SharkFest'26 Europe

Daniel Spiekermann

Daniel Spiekermann has more than 20 years of experience in communications technology and worked for many years as a forensic scientist for various law enforcement agencies, focusing on computer and network forensics. After completing his doctorate at the FernUniversität in Hagen in 2019, he began working as a professor of digital forensics at the Lower Saxony Police Academy in 2020. Since 2023, he has been teaching as a professor of distributed systems at the Dortmund University of Applied Sciences and Arts, conducting research on virtual networks and digital forensics.


Session

11-04
16:00
60min
Detecting Network based Covert Channels with Wireshark
Daniel Spiekermann

Modern network security mechanisms primarily focus on detecting known attack signatures and anomalous traffic volumes. However, network-based covert channels present a sophisticated threat by exfiltrating data and establishing Command-and-Control (C2) communication disguised as legitimate traffic. By manipulating protocol fields within standard suites—such as DNS, ICMP, or TCP headers—adversaries can bypass perimeter defenses undetected. The presentation begins with a structured introduction to the fundamentals of covert channels, establishing a theoretical foundation for their categorization and mechanics. Following this introduction, I will demonstrate practical detection methodologies directly within Wireshark using real-world traffic captures.

Security
Room 2