Covert L2/L3 tunneling via SIP signaling on embedded hardware: attack, evasion, and detection

Cargando...
Miniatura
Fecha
2026-10
Título de la revista
ISSN de la revista
Título del volumen
Editor
Academic Press
google-scholar
Resumen
Covert channels exploiting application-layer protocols represent a persistent threat in enterprise environments, particularly when targeting endpoints that remain outside the scope of endpoint detection and response solutions, such as embedded Voice over Internet Protocol (VoIP) phones. Existing SIP-based covert channels either embed low-bandwidth steganographic data within call-lifecycle signaling messages (Mazurczyk and Szczypiorski, 2008; Mehić et al., 2014; Tsiatsikas et al., 2015), or achieve higher capacity by requiring active Real-time Transport Protocol (RTP) media streams (Schmidt et al., 2018; Saenger et al., 2020). However, to our knowledge, no prior work implements continuous Layer 2/Layer 3 tunneling over standalone SIP signaling outside of call contexts, nor validates such a channel on real embedded hardware against multiple network intrusion detection systems. We present a covert channel that encapsulates arbitrary Ethernet frames and IP packets within SIP OPTIONS messages, which are lightweight requests typically used for NAT keep-alive and capability probing, without establishing any voice call. A portable proof-of-concept with TUN/TAP virtual interfaces and ChaCha20 symmetric encryption has been implemented and deployed on two ARM-based IP phones from different vendors, showing that even resource-constrained embedded devices can serve as covert network egress nodes. Empirical evasion testing against Suricata, Snort 3, Zeek, and a FortiGate firewall with full Unified Threat Management (UTM) services reveals that the channel achieves a secure operating bandwidth of 128 kbit/s without triggering alerts on any of the tested platforms. Analysis of the tested rulesets and parsers reveals the absence of entropy-based or header-length anomaly rules for Session Initiation Protocol (SIP), accounting for the detection gap. To address this, we implement a lightweight statistical detection mechanism that analyzes non-standard SIP header entropy, showing that the covert channel can be identified through targeted analysis of header content. The gap is not inherent to SIP: current rulesets inspect syntax but not header content, length, or entropy. Adding any of these features is sufficient to detect the channel, as shown by the Zeek script and Suricata 8 rule provided as supplementary material. A single entropy threshold can itself be evaded through low-entropy padding. We therefore show that multi-feature and anomaly-based detectors recover identification of the channel where the scalar test fails. We also contribute a synthetic benign SIP corpus, generated with SIPp to emulate multiple devices and signaling scenarios, released as supplementary material for evaluating false positives beyond the single legacy dataset previously available.
Palabras clave
Covert channels
NIDS
Red team
RTC
SIP
VoIP
Descripción
Materias
Cita
Gorrochategui, G., Zulaika, U., & Garaizar, P. (2026). Covert L2/L3 tunneling via SIP signaling on embedded hardware: attack, evasion, and detection. Journal of Network and Computer Applications, 254. https://doi.org/10.1016/J.JNCA.2026.104546
Colecciones