BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//conference.wireshark.org//sf26eu//talk//CS3YAN
BEGIN:VTIMEZONE
TZID:CET
BEGIN:STANDARD
DTSTART:20001029T040000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=10
TZNAME:CET
TZOFFSETFROM:+0200
TZOFFSETTO:+0100
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20000326T030000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=3
TZNAME:CEST
TZOFFSETFROM:+0100
TZOFFSETTO:+0200
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
UID:pretalx-sf26eu-CS3YAN@conference.wireshark.org
DTSTART;TZID=CET:20261104T160000
DTEND;TZID=CET:20261104T170000
DESCRIPTION:Modern network security mechanisms primarily focus on detecting
  known attack signatures and anomalous traffic volumes. However\, network-
 based covert channels present a sophisticated threat by exfiltrating data 
 and establishing Command-and-Control (C2) communication disguised as legit
 imate traffic. By manipulating protocol fields within standard suites—su
 ch as DNS\, ICMP\, or TCP headers—adversaries can bypass perimeter defen
 ses undetected. The presentation begins with a structured introduction to 
 the fundamentals of covert channels\, establishing a theoretical foundatio
 n for their categorization and mechanics. Following this introduction\, I 
 will demonstrate practical detection methodologies directly within Wiresha
 rk using real-world traffic captures.
DTSTAMP:20260922T091936Z
LOCATION:Room 2
SUMMARY:Detecting Network based Covert Channels with Wireshark - Daniel Spi
 ekermann
URL:https://conference.wireshark.org/sf26eu/talk/CS3YAN/
END:VEVENT
END:VCALENDAR
