{"data":{"id":"SC-31","name":"Covert Channel Analysis","family":"SC","family_name":"System and Communications Protection","withdrawn":false,"description":"a. Perform a covert channel analysis to identify those aspects of communications within the system that are potential avenues for covert [Selection (one or more): storage; timing] channels; and\nb. Estimate the maximum bandwidth of those channels.","supplemental_guidance":"Developers are in the best position to identify potential areas within systems that might lead to covert channels. Covert channel analysis is a meaningful activity when there is the potential for unauthorized information flows across security domains, such as in the case of systems that contain export-controlled information and have connections to external networks (i.e., networks that are not controlled by organizations). Covert channel analysis is also useful for multilevel secure systems, multiple security level systems, and cross-domain systems.","enhancements":[{"id":"SC-31(01)","name":"Test Covert Channels for Exploitability","statement":"Test a subset of the identified covert channels to determine the channels that are exploitable.","baselines":[]},{"id":"SC-31(02)","name":"Maximum Bandwidth","statement":"Reduce the maximum bandwidth for identified covert [Selection (one or more): storage; timing] channels to [Assignment: organization-defined values].","baselines":[]},{"id":"SC-31(03)","name":"Measure Bandwidth in Operational Environments","statement":"Measure the bandwidth of [Assignment: organization-defined subset of identified covert channels] in the operational environment of the system.","baselines":[]}],"baseline_low":false,"baseline_moderate":false,"baseline_high":false,"nist_800_53":{"rev5":{"id":"SC-31","name":"Covert Channel Analysis","description":"a. Perform a covert channel analysis to identify those aspects of communications within the system that are potential avenues for covert [Selection (one or more): storage; timing] channels; and\nb. Estimate the maximum bandwidth of those channels.","discussion":"Developers are in the best position to identify potential areas within systems that might lead to covert channels. Covert channel analysis is a meaningful activity when there is the potential for unauthorized information flows across security domains, such as in the case of systems that contain export-controlled information and have connections to external networks (i.e., networks that are not controlled by organizations). Covert channel analysis is also useful for multilevel secure systems, multiple security level systems, and cross-domain systems.","related_controls":["AC-03","AC-04","SA-08","SI-11"],"baseline_low":null,"baseline_moderate":null,"baseline_high":null,"baseline_privacy":null,"new_in_rev5":false,"changes_from_rev4":"No significant title changes from Rev 4."}},"compliance_mappings":{"iso_27001_2022":[],"iso_27002_2022":["8.12"],"cobit_2019":[],"pci_dss_v4":[],"nist_csf_2":[],"cis_controls_v8":[],"soc2_tsc":[],"finos_ccc":[],"iso_42001_2023":[],"iec_62443":[],"asd_e8":[],"nis2":[],"apra_cps_234":[],"mas_trm":[],"pra_op_resilience":[],"bsi_grundschutz":[],"anssi":[],"osfi_b13":[],"finma_circular":[],"gdpr":[],"dora":[],"bio2":["8.12"],"rbi_csf":["Annex1.4"],"fisc":[],"lgpd_bcb":[],"hkma_tme1":[],"mlps_2":[],"dnb_good_practice":[],"cra":[],"swift_cscf":[],"nerc_cip":[],"nrc_73_54":[],"tsa_psd":[],"ieee_1686":[],"ferc_cip":[],"doe_c2m2":[],"api_1164":[],"awia":[],"iaea_nss":[],"pci_pts":[],"fips_140":[],"cbest":[],"tiber_eu":[],"pci_hsm":[],"common_criteria":[],"isae_3402":[],"fca_sysc_13":[],"fda_21_cfr_11":[],"fda_cyber":[],"hitrust_csf":[],"iso_27799":[],"lloyds_ms":[],"naic_ds":[],"nhs_dspt":[],"pra_ss1_23":[],"solvency_ii":[],"owasp_masvs_v2":[],"csa_ccm_v4":[],"csa_aicm":[],"ccss_v9":[],"mica":[],"basel_sco60":[],"bssc":[],"sec_custody_digital":[],"dpdpa":[]},"attack_techniques":[{"id":"T1041","name":"Exfiltration Over C2 Channel","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Covert channel analysis identifies potential exfiltration paths within C2 channels by analyzing system communication patterns for hidden data transfer capabilities that adversaries exploit for data theft."},{"id":"T1048","name":"Exfiltration Over Alternative Protocol","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Analyzing system communications for covert channel potential identifies alternative protocol paths that adversaries exploit for exfiltration, enabling targeted controls on identified covert exfiltration channels."},{"id":"T1071","name":"Application Layer Protocol","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Covert channel analysis of application-layer protocol communications identifies bandwidth and timing characteristics that adversaries exploit to embed C2 data within legitimate protocol traffic."},{"id":"T1567","name":"Exfiltration Over Web Service","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Analyzing web service communications for covert channel potential identifies exfiltration pathways through cloud storage and SaaS platforms that adversaries leverage for data theft over web services."},{"id":"T1048.002","name":"Exfiltration Over Asymmetric Encrypted Non-C2 Protocol","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Covert channel analysis specifically identifies encrypted non-C2 protocol channels (HTTPS to non-standard endpoints, encrypted FTP) that adversaries exploit for asymmetric encrypted exfiltration."},{"id":"T1048.003","name":"Exfiltration Over Unencrypted Non-C2 Protocol","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Analyzing unencrypted protocol channels for covert data transfer potential identifies cleartext exfiltration pathways through DNS, HTTP, and other protocols that adversaries use for unencrypted data exfiltration."},{"id":"T1071.001","name":"Web Protocols","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Covert channel analysis of web protocol communications estimates bandwidth capacity of HTTP/HTTPS channels for hidden data transfer, enabling controls that limit adversary C2 within web traffic."},{"id":"T1071.002","name":"File Transfer Protocols","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Analyzing file transfer protocol communications for covert channel characteristics identifies bandwidth and timing channels within FTP/SFTP traffic that adversaries exploit for hidden C2 data exchange."},{"id":"T1071.003","name":"Mail Protocols","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Covert channel analysis of mail protocol communications identifies hidden data transfer capabilities within SMTP/IMAP traffic that adversaries exploit for email-based C2 channels."},{"id":"T1071.004","name":"DNS","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Analyzing DNS communications for covert channel bandwidth estimates the data transfer capacity of DNS query/response channels, enabling controls against DNS-based C2 and data exfiltration tunneling."},{"id":"T1071.005","name":"Publish/Subscribe Protocols","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Covert channel analysis of publish/subscribe protocol communications identifies hidden data transfer capabilities within MQTT, AMQP, and similar protocols that adversaries exploit for C2."}],"metadata":{"last_reviewed":"2026-02-19","review_notes":"","mapping_status":"complete"},"function":"preventative","used_by_patterns":[]}}