9 ms·
Academics steal data from air-gapped systems using PC fan vibrations
- peter_d_sherman 6y agoExcerpt: "In past research, Guri and his team at the Ben-Gurion university's Cyber-Security Research Center have shown that attackers could steal data from secure systems using a plethora of techniques such as: LED-it-Go - exfiltrate data from air-gapped systems via an HDD's activity LED USBee - force a USB connector's data bus give out electromagnetic emissions that can be used to exfiltrate data AirHopper - use the local GPU card to emit electromagnetic signals to a nearby mobile phone, also used to steal data Fansmitter - steal data from air-gapped PCs using sounds emanated by a computer's GPU fan DiskFiltration - use controlled read/write HDD operations to steal data via sound waves BitWhisper - exfiltrate data from non-networked computers using heat emanations Unnamed attack - uses flatbed scanners to relay commands to malware infested PCs or to exfiltrate data from compromised systems xLED - use router or switch LEDs to exfiltrate data aIR-Jumper - use a security camera's infrared capabilities to steal data from air-gapped networks HVACKer - use HVAC systems to control malware on air-gapped systems MAGNETO & ODINI - steal data from Faraday cage-protected systems MOSQUITO - steal data from PCs using attached speakers and headphones PowerHammer - steal data from air-gapped systems using power lines CTRL-ALT-LED - steal data from air-gapped systems using keyboard LEDs BRIGHTNESS - steal data from air-gapped systems using screen brightness variations
- jbob2000 6y agoCan I get some clarity on the types of data they extract? Looking at blinking LEDs tells me that the HDD is on and processing something, yes, but it doesn’t tell me the digits of the credit card number it’s processing (for example). Do they researchers track the value of the information they “steal”? Or is any data at all valuable?
- ken 6y ago"Guri's research doesn't look at ways of compromising and planting malware on these super-secure systems" ... "malicious code planted on an air-gapped system can control the speed at which fans work"
- jlg23 6y agoIf you control the blinking of the led you have established a very low bandwidth communication channel.
- jbob2000 6y agoOhhh I misunderstood; I thought they were stealing data by simply observing the blinking LED, not that they had infiltrated the computer and were controlling the LED.
- na85 6y agoThe term "exfiltrate" implies that the data is being "pushed" or otherwise sent outward from the machine, as opposed to being harvested from the outside.
- fbi-director 6y agoThank you, because you wrote this, I too now understand what they meant. My train of thought was apparently on the same track as yours!
- hutzlibu 6y agoAllmost (or all?) of those attacks are only possible, if the target computer is infected. And the scenario is that the virus wants to send data out, to a nearby decice which is also infected.
- skykooler 6y agoWhich is why this is "exfiltration", not "infiltration".
- WoahNoun 6y agoIt's about how to get data out once you've already compromised the machine. You control the blinking of the LED to match match the data you want to capture out.
- mlazos 6y agoBasically the idea is that air gapped is still not secure. If someone plugs in a foreign flash drive into a computer that is air gapped one would think the data can’t leave the secure machine. With these methods though, it’s clear that any hardware observable to the outside world can be used to exfiltrate data
- makapuf 6y agoWell, I think anyone could have thought of the screen or speakers or, well the usb you achieved to plug to get data out of a computer. You have no network but I doubt you can consider airgapped a pc you just plugged a usb device into. Why not plug a mini wifi chip then ?
- amelius 6y agoWe have already seen these kinds of attacks in the early days of computing, where people could read a CRT from a nearby parked van. https://en.wikipedia.org/wiki/Van_Eck_phreaking https://en.wikipedia.org/wiki/Van_Eck_phreaking (and if you have access to the machine, then this only makes it easier to get data out)
- alexgmcm 6y agoI remember reading about that in Cryptonomicon, I knew it was technically possible but I didn't realise it actually worked.
- piinthesky 6y ago> AirHopper - use the local GPU card to emit electromagnetic signals I had this on my W10 1909 machine until the recent MS updates earlier this week. No AV, not even MS own AV picks it up, but I have found a way to detect it.
- heavenlyblue 6y agoIs there a table of the associated bandwidths?
- lostlogin 6y ago> DiskFiltration - use controlled read/write HDD operations to steal data via sound waves There is almost nothing I miss about spinning disks, but having an audible indication that something was going wrong was helpful. I refer to inappropriate disk usage (too little or too much) rather than the noises that preceded a disk death.
