Daniel Spiekermann
Daniel Spiekermann has more than 20 years of experience in communications technology and worked for many years as a forensic scientist for various law enforcement agencies, focusing on computer and network forensics. After completing his doctorate at the FernUniversität in Hagen in 2019, he began working as a professor of digital forensics at the Lower Saxony Police Academy in 2020. Since 2023, he has been teaching as a professor of distributed systems at the Dortmund University of Applied Sciences and Arts, conducting research on virtual networks and digital forensics.
Session
Modern network security mechanisms primarily focus on detecting known attack signatures and anomalous traffic volumes. However, network-based covert channels present a sophisticated threat by exfiltrating data and establishing Command-and-Control (C2) communication disguised as legitimate traffic. By manipulating protocol fields within standard suites—such as DNS, ICMP, or TCP headers—adversaries can bypass perimeter defenses undetected. The presentation begins with a structured introduction to the fundamentals of covert channels, establishing a theoretical foundation for their categorization and mechanics. Following this introduction, I will demonstrate practical detection methodologies directly within Wireshark using real-world traffic captures.