>
      <journal-title-group>
        <journal-title>Problems of information security. Computer systems</journal-title>
        <trans-title-group xml:lang="ru">
          <trans-title>Проблемы информационной безопасности. Компьютерные системы</trans-title>
        </trans-title-group>
      </journal-title-group>
      <issn pub-type="epub">2071-8217</issn>
    </journal-meta>
    <article-meta xmlns:xlink="http://www.w3.org/1999/xlink">
      <article-id pub-id-type="publisher-id">5</article-id>
      <article-id pub-id-type="doi">10.48612/jisp/r5fz-um2f-mh48</article-id>
      <title-group>
        <article-title>Covert storage channels in the TLS protocol</article-title>
        <trans-title-group xml:lang="ru">
          <trans-title>Скрытые каналы по памяти в протоколе TLS</trans-title>
        </trans-title-group>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <contrib-id contrib-id-type="orcid">0000-0003-4374-1645</contrib-id>
          <name>
            <surname>Finoshin</surname>
            <given-names>Mikhail</given-names>
          </name>
          <xref ref-type="aff" rid="aff1"/>
          <email>MAFinoshin@mephi.ru</email>
        </contrib>
        <contrib contrib-type="author">
          <contrib-id contrib-id-type="orcid">0000-0003-3022-8973</contrib-id>
          <name>
            <surname>Ivanova</surname>
            <given-names>Irina</given-names>
          </name>
          <xref ref-type="aff" rid="aff2"/>
          <email>iid.ivanova@yandex.ru</email>
        </contrib>
        <contrib contrib-type="author">
          <contrib-id contrib-id-type="orcid">0000-0002-4429-8799</contrib-id>
          <contrib-id contrib-id-type="scopus">55229487100</contrib-id>
          <name>
            <surname>Zhukov</surname>
            <given-names>Igor</given-names>
          </name>
          <xref ref-type="aff" rid="aff1"/>
          <email>i.zhukov@inbox.ru</email>
        </contrib>
        <contrib contrib-type="author">
          <name>
            <surname>Zuikov</surname>
            <given-names>Alexander</given-names>
          </name>
          <xref ref-type="aff" rid="aff3"/>
          <email>az@hex.team</email>
        </contrib>
      </contrib-group>
      <aff id="aff1">National Research Nuclear University MEPhI (Moscow Engineering Physics Institute)</aff>
      <aff id="aff2">Russian University of Transport (MIIT)</aff>
      <aff id="aff3">LLC Hexagon</aff>
      <pub-date publication-format="electronic" date-type="pub" iso-8601-date="2024-12-20">
        <day>20</day>
        <month>12</month>
        <year>2024</year>
      </pub-date>
      <issue>4</issue>
      <fpage>53</fpage>
      <lpage>62</lpage>
      <self-uri xmlns:xlink="http://www.w3.org/1999/xlink" content-type="pdf" xlink:href="https://jisp.spbstu.ru/userfiles/files/soderzhaniya/2024_4-7-8.pdf"/>
      <abstract xml:lang="en">
        <p>Protection methods against TLS covert storage channels using the Random and SessionID fields of the ClientHello message are proposed. Protection means have been developed using the proposed protection methods: a module for IDS/IPS Suricata that filters TLS packets depending on the SessionID contents, and a proxy server that reformats packets transmitted to the communication environment. A comparative analysis of the implemented protection means was carried out from the point of view of their impact on the communication channel bandwidth and their effectiveness in the secret information transfer countering. The developed protection means are applicable for integration into existing protection systems against network covert channels. Recommendations on the use of proposed protection means depending on the desired level of security are given</p>
      </abstract>
      <kwd-group xml:lang="en">
        <kwd>secret information</kwd>
        <kwd>ClientHello message</kwd>
        <kwd>Random</kwd>
        <kwd>SessionID field</kwd>
        <kwd>proxy server</kwd>
        <kwd>filtering mean</kwd>
      </kwd-group>
    </article-meta>
  </front>
</article>