- function_seven 6y agoYou know how some electric cars create fake engine noise at low speeds to avoid sneaking up on pedestrians? I wish that was an option with SSDs. A little speaker included with the package that I could toggle on. All it does it make fake HDD sounds. Bonus if those sounds match the underlying logical distance and “shape” of the read/write activity.
- detaro 6y agoI wonder if one could make something driven purely by the diskactivity LED that's mildly convincing
- _Nat_ 6y agoSeems like a quirky-fun sorta project! If you've got an SSD connected by a power cord, presumably you could insert an electric-current-meter to see how much power it's drawing, then hook up a speaker to make corresponding sounds. Maybe also put a temperature probe inside of the SSD's box (perhaps directly on a controller-IC?), then another probe just outside of the SSD's box (or inside of it, but away from the controller-IC?), then use that temperature difference too? A software solution would probably be easier, but then you'd have to trust the system to give correct information, which I guess would defeat the point. Someone who'd really want to go at this might make their own controller to place between the motherboard and SSD. But unless it's passive/transparent, allowing the normal SSD driver to be used, that'd seem to require writing a driver for the controller too.
- johnchristopher 6y agoMight still be working https://www.1014.org/code/nullsoft/nbeep/ https://www.1014.org/code/nullsoft/nbeep/
- JoshTriplett 6y agoAlso from the same group, GSMem: exfiltrate data by generating GSM signals using nothing but RAM access patterns. https://www.usenix.org/node/190937 https://www.usenix.org/node/190937
- deleted 6y ago[deleted]
- soVeryTired 6y agoAnyone know how practical these attacks are in the real world? Are they just an academic exercise or is there a real threat? One issue that jumps out at me is if the system is air-gapped, how does the malicious software get there in the first place without being detected?
- bob1029 6y agoI would say they are impractical if you have perfect physical security. Assuming your initial condition is that the air-gapped system is 100% clean to start with, you would need physical access at least one time to kick off the show for all of these crazy schemes.
- estebarb 6y agoUnless you control each and every provider is difficult to achieve perfect physical security. Most companies just bought the fans from somebody else.
- tams 6y agoAir gapping only means lack of network interfaces, so sneakernet is used to transmit data. And sneakernet (floppies back then) was the primary delivery medium for computer viruses before it was common for personal computers to have internet access.
- pseudoramble 6y agoIn regard to your 2nd question, there are a few ways I'm aware of: 1. USB devices. If you need to move software from outside the air gap to inside, it's pretty easy to imagine somebody copying malicious software unintentionally through that. You might think that typical AV could detect it, but that could either be worked around, disabled by the operators of those systems, or simply not up-to-date because they're in the air gap. 2. Sometimes, air-gapped systems still have some kind of tunnel that allows an exceptional connection between a system outside the air gap. If you knew how to access that tunnel, you could effectively compromise the air gapped network. I'm sure there are more ways too. But those are a few I know off-hand.
- 6y ago
- benibela 6y agoThey could try it with coil whine I am just working on a chart that shows a tooltip when the mouse cursor hovers over a data point. Everytime the tooltip is shown, my laptop cheeps edit: or even if I just scroll the browser window
- calaphos 6y agoQuite a problem, especially when considering cryptographic implementations. Here's am article from 2016: https://dl.acm.org/doi/10.1145/2851486 https://dl.acm.org/doi/10.1145/2851486
- fnord77 6y agoMaybe, I am wrong, but none of these seem particularly high-bandwidth
- fooker 6y agoSpectre exploits are low bandwidth too.
- kardos 6y agoYeah you won't extract a large database with these methods, but you could extract an encryption key or SSH key ... a kilobyte goes a long way here
- netflixandkill 6y agoAs a practical example, the keys and metadata for a root certificate authority are only a few kilobytes.
- hutzlibu 6y agoAnother practical example, names of secret agents and places of meetings are not long, either.
- kevindong 6y agoThe article says: > In fact, data can be exfiltrated through vibrations at a lowly speed of half a bit per second, making AiR-ViBeR one of the slowest exfiltration methods that Guri and his team have come up with in recent years. My personal private key has a file size of 3,243 bytes. At the quoted speed, it would take ~14.4 hours to steal assuming that the time spent recording is completely continuous. A single ASCII character would take 16 seconds to "steal".
