FINDING · DEFENSE

The hash-based filtering strategy shifts covert channel security from algorithm secrecy to key secrecy per Kerckhoffs's principle: even when the covert algorithm is fully exposed, an adversary without the pre-shared key cannot identify which sparse subset (~1/2^L) of packets carries covert data, transforming the detection problem from statistical pattern recognition to exhaustive key-space search. The authors recommend a minimum Input Key length of 128 bits.

From 2026-zou-hiding-trees-forestHiding the Trees in the Forest: Building Network Covert Channels with Hash-Based Covert Carrier Filtering · §3.2, §4.1, §4.2.4 · 2026 · arXiv preprint

Implications

Tags

censors
generic
techniques
ml-classifiertraffic-shapefully-encrypted-detect
defenses
randomizationsteganographymeta-resistance

Extracted by claude-sonnet-4-6 — review before relying.