{"id":"https://openalex.org/W2973226827","doi":"https://doi.org/10.3390/info10090284","title":"Another Step in the Ladder of DNS-Based Covert Channels: Hiding Ill-Disposed Information in DNSKEY RRs","display_name":"Another Step in the Ladder of DNS-Based Covert Channels: Hiding Ill-Disposed Information in DNSKEY RRs","publication_year":2019,"publication_date":"2019-09-12","ids":{"openalex":"https://openalex.org/W2973226827","doi":"https://doi.org/10.3390/info10090284","mag":"2973226827"},"language":"en","primary_location":{"id":"doi:10.3390/info10090284","is_oa":true,"landing_page_url":"https://doi.org/10.3390/info10090284","pdf_url":"https://www.mdpi.com/2078-2489/10/9/284/pdf","source":{"id":"https://openalex.org/S4210219776","display_name":"Information","issn_l":"2078-2489","issn":["2078-2489"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":"https://openalex.org/P4310310987","host_organization_name":"Multidisciplinary Digital Publishing Institute","host_organization_lineage":["https://openalex.org/P4310310987"],"host_organization_lineage_names":["Multidisciplinary Digital Publishing Institute"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Information","raw_type":"journal-article"},"type":"article","indexed_in":["crossref","doaj"],"open_access":{"is_oa":true,"oa_status":"gold","oa_url":"https://www.mdpi.com/2078-2489/10/9/284/pdf","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5059647371","display_name":"\u039c\u03ac\u03c1\u03b9\u03bf\u03c2 \u0391\u03bd\u03b1\u03b3\u03bd\u03c9\u03c3\u03c4\u03cc\u03c0\u03bf\u03c5\u03bb\u03bf\u03c2","orcid":"https://orcid.org/0000-0002-9193-8517"},"institutions":[{"id":"https://openalex.org/I204778367","display_name":"Norwegian University of Science and Technology","ror":"https://ror.org/05xg72x27","country_code":"NO","type":"education","lineage":["https://openalex.org/I204778367"]}],"countries":["NO"],"is_corresponding":true,"raw_author_name":"Marios Anagnostopoulos","raw_affiliation_strings":["Department of Information Security and Communication Technology, Norwegian University of Science &amp; Technology, 2802 Gj\u00f8vik, Norway"],"raw_orcid":"https://orcid.org/0000-0002-9193-8517","affiliations":[{"raw_affiliation_string":"Department of Information Security and Communication Technology, Norwegian University of Science &amp; Technology, 2802 Gj\u00f8vik, Norway","institution_ids":["https://openalex.org/I204778367"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5001859732","display_name":"John Andr\u00e9 Seem","orcid":null},"institutions":[{"id":"https://openalex.org/I204778367","display_name":"Norwegian University of Science and Technology","ror":"https://ror.org/05xg72x27","country_code":"NO","type":"education","lineage":["https://openalex.org/I204778367"]}],"countries":["NO"],"is_corresponding":false,"raw_author_name":"John Andr\u00e9 Seem","raw_affiliation_strings":["Department of Information Security and Communication Technology, Norwegian University of Science &amp; Technology, 2802 Gj\u00f8vik, Norway"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Department of Information Security and Communication Technology, Norwegian University of Science &amp; Technology, 2802 Gj\u00f8vik, Norway","institution_ids":["https://openalex.org/I204778367"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":2,"corresponding_author_ids":["https://openalex.org/A5059647371"],"corresponding_institution_ids":["https://openalex.org/I204778367"],"apc_list":{"value":1400,"currency":"CHF","value_usd":1515},"apc_paid":{"value":1400,"currency":"CHF","value_usd":1515},"fwci":0.1451,"has_fulltext":true,"cited_by_count":1,"citation_normalized_percentile":{"value":0.58507767,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":89,"max":94},"biblio":{"volume":"10","issue":"9","first_page":"284","last_page":"284"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11598","display_name":"Internet Traffic Analysis and Secure E-voting","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11598","display_name":"Internet Traffic Analysis and Secure