- moonchild 6y agoASCII is a 7-bit encoding, it would take 14 seconds.
- 6y ago
- varjag 6y agoThey don't "steal" the data from an uncompromised system but establish a backchannel on a compromised one.
- _bxg1 6y agoThat's an important distinction. I was wondering how in the world arbitrary data was making it to the fan.
- varjag 6y agoYep. As long as you have control over the system, you can use any physical phenomenon to communicate: blink the LEDs, beep with the speaker, tap it out with robot arm etc. Not very groundbreaking per se.
- deleted 6y ago[deleted]
- surround 6y agoHere’s an article from 2016 about the same team. In this attack, they use the sound of the fans instead of the vibration. The difference is, they would need microphone permissions in infected smartphones, whereas the vibration method can be transmitted with accelerometers (which doesn’t require user’s permission) https://www.wired.com/2016/06/clever-attack-uses-sound-computers-fan-steal-data/ https://www.wired.com/2016/06/clever-attack-uses-sound-compu...
- hutzlibu 6y agoUse case for air gapping technics, despite their small bandwidth: - very powerful agencies with the aim to get valuable information exists - they want and do infect as many systems as possible automatically, by sneaking into them by all means avaiable (OS updates, hardware backdoors, zero days, ..), wih the hope of getting to valuable targets eventually (but zombies have a value, too) - any organization with very sensitive data, high value research or other (smaller) intelligence agency knows that, so they try to have their most sensitive data on air gapped networks or single computers. - the attackers already drown in information and do not want their virus to be exposed so easy, so air gapping technics will likely be not used normaly to reduce dedection risk (also the are slow and unreliable) But, now to get the most sensitive informations, all the atackers have to do, is checking if the system is air-gapped. Means, it is likely that it is a high value target. Now the various technices come into play, so the virus tries to communicate with the outside world in the hope of a also infected device nearby with which it can maybe exchange a few kb. If he can make a small connection, then a human (or algorithm) can check, if it is really a high value target worth deploying more sophisticated attacks, or just a paranoid hacker trying to protect his personal stuff, or just a old forgotting pc. In other words, if you have really sensitive data, air gapping it, might be the way to attract attackers in the first place .. Computer security is hard.
- SilasX 6y agoI "stole" data about when my co-workers were starting npm based on when I heard their laptop fans come on.
- userbinator 6y agoIn theory, anything that can have at least two distinct observable states can be used to store/transmit data. That is, after all, the whole principle which makes binary digital computing possible.
- seanwilson 6y ago> Guri says that malicious code planted on an air-gapped system can control the speed at which fans work. By moderating fan speed up and down, the attacker can control the frequency of the vibrations coming off the fan. Ah, so it's a malicious program using fan vibrations to communicate data to an attacker via sound where the attacker doesn't have a network connection to the computer the malicious program is running on? I thought it was going to be something to do with e.g. passively reading passwords/keys via the fan vibrations somehow when the system was running non-malicious code.
- alexfromapex 6y agoThe data bandwidth for fan speed modulation has to be very slow when compared to more traditional data transfer methods I’d imagine?
- BenjiWiebe 6y agoSo I guess on an air gapped computer, it's a good idea to set the fans to 100% in BIOS, rather than smart control / auto.
- notatoad 6y agogiven the list of other exploits these guys have for exfiltrating data from airgapped computers, it seems like if you are going to the trouble of making an airgapped computer, you should put it in its own room with no other computers and that nobody is allowed to bring their phone into.
- lopmotr 6y agoWhy is this research? Everyone knows that software can control fan speed either directly with commands or indirectly with load. Everyone also knows you can hear the sounds fans make and microphones can pick up sounds or vibrations. It seems to be just a mundane engineering job or hobby project. Maybe there's some value in getting a higher bandwidth or longer range detection or whatever, but the basic principle is too obviously true to need to be proved.
- netflixandkill 6y agoHow fun. Practical implementation in most cases is movie plot level implausible, but for certain high value systems we already know that state level actors have the resources and patience to do something like build a side channel link by having air gapped systems relay in and out via acoustics with HVAC or whatever. This is going to be a lot more serious as IOY device capabilities increase -- so many available microphones and radios built into everything.