NIST 800-53 r5 · Controls catalogue · Family SC
SC-31Covert Channel Analysis
Perform a covert channel analysis to identify those aspects of communications within the system that are potential avenues for covert {{ insert: param, sc-31_odp }} channels; and Estimate the maximum bandwidth of those channels.
Last updated: 20 August 2026 13:14 UTC
Implementations targeting this control (0)
- No implementations targeting this control yet.
ATT&CK techniques this control mitigates (11)
- T1041 Exfiltration Over C2 Channel Exfiltration
- T1048 Exfiltration Over Alternative Protocol Exfiltration
- T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol Exfiltration
- T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol Exfiltration
- T1071 Application Layer Protocol Command And Control
- T1071.001 Web Protocols Command And Control
- T1071.002 File Transfer Protocols Command And Control
- T1071.003 Mail Protocols Command And Control
- T1071.004 DNS Command And Control
- T1071.005 Publish/Subscribe Protocols Command And Control
- T1567 Exfiltration Over Web Service Exfiltration
Weaknesses this control addresses (3)AI-assisted
CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.
| CWE | Name | CVEs | Why this control addresses it |
|---|---|---|---|
CWE-203 | Observable Discrepancy | 800+ | Observable discrepancies in system behavior can be modulated to create covert storage or timing channels; the required analysis detects and constrains such avenues. |
CWE-208 | Observable Timing Discrepancy | 100+ | Observable timing discrepancies are a primary mechanism for constructing covert timing channels; analysis identifies and bounds them, limiting exploitation. |
CWE-385 | Covert Timing Channel | 43 | Directly targets covert timing channels by requiring identification and bandwidth estimation, enabling mitigation that reduces or eliminates their usability. |
Top CVEs where this control is the strongest mitigation
| CVE | Risk | CVSS | EPSS | Match |
|---|---|---|---|---|
CVE-2026-5598 UPD | 6.0 | 7.5 | 0.0090 | good |
CVE-2023-46809 UPD | 5.9 | 7.4 | 0.0130 | good |
CVE-2025-59425 UPD | 5.9 | 7.5 | 0.0053 | good |
CVE-2025-0306 UPD | 5.8 | 7.4 | 0.0065 | good |
CVE-2025-9231 UPD | 5.6 | 6.5 | 0.0223 | good |
CVE-2026-6478 UPD | 5.2 | 6.5 | 0.0056 | good |
CVE-2024-2236 UPD | 4.9 | 5.9 | 0.0111 | good |
CVE-2024-26306 UPD | 4.9 | 5.9 | 0.0110 | good |
CVE-2024-25964 UPD | 4.6 | 5.3 | 0.0067 | good |
CVE-2024-45192 UPD | 4.3 | 5.3 | 0.0054 | good |
CVE-2025-27587 UPD | 4.2 | 5.3 | 0.0038 | good |
CVE-2025-66442 | 4.0 | 5.1 | 0.0027 | good |
CVE-2024-13176 UPD | 3.6 | 4.1 | 0.0061 | good |
CVE-2025-7396 UPD | 3.6 | 4.6 | 0.0019 | good |
CVE-2025-69893 UPD | 3.6 | 4.6 | 0.0024 | good |
CVE-2024-11862 UPD | 3.5 | 5.1 | 0.0014 | good |
CVE-2026-42768 UPD | 3.4 | 3.7 | 0.0058 | good |
CVE-2023-33855 UPD | 3.3 | 3.7 | 0.0045 | good |
CVE-2025-49087 UPD | 3.3 | 4.0 | 0.0040 | good |
CVE-2024-36405 UPD | 4.7 | 5.9 | 0.0052 | good |
CVE-2024-23170 UPD | 4.3 | 5.5 | 0.0031 | good |
CVE-2025-59432 UPD | 3.5 | 6.6 | 0.0085 | good |
CVE-2024-23342 UPD | 5.9 | 7.4 | 0.0098 | good |
CVE-2025-29780 UPD | 3.5 | 5.8 | 0.0023 | good |
CVE-2025-53826 UPD | 7.3 | 9.8 | 0.0050 | good |