E-voting","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9988999962806702,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9973999857902527,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/covert-channel","display_name":"Covert channel","score":0.87347412109375},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.7282576560974121},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.6893078088760376},{"id":"https://openalex.org/keywords/covert","display_name":"Covert","score":0.6716430187225342},{"id":"https://openalex.org/keywords/encryption","display_name":"Encryption","score":0.5127049684524536},{"id":"https://openalex.org/keywords/channel","display_name":"Channel (broadcasting)","score":0.4824700653553009},{"id":"https://openalex.org/keywords/context","display_name":"Context (archaeology)","score":0.4787939488887787},{"id":"https://openalex.org/keywords/computer-network","display_name":"Computer network","score":0.46930673718452454},{"id":"https://openalex.org/keywords/protocol","display_name":"Protocol (science)","score":0.43517422676086426},{"id":"https://openalex.org/keywords/key","display_name":"Key (lock)","score":0.42989301681518555},{"id":"https://openalex.org/keywords/cloud-computing-security","display_name":"Cloud computing security","score":0.13014551997184753},{"id":"https://openalex.org/keywords/security-information-and-event-management","display_name":"Security information and event management","score":0.11742806434631348},{"id":"https://openalex.org/keywords/cloud-computing","display_name":"Cloud computing","score":0.07632693648338318}],"concepts":[{"id":"https://openalex.org/C29024540","wikidata":"https://www.wikidata.org/wiki/Q1476964","display_name":"Covert channel","level":5,"score":0.87347412109375},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.7282576560974121},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6893078088760376},{"id":"https://openalex.org/C2779338814","wikidata":"https://www.wikidata.org/wiki/Q5179285","display_name":"Covert","level":2,"score":0.6716430187225342},{"id":"https://openalex.org/C148730421","wikidata":"https://www.wikidata.org/wiki/Q141090","display_name":"Encryption","level":2,"score":0.5127049684524536},{"id":"https://openalex.org/C127162648","wikidata":"https://www.wikidata.org/wiki/Q16858953","display_name":"Channel (broadcasting)","level":2,"score":0.4824700653553009},{"id":"https://openalex.org/C2779343474","wikidata":"https://www.wikidata.org/wiki/Q3109175","display_name":"Context (archaeology)","level":2,"score":0.4787939488887787},{"id":"https://openalex.org/C31258907","wikidata":"https://www.wikidata.org/wiki/Q1301371","display_name":"Computer network","level":1,"score":0.46930673718452454},{"id":"https://openalex.org/C2780385302","wikidata":"https://www.wikidata.org/wiki/Q367158","display_name":"Protocol (science)","level":3,"score":0.43517422676086426},{"id":"https://openalex.org/C26517878","wikidata":"https://www.wikidata.org/wiki/Q228039","display_name":"Key (lock)","level":2,"score":0.42989301681518555},{"id":"https://openalex.org/C184842701","wikidata":"https://www.wikidata.org/wiki/Q370563","display_name":"Cloud computing security","level":3,"score":0.13014551997184753},{"id":"https://openalex.org/C103377522","wikidata":"https://www.wikidata.org/wiki/Q3493999","display_name":"Security information and event management","level":4,"score":0.11742806434631348},{"id":"https://openalex.org/C79974875","wikidata":"https://www.wikidata.org/wiki/Q483639","display_name":"Cloud computing","level":2,"score":0.07632693648338318},{"id":"https://openalex.org/C204787440","wikidata":"https://www.wikidata.org/wiki/Q188504","display_name":"Alternative