| Vulnerability/ies (Wuyts, 2015) | Conditions for relevance | Rationale |
|---|---|---|
| A Side channel analysis (D_df2) is based on timing information, power consumption, electromagnetic leaks, etc. It can be used as a source of information which can be exploited to detect the communication. | Do any actions lead to generate footprints in the communication channel? (e.g., Timing information, power consumption, electromagnetic leaks) | If there are no actions generating footprints in the communication channel, the vulnerability is not relevant. |
| B Transmitted data can become detectable when there is no or insufficient dummy traffic (D_DF4) sent at some lower layer of the communication network, such that messages fail to appear random for all parties except the sender and the recipient(s). | Is data traffic in the channel very low? | If the traffic is not low, this vulnerability may not be relevant. |
| C When weak information hiding techniques (D_df3) are used, steganalysis attacks (D_df8) are possible (detecting messages hidden using steganography). | Channel not encrypted? | If channel is not encrypted, low entropy of unencrypted data facilitates steganography attacks. |
| D Detectability of a data flow may happen if the system uses a covert channel in the wrong way (D_df6, D_df7, D_df12, D_df13). | Covert channel used to avoid detectability? | If covert channel is not used these vulnerabilities are not relevant. |
| E The detectability threat can occur because of a weak spread spectrum communication (D_df5), resulting in deficiencies in the establishment of secure communications (allowing eavesdropping (D_df9)), insufficient resistance to natural interference and jamming (D_df10), and insufficient resistance to fading (D_df11). | Is the communication channel wireless? | These vulnerabilities are relevant if the communication is performed on a wireless channel. |
| Vulnerability/ies ( | Conditions for relevance | Rationale |
|---|---|---|
| Do any actions lead to generate footprints in the communication channel? (e.g., Timing information, power consumption, electromagnetic leaks) | If there are no actions generating footprints in the communication channel, the vulnerability is not relevant. | |
| Is data traffic in the channel very low? | If the traffic is not low, this vulnerability may not be relevant. | |
| Channel not encrypted? | If channel is not encrypted, low entropy of unencrypted data facilitates steganography attacks. | |
| Covert channel used to avoid detectability? | If covert channel is not used these vulnerabilities are not relevant. | |
| Is the communication channel wireless? | These vulnerabilities are relevant if the communication is performed on a wireless channel. |
Sharing content requires targeting cookies to be enabled. Please update your cookie preferences to use this feature.