TimeLSB: eBPF-based Covert Channel on TCP Timestamps
21st International Conference on Network and Service Management, CNSM 2025, Bologna, Hindistan, 27 - 31 Ekim 2025, (Tam Metin Bildiri)
- Yayın Türü: Bildiri / Tam Metin Bildiri
- Doi Numarası: 10.23919/cnsm67658.2025.11297460
- Basıldığı Şehir: Bologna
- Basıldığı Ülke: Hindistan
- Anahtar Kelimeler: covert channel, eBPF, in-kernel packet processing, tc, TCP, TCP timestamp option
- Orta Doğu Teknik Üniversitesi Adresli: Evet
Özet
This paper presents TimeLSB, a covert channel built on TCP timestamps using extended Berkeley Packet Filter (eBPF) technology. The channel encodes information by modifying the least significant bit of timestamp values through a CRC32-based scheme in the Linux kernel, while a passive receiver reconstructs the hidden message. We implement and evaluate this channel under a range of controlled network impairments, demonstrating that embedding covert bits does not significantly alter the behavior of normal TCP connections. The eBPF implementation introduces only on average 250 ns of processing overhead per packet, which corresponds to several million packets per second and is negligible compared to typical forwarding performance. Finally, we analyze detectability using the distinct-timestamp ratio, showing that while absolute values differ from prior work, the metric still provides a stable separation between covert and normal flows. These results highlight the practicality of an eBPFbased covert channel and provide defensive insights for network security operations.