medicine","level":2,"score":0.0},{"id":"https://openalex.org/C86803240","wikidata":"https://www.wikidata.org/wiki/Q420","display_name":"Biology","level":0,"score":0.0},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.0},{"id":"https://openalex.org/C138885662","wikidata":"https://www.wikidata.org/wiki/Q5891","display_name":"Philosophy","level":0,"score":0.0},{"id":"https://openalex.org/C71924100","wikidata":"https://www.wikidata.org/wiki/Q11190","display_name":"Medicine","level":0,"score":0.0},{"id":"https://openalex.org/C151730666","wikidata":"https://www.wikidata.org/wiki/Q7205","display_name":"Paleontology","level":1,"score":0.0},{"id":"https://openalex.org/C142724271","wikidata":"https://www.wikidata.org/wiki/Q7208","display_name":"Pathology","level":1,"score":0.0},{"id":"https://openalex.org/C41895202","wikidata":"https://www.wikidata.org/wiki/Q8162","display_name":"Linguistics","level":1,"score":0.0}],"mesh":[],"locations_count":4,"locations":[{"id":"doi:10.3390/info10090284","is_oa":true,"landing_page_url":"https://doi.org/10.3390/info10090284","pdf_url":"https://www.mdpi.com/2078-2489/10/9/284/pdf","source":{"id":"https://openalex.org/S4210219776","display_name":"Information","issn_l":"2078-2489","issn":["2078-2489"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":"https://openalex.org/P4310310987","host_organization_name":"Multidisciplinary Digital Publishing Institute","host_organization_lineage":["https://openalex.org/P4310310987"],"host_organization_lineage_names":["Multidisciplinary Digital Publishing Institute"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Information","raw_type":"journal-article"},{"id":"pmh:oai:doaj.org/article:a96979fabda343ee8dad98848907d9fb","is_oa":true,"landing_page_url":"https://doaj.org/article/a96979fabda343ee8dad98848907d9fb","pdf_url":null,"source":{"id":"https://openalex.org/S4306401280","display_name":"DOAJ (DOAJ: Directory of Open Access Journals)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by-sa","license_id":"https://openalex.org/licenses/cc-by-sa","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"Information, Vol 10, Iss 9, p 284 (2019)","raw_type":"article"},{"id":"pmh:oai:mdpi.com:/2078-2489/10/9/284/","is_oa":true,"landing_page_url":"http://dx.doi.org/10.3390/info10090284","pdf_url":null,"source":{"id":"https://openalex.org/S4306400947","display_name":"MDPI (MDPI AG)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I4210097602","host_organization_name":"Multidisciplinary Digital Publishing Institute (Switzerland)","host_organization_lineage":["https://openalex.org/I4210097602"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"Information","raw_type":"Text"},{"id":"pmh:oai:ntnuopen.ntnu.no:11250/2640905","is_oa":true,"landing_page_url":"http://hdl.handle.net/11250/2640905","pdf_url":null,"source":{"id":"https://openalex.org/S4306401716","display_name":"Duo Research Archive (University of Oslo)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I184942183","host_organization_name":"University of Oslo","host_organization_lineage":["https://openalex.org/I184942183"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"1-8","raw_type":"info:eu-repo/semantics/article"}],"best_oa_location":{"id":"doi:10.3390/info10090284","is_oa":true,"landing_page_url":"https://doi.org/10.3390/info10090284","pdf_url":"https://www.mdpi.com/2078-2489/10/9/284/pdf","source":{"id":"https://openalex.org/S4210219776","display_name":"Information","issn_l":"2078-2489","issn":["2078-2489"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":"https://openalex.org/P4310310987","host_organization_name":"Multidisciplinary Digital Publishing Institute","host_organization_lineage":["https://openalex.org/P4310310987"],"host_organization_lineage_names":["Multidisciplinary Digital Publishing Institute"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Information","raw_type":"journal-article"},"sustainable_development_goals":[{"display_name":"Industry, innovation and infrastructure","id":"https://metadata.un.org/sdg/9","score":0.550000011920929}],"awards":[],"funders":[{"id":"https://openalex.org/F4320311040","display_name":"Norges Teknisk-Naturvitenskapelige