Abstract-A VoIP covert channel is a mechanism that utilizes an IP phone conversation to illicitly transfer information across a network. In this paper, we present a model of VoIP covert channels that explains their main components and functions. We provide a performance evaluation framework, and quantify the threat to users. Our results demonstrate that covert channels represent an immediate threat to VoIP users. We discuss possible course of actions to detect attacks and mitigate the risk of information leakage.Index Terms-voice over IP, channel capacity, security of data, covert communication, watermarking, VoIP covert channel.