3 ms·
x-rays are useful to identify parts which don't belong in the original design, though it doesnt say anything about these parts. It can be manufacturing errors /
by vectorEQ 8y ago
x-rays are useful to identify parts which don't belong in the original design, though it doesnt say anything about these parts. It can be manufacturing errors / design iterations not well documented or any number of things besides a malicious implant. more manual analysis will always be needed. But if you have tons of PCBs to go through it can give a quick overview what chips might be good initial targets.
some people noted that some 'hardware' attacks can't be seen because they use original parts. -> that's a silly statement, as that would make it a firmware attack, not a hardware attack (even though physical access might be needed to flash the chip, it's the firmware which is malicious, not the chip itsefl. i.e. other type of threat / use-case).
i think the problem with x-rays, apart from them being hazardous in themselves, the cost and availibility of equipment is not practical for reverse engineers and researchers apart from some highest tier companies doing this.
A question to NH about this which might be more interesting:
do you think you can get similar results using ultrasound? Because ultrasound devices are fairly cheap and can be made at home fairly easily compared to x-ray technology. It's also much less hazardous to the researchers....
- ChrisLomont 8y ago>that's a silly statement, as that would make it a firmware attack, not a hardware attack Original parts can also have attacks not in firmware, without changing the transistor layouts, via dopant attacks [1, paper at 2]. [1] https://www.researchgate.net/publication/262211582_Stealthy_Dopant-Level_Hardware_Trojans https://www.researchgate.net/publication/262211582_Stealthy_... [2] https://sharps.org/wp-content/uploads/BECKER-CHES.pdf https://sharps.org/wp-content/uploads/BECKER-CHES.pdf
- rasz 8y ago>some people noted that some 'hardware' attacks can't be seen because they use original parts. You can have original looking part. Imagine a 8Mbit SOIC SPI NOR flash chip. Looks the part, belongs in its spot, you decap it and it sure does look like a flash Die with its normal Flash controller. Now consider this: http://travisgoodspeed.blogspot.com/2012/07/emulating-usb-devices-with-python.html http://travisgoodspeed.blogspot.com/2012/07/emulating-usb-de... I cant find it right now, but Afair Travis (or maybe it was hak5 RubberDucky folks) noticed early on that its pretty trivial to detect what is happening on the Host side of the interface - what operating system am I plugged into and at what phase of the operation are we on (bios query, OS loading drivers). Imagine a Flash chip that is able to tell (power sequencing, timing and order of commands) if its booting a particular controller on the board, or if its being read in a flash programmer. Flash chips have processors running their own firmware nowadays, turtles all the way own.