Universitet","ror":"https://ror.org/05xg72x27"}],"has_content":{"pdf":true,"grobid_xml":true},"content_urls":{"pdf":"https://content.openalex.org/works/W2973226827.pdf","grobid_xml":"https://content.openalex.org/works/W2973226827.grobid-xml"},"referenced_works_count":13,"referenced_works":["https://openalex.org/W85558978","https://openalex.org/W1572744584","https://openalex.org/W1989598342","https://openalex.org/W2000309792","https://openalex.org/W2004078625","https://openalex.org/W2022350629","https://openalex.org/W2136495567","https://openalex.org/W2202023669","https://openalex.org/W2605860169","https://openalex.org/W2762944945","https://openalex.org/W2948023660","https://openalex.org/W2963379686","https://openalex.org/W2987823657"],"related_works":["https://openalex.org/W2409612194","https://openalex.org/W4224042389","https://openalex.org/W174282171","https://openalex.org/W20460883","https://openalex.org/W1587013156","https://openalex.org/W4239080508","https://openalex.org/W2326198059","https://openalex.org/W4319780484","https://openalex.org/W4386088729","https://openalex.org/W4376311794"],"abstract_inverted_index":{"Covert":[0],"channel":[1,54],"communications":[2],"are":[3,17,144,156],"of":[4,11,19,34,44,61,85,91,95,119,175,199,214,237,248,263,284,292,305],"vital":[5],"importance":[6],"for":[7,58,74,234,245],"the":[8,27,31,41,59,89,120,151,165,173,177,196,204,211,222,235,246,279,289,293,303,306],"ill-motivated":[9],"purposes":[10,60],"cyber-crooks.":[12],"Through":[13],"these":[14],"channels,":[15],"they":[16],"capable":[18],"communicating":[20],"in":[21,111,158,226,253,278,299],"a":[22,51,62,93,108,138,147,183,215,249,261],"stealthy":[23,52],"way,":[24],"unnoticed":[25],"by":[26,127,132,171],"defenders":[28],"and":[29,77,134,154,191,273,275],"bypassing":[30],"security":[32,128,160],"mechanisms":[33],"protected":[35],"networks.":[36],"The":[37],"covert":[38,53,102,139,184,308],"channels":[39],"facilitate":[40],"hidden":[42],"distribution":[43,247],"data":[45,80,198,283],"to":[46,66,69,194,301],"internal":[47,83],"agents.":[48],"For":[49],"instance,":[50],"could":[55],"be":[56,231],"beneficial":[57,190],"botmaster":[63],"that":[64,123,188],"desires":[65],"send":[67],"commands":[68],"their":[70],"bot":[71],"army,":[72],"or":[73,130,240,243],"exfiltrating":[75],"corporate":[76],"sensitive":[78],"private":[79],"from":[81],"an":[82,86,200,238],"network":[84,96],"organization.":[87],"During":[88],"evolution":[90],"Internet,":[92],"plethora":[94],"protocols":[97,122],"has":[98,107],"been":[99],"exploited":[100,157,233],"as":[101,115,182,288],"channel.":[103,185,309],"DNS":[104,152,178,280,294],"protocol":[105,153],"however":[106],"prominent":[109,268],"position":[110],"this":[112,163,257],"exploitation":[113],"race,":[114],"it":[116,229],"is":[117,124,189],"one":[118],"few":[121,148],"rarely":[125],"restricted":[126],"policies":[129],"filtered":[131],"firewalls,":[133],"thus":[135],"fulfills":[136],"perfectly":[137],"channel\u2019s":[140],"requirements.":[141],"Therefore,":[142],"there":[143],"more":[145],"than":[146],"cases":[149],"where":[150],"infrastructure":[155],"well-known":[159],"incidents.":[161],"In":[162],"context,":[164],"work":[166],"at":[167],"hand":[168],"puts":[169],"forward":[170],"investigating":[172],"feasibility":[174],"exploiting":[176],"Security":[179],"Extensions":[180],"(DNSSEC)":[181],"We":[186],"demonstrate":[187,302],"quite":[192],"straightforward":[193],"embed":[195],"arbitrary":[197],"aggressor\u2019s":[201],"choice":[202,286],"within":[203],"DNSKEY":[205,220],"resource":[206],"record,":[207],"which":[208],"normally":[209],"provides":[210],"public":[212,223,290],"key":[213,224,291],"DNSSEC-enabled":[216],"domain":[217],"zone.":[218],"Since":[219],"contains":[221],"encoded":[225,252],"base64":[227,254],"format,":[228],"can":[230],"easily":[232],"dissemination":[236],"encrypted":[239],"stego":[241],"message,":[242],"even":[244],"malware\u2019s":[250],"binary":[251],"string.":[255],"To":[256],"end,":[258],"we":[259,276],"implement":[260],"proof":[262],"concept":[264],"based":[265],"on":[266],"two":[267],"nameserver":[269],"software,":[270],"namely":[271],"BIND":[272],"NDS,":[274],"publish":[277],"hierarchy":[281],"custom":[282],"our":[285,297],"concealed":[287],"zone":[295],"under":[296],"jurisdiction":[298],"order":[300],"effectiveness":[304],"proposed":[307]},"counts_by_year":[{"year":2021,"cited_by_count":1}],"updated_date":"2026-05-21T06:26:12.895304","created_date":"2025-10-10T00:00:00"}
