Covert Channels in the RFC Corpus: A Survey and Measurement Study of Unused, Reserved, and Optional Protocol Fields
paper authors: Bommarito, M. J., II
year: 2026
venue: Working paper (draft)
details: Draft manuscript. A keyword-guided screen of every RFC from 1 to 9937 (9,738 issued documents) yielding a 190-entry catalog of covert-channel carrier fields across 74 protocols: 181 primary candidate fields, 176 usable in practice. Reserved and must-be-zero bits, the fields most often discussed in prior work, are 45.7% of the catalog but only 3.5% of its capacity; a handful of padding, codepoint, and optional fields hold 87.1% of the theoretical capacity, and 19.3% of fields ride the wire under cryptographic integrity while holding 42.4% of the total capacity, out of any in-path observer's reach. All usable channels are implemented and measured for byte-for-byte recovery, throughput, and efficiency between Linux hosts using a new open-source Python library, Celatim, with 280 cross-host native-protocol executions, 72 paired trials on each of two production-daemon paths, and a benign-cohort detector evaluation (ROC/PR, Wilson intervals, prevalence-adjusted precision across three tool backends). The catalog, channel implementations, measurement code, and detection/scrub generators are released open source (Apache-2.0).
pdf preview
citation
Bommarito, M. J., II (2026). Covert Channels in the RFC Corpus: A Survey and Measurement Study of Unused, Reserved, and Optional Protocol Fields. Working paper (draft). Draft manuscript. A keyword-guided screen of every RFC from 1 to 9937 (9,738 issued documents) yielding a 190-entry catalog of covert-channel carrier fields across 74 protocols: 181 primary candidate fields, 176 usable in practice. Reserved and must-be-zero bits, the fields most often discussed in prior work, are 45.7% of the catalog but only 3.5% of its capacity; a handful of padding, codepoint, and optional fields hold 87.1% of the theoretical capacity, and 19.3% of fields ride the wire under cryptographic integrity while holding 42.4% of the total capacity, out of any in-path observer's reach. All usable channels are implemented and measured for byte-for-byte recovery, throughput, and efficiency between Linux hosts using a new open-source Python library, Celatim, with 280 cross-host native-protocol executions, 72 paired trials on each of two production-daemon paths, and a benign-cohort detector evaluation (ROC/PR, Wilson intervals, prevalence-adjusted precision across three tool backends). The catalog, channel implementations, measurement code, and detection/scrub generators are released open source (Apache-2